On September 10, 2026, the ShinyHunters hacking group claimed responsibility for breaching McKesson, a major medical supplier, stealing 6.4 million records. The leaked data includes information on patients, staff, and healthcare providers, with records logged in the Have I Been Pwned database.
Healthcare technology company Veradigm disclosed on September 8–9, 2026, that attackers stolen credentials from a third-party vendor to access its customer service API, exposing patient personal data including Social Security numbers. The Gentlemen ransomware gang claimed responsibility for the attack.
Healthcare and pharmaceutical distribution giant McKesson on 2026-08-28 disclosed a cybersecurity incident involving unauthorized access and data theft, with the ShinyHunters extortion group claiming on 2026-08-30 to have exfiltrated 284 million healthcare records via vishing attacks on third-party applications. The breach represented one of the largest healthcare data exposures.