STOCK TITAN

Cyber incident hits McKesson (NYSE: MCK) systems; impact under review

(Moderate)
(Neutral)
Form Type
8-K

Rhea-AI Filing Summary

McKesson Corporation (MCK) reported that on August 25, 2026 it discovered a cybersecurity incident affecting its information systems. The investigation is in its early stages, and additional information and updates are being made available on the company’s website at www.mckesson.com/cybersecurity.

As of this report, McKesson states it has not determined that the incident is material or that it has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations.

Positive

  • None.

Negative

  • None.
Item 7.01 Regulation FD Disclosure Disclosure
Material non-public information disclosed under Regulation Fair Disclosure, often investor presentations or guidance.
Item 9.01 Financial Statements and Exhibits Exhibits
Financial statements, pro forma financial information, or exhibit attachments filed with this report.
Cybersecurity incident discovery date August 25, 2026 Date McKesson discovered the cybersecurity incident affecting its information systems
1.625% Notes due 2026 1.625% Interest rate on McKesson’s notes due 2026 listed on the New York Stock Exchange
3.125% Notes due 2029 3.125% Interest rate on McKesson’s notes due 2029 listed on the New York Stock Exchange
Report signature date August 28, 2026 Date McKesson’s 8-K report was signed by the Executive Vice President and Chief Legal Officer
cybersecurity incident technical
"McKesson Corporation discovered a cybersecurity incident affecting its information systems."
A cybersecurity incident is an event where someone's computer systems or data are attacked or broken into without permission. It matters because it can lead to stolen information, financial loss, or disruptions in services, similar to a break-in at a store that damages property or steals valuable items.
emerging growth company regulatory
"405) or Rule 12b-2 of the Securities Exchange Act of 1934 (17 CFR §240.12b-2). Emerging growth company"
An emerging growth company is a recently public or smaller public firm that qualifies for temporary, lighter regulatory and disclosure rules to reduce the cost and effort of being public. For investors, it means the company may provide less historical financial detail and face fewer reporting requirements than larger firms, so it can grow more quickly but also carries higher uncertainty—like buying a promising early-stage product with fewer user reviews.
Inline XBRL technical
"Cover Page Interactive Data File - the cover page iXBRL tags are embedded within the Inline XBRL document"
Inline XBRL is a file format for financial filings that embeds machine-readable data tags directly inside the human-readable report, so the same document can be read by people and parsed by software. For investors it makes extracting, comparing and verifying financial numbers faster and more reliable—like a grocery list where each item also has a barcode—reducing manual errors and speeding up analysis.

FAQ

What cybersecurity incident did McKesson (MCK) disclose in this 8-K?

McKesson disclosed that on August 25, 2026 it discovered a cybersecurity incident affecting its information systems. The company states the investigation is in its early stages and is providing information and updates on www.mckesson.com/cybersecurity.

Has McKesson (MCK) determined that the cybersecurity incident is material?

No. McKesson states it has not determined that the incident is material as of the date of the report and has not determined that it has had, or is reasonably likely to have, any material impact on the company.

Does McKesson report any financial impact from the cybersecurity incident?

McKesson states it has not determined that the incident has had, or is reasonably likely to have, any material impact on its financial condition or results of operations. No specific financial effects are quantified in this report.

Where can investors find updates on McKesson’s cybersecurity incident?

McKesson indicates that information about the incident, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity.

Who signed McKesson’s 8-K about the cybersecurity incident?

The report was signed on behalf of McKesson Corporation by Michele Lau, who is identified as Executive Vice President and Chief Legal Officer.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google
Learn about SEC filing dates
00009276538-K2026-08-25false00009276532026-08-252026-08-250000927653us-gaap:CommonStockMember2026-08-252026-08-250000927653mck:A1.625NotesDue2026Member2026-08-252026-08-250000927653mck:A3.125NotesDue2029Member2026-08-252026-08-25

 
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
WASHINGTON, DC 20549
FORM 8-K
CURRENT REPORT
Pursuant to Section 13 or 15(d)
of the Securities Exchange Act of 1934
Date of report (Date of earliest event reported): August 25, 2026
mckessonlogoa04.jpg
McKESSON CORPORATION
(Exact Name of Registrant as Specified in Charter)
Delaware1-1325294-3207296
(State or Other Jurisdiction
of Incorporation)
(Commission
File Number)
(I.R.S. Employer
Identification No.)
6555 State Hwy 161
Irving, TX 75039
(Address of Principal Executive Offices, and Zip Code)
(972) 446-4800
Registrant’s Telephone Number, Including Area Code
Not Applicable
(Former Name or Former Address, if Changed Since Last Report)
Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions (see General Instruction A.2. below):
Written communication pursuant to Rule 425 under the Securities Act (17 CFR 230.425)
Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12)
Pre-commencement communication pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b))
Pre-commencement communication pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c))
Securities registered pursuant to Section 12(b) of the Act:
Title of each classTrading
Symbol(s)
Name of each exchange
on which registered
Common stock, $0.01 par valueMCKNew York Stock Exchange
1.625% Notes due 2026MCK26New York Stock Exchange
3.125% Notes due 2029MCK29New York Stock Exchange
Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (17 CFR §230.405) or Rule 12b-2 of the Securities Exchange Act of 1934 (17 CFR §240.12b-2).
Emerging growth company  
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act.  ☐



Item 7.01
Regulation FD Disclosure.

On August 25, 2026, McKesson Corporation discovered a cybersecurity incident affecting its information systems. An investigation of the incident is in its early stages. Information about the incident, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity.

As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations.

Item 9.01
Financial Statements and Exhibits.
(d) Exhibits.
Exhibit No.  Description
104 Cover Page Interactive Data File - the cover page iXBRL tags are embedded within the Inline XBRL document





SIGNATURES
Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned hereunto duly authorized.
Date: August 28, 2026
 
McKesson Corporation
By:/s/ Michele Lau
Michele Lau
Executive Vice President and
Chief Legal Officer


Filing Exhibits & Attachments

4 documents