McKesson, one of the largest healthcare distributors in the United States, is currently investigating a significant data breach that has been claimed by the cybercriminal group ShinyHunters. The company, which has been serving over 40,000 corporate and institutional customers since its founding in 1833, announced on August 28 that unauthorized access and data exfiltration occurred through third-party applications. By the following day, McKesson confirmed that the breach involved certain customer data from its Oncology & Multispecialty and Medical-Surgical business units. Despite the breach, McKesson assured that customer services remain operational and that there is no ongoing unauthorized activity within its corporate network. ShinyHunters claims to have stolen approximately 284 million records and has demanded a ransom of $55 million. Reports indicate that social engineering tactics were used to target McKesson employees, facilitating the initial access into the system. Industry experts like John Strand from Black Hills Information Security emphasize the growing complexity of securing third-party application environments, particularly with SaaS providers. He urges companies to enhance their supply-chain security measures by scrutinizing their vendors more rigorously. This incident follows closely on the heels of another breach in the healthcare supply chain involving Boston Scientific, which led to global disruptions.