Back to news
Cybersecurity Alert
September 12, 2026 by EmailMeNow IT Consulting

McKesson Confirms Data Theft; Northern Texas Lawsuits Cite Voice Phishing

Irving-based McKesson (MCK) posted a Sept 8 notice after an Aug 20–25 incident on employee accounts. ShinyHunters claimed vishing. N.D. Tex has 15 suits. Audits (ideal 100%): sec.gov 88%, ic3.gov 87%, mckesson.com 69%, covermymeds.com 58%.

Source: McKesson · SEC · Law.com · CourtListener

NewsHealthcareTexasData BreachPhishingVishingMcKessonMFAYubiKeyAuthenticator AppsCybersecurity
Texas healthcare office at dusk with an off-hook desk phone and a redacted unauthorized-access banner

McKesson Corporation — the Irving, Texas drug distributor and healthcare-technology company traded as MCK — confirmed a cybersecurity incident that targeted employee corporate accounts between August 20 and August 25, 2026. Its September 8 notice says data was taken from third-party applications, and that personal and protected health information may be in the set.

This is not a duplicate of the Nutex Health Item 1.05. That August Nutex recap only pointed at McKesson’s earlier service-degradation coverage as a sibling. It is also not the MSG / ShinyHunters vishing or CNO Services vishing stories — different victims.

The new hook in this week’s Texas phishing/ransomware alert pile is the lawsuit wave. Law.com (September 11) reported at least a dozen class actions in northern Texas, including Hall v. McKesson Corp. and CoverMyMeds LLC. CourtListener now shows 15 N.D. Tex. dockets from August 30 through September 10, 2026.

McKesson has not named a crew and has not called the incident material in its 8-K. Treat ShinyHunters, the 284 million records figure, and the voice-phishing of two employees as claims unless McKesson confirms them.

Texas healthcare office at dusk with an off-hook desk phone and a redacted unauthorized-access banner

Snapshot

FieldDetail
CompanyMcKesson Corp. (NYSE: MCK) · HQ Irving, TX
WindowAug 20–25, 2026 (company notice)
SEC filingItem 7.01 8-K dated Aug 28 — not Item 1.05
ActorShinyHunters claimed; not named by McKesson
CourtListener15 N.D. Tex. suits · first Hall 3:26-cv-02958 · Aug 31

What McKesson has confirmed

The August 28 Item 7.01 Form 8-K said McKesson discovered a cybersecurity incident on August 25 and pointed readers to mckesson.com/cybersecurity. As of that filing it had not determined the incident was material or likely to hit results. That is FD disclosure, not the material-incident box Nutex used.

The September 8 substitute notice is more specific:

  • Employee corporate accounts were targeted.
  • The window is August 20–25.
  • McKesson is a vendor to providers, so PHI may be in the copied set.
  • Possible data includes names, addresses, emails, patient IDs, dates of birth, insurance IDs, diagnoses and medicines, billing / card / bank fields, and Social Security numbers — not the same for every person.
  • Patients, guarantors, and others may be in scope. Individual notices come later, through customers.
  • A call center is at 1-855-760-5202. HQ in the notice: 6555 State Highway 161, Irving, TX 75039.

Do not treat a missing Texas OAG row yet as “no Texans were affected.” The company says the review is early.

What ShinyHunters claimed — and what the lawsuits say

HIPAA Journal and CyberScoop reported that ShinyHunters listed McKesson and claimed about 1 TB taken from Salesforce / Snowflake, a ransom above $55 million, and 284 million raw records (rows, not unique patients). CyberInsider said the group told them they voice-phished two employees. McKesson declined to confirm the actor or those counts.

Law.com’s September 11 piece is the lawsuit story: at least a dozen northern Texas complaints accuse McKesson of failing to protect patient data and of slow disclosure. The article names Hall v. McKesson Corp. and CoverMyMeds LLC.

CourtListener RECAP (checked September 12, 2026) lists 15 N.D. Texas dockets captioned against McKesson Corporation, filed August 30–September 10. Examples:

CaseNumberFiled
O’Connor3:26-cv-02929Aug 30
Hall3:26-cv-02958Aug 31
Chavez3:26-cv-03077Sept 10

These are alleged class actions. They do not prove the vishing path in court. They do show how fast a vendor PHI incident becomes Texas federal litigation.

Help-desk cubicle with a headset and a redacted voice-verify script beside a class-action folder

What patients and clinics should do

  1. Type mckesson.com or the official notice yourself. Do not use a “McKesson settlement / IDX / credit-monitor” link from email or text.
  2. If you paid a bill or received care through a McKesson oncology, multispecialty, medical-surgical, or CoverMyMeds workflow, watch EOBs and credit. Enroll in the company’s IDX offer only from a host you typed.
  3. Clinics: assume follow-on fake IT callbacks and fake prior-auth portals. Call back a number already on file.
  4. Freeze credit and report misuse at IdentityTheft.gov and IC3.
  5. A hardware key does not un-copy files that already left. It does cut a lot of the callback and fake-login wave that follows this headline.

MFA: YubiKey and Google Authenticator

Voice phishing beats SMS and many push prompts: the caller asks you to read a code or approve a prompt. Grades match our MFA directory.

GradeMeaning
FailDocumented second factor is SMS, voice, or email OTP — or no public path
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
McKessonFailNoNo
CoverMyMedsFailNoNo

Public McKesson 2FA help for US Oncology / Ontada points staff to the proprietary McKesson Authenticator app (push + in-app TOTP) via selfservice.usoncology.com. That is a vendor-locked token. There is no public retail YubiKey or Google Authenticator enrollment path. CoverMyMeds patient/provider pages we checked do not name either method. A locked app does not stop a voice callback.

Directory: MFA support directory · Category → Healthcare.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key and phone authenticator beside a face-down employee badge

Independent cybersecurity audits

We audited the official McKesson, CoverMyMeds, SEC, and reporting hosts on September 12, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not prove how the accounts were phished.

OrganizationDomainOverallvs 100%
U.S. SECsec.gov88%−12
FBI IC3ic3.gov87%−13
McKessonmckesson.com69%−31
CoverMyMedscovermymeds.com58%−42
DomainIdentityTransportWebsite
sec.gov90%45%98%
ic3.gov90%45%97%
mckesson.com90%15%42%
covermymeds.com65%15%37%

Audit links: sec.gov · ic3.gov · mckesson.com · covermymeds.com

mckesson.com at 69% is still −31 from the ideal. Transport 15% on both McKesson hosts is a mail-transport gap — not a reason to trust a “McKesson IT” callback. sec.gov is the 8-K host. ic3.gov is the reporting host.

Domain audit scoreboard versus the 100 percent ideal

Website stack note

Passive website-tech probes on September 12, 2026:

DomainStack signal
mckesson.comStack undetected; DigiCert TLS expires 2027-03-15
covermymeds.comStack undetected; DigiCert TLS expires 2027-03-26
sec.govDrupal (version hidden); DigiCert TLS expires 2027-03-02
ic3.govStack undetected; DigiCert TLS expires 2027-01-05

Point-in-time only. A live marketing homepage is not a forensic finding on the vishing path.

Blacklist and lookalike domains

Email blacklist checks (public DoH, September 12, 2026): mckesson.com, sec.gov, and ic3.gov were clear on mail/domain lists we can query. covermymeds.com showed an informational SPFBL hit on a shared Proofpoint MX — not a reason to lead “CoverMyMeds is blacklisted.” SEC web/CDN IPs also showed SPFBL notes. Do not lead as “McKesson is blacklisted.”

DNS lookalike scans (BEC profile, registered signals only):

Brand scannedTo reviewLikely ownedBEC staging
mckesson.com3724
covermymeds.com2200
sec.gov1400
ic3.gov1501

High-interest registered names (investigate; not proof this incident used them):

LookalikeTechniqueNote
mckeason.comadjacent-keyBEC staging (NS + MX)
mckess0n.comhomoglyphBEC staging (NS + MX)
mckessoin.cominsertionBEC staging (NS + MX)
mckessons.cominsertionBEC staging (NS + MX)
ic3.comtld-swapBEC staging — not the .gov bureau
sec.comtld-swapLive .com — not the Commission

mckesson.net and mckesson.org point at the brand. Type mckesson.com, not a one-letter swap. Continuous monitoring: Cybersquat Domain Monitoring.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and phishing-resistant MFA aimed at the 100% ideal.


Sources: McKesson notice of data breach (Sept 8, 2026) · McKesson Item 7.01 8-K (filed Aug 28) · Law.com (Sept 11) · HIPAA Journal · CyberScoop · CyberInsider · CourtListener N.D. Tex. RECAP searches September 12, 2026 (Hall 3:26-cv-02958). Independent EmailMeNow audits, website-tech, blacklist, and cybersquat September 12, 2026. Domain scores: audit.emailmenow.com only. Google Alerts weekly scan used as a lead, not as confirmation.