← All Briefings
Briefings


McKesson Breach Shows Third-Party Apps Still The Weak Point

McKesson disclosed unauthorized access to "third-party applications" that led to theft of patient data, with the ShinyHunters extortion group claiming credit. McKesson is the largest pharmaceutical distributor in the United States, moving roughly a third of the country's drug supply. The company has not named the applications, the access method, or the number of patients affected. What it has confirmed is that the breach did not require compromising McKesson's core network, only a connected application with a trust relationship to it.

That distinction matters for every hospital system and pharmacy chain that treats McKesson as a vendor rather than an attack surface. ShinyHunters has spent 2026 running the same play against Salesforce-linked instances at other major retailers and healthcare firms, harvesting OAuth tokens rather than breaking passwords. The open question for McKesson's downstream customers is which third-party integration touched their own patient records, and whether McKesson's incident response, not yet detailed publicly, will name it before regulators require the answer under HIPAA breach notification rules.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.