McKesson reports cyberattack affecting third-party application
The Fortune 9 pharmaceutical distributor disclosed service degradation to regulators while investigating an incident involving an unnamed vendor platform.
McKesson, one of the largest pharmaceutical distributors in North America, has informed regulators it is investigating a cybersecurity incident tied to a third-party application. The company warned of service degradation as the investigation proceeds.
The disclosure, filed with regulators, offers limited detail. McKesson described the probe as being in its early stages and did not name the affected vendor or specify which services have been impaired. The company also did not confirm whether the incident involves ransomware, though the pattern—third-party compromise, service disruption, regulatory filing—matches recent supply chain attacks on healthcare infrastructure.
McKesson's position in the pharmaceutical supply chain amplifies the operational risk. The company distributes roughly one-third of all pharmaceuticals used daily in North America and provides technology platforms to hospitals, pharmacies, and oncology practices. Any sustained disruption to its logistics or software services could cascade into inventory shortages, delayed prescriptions, or care interruptions at thousands of facilities.
- 01Hospitals and pharmacies relying on McKesson platforms may face order delays or inventory gaps.
- 02Pharmaceutical supply chain visibility could degrade if logistics systems remain impaired.
- 03Third-party vendor risk remains the dominant attack surface in healthcare infrastructure.
- 04Regulators may accelerate scrutiny of supply chain cybersecurity controls in critical sectors.
TerminalFix Variant Exploits Fake CAPTCHAs to Deploy Backdoor
Microsoft discloses new ClickFix evolution that directs victims to Windows Terminal, bypassing traditional Run dialog defenses and increasing attack complexity.
Hasbro Discloses Employee Data Breach Following Earlier Cyberattack
The toy and game maker confirms personal information of employees was exposed in a breach tied to operational disruptions earlier this year.
Chinese Actor Exploits ownCloud Flaw, Steals Philippine Nuclear Records
CISA adds critical vulnerability to exploit catalog after breach at Philippine research body. Chinese-speaking threat actor weaponized file-sharing flaw.