The McKesson Breach and the Fake Invoice North Texas Practices Should Expect
The McKesson breach exposed supplier billing data. Here is the fake invoice risk it creates for North Texas practices and what to do this week if one arrives or leaves your mailbox.
On August 28, 2026, McKesson, the Irving-headquartered pharmaceutical and medical supply distributor, told the Securities and Exchange Commission that someone had broken into its systems and walked out with data. For most people in North Texas that headline sounded like a national healthcare story. For the clinics, pharmacies, oncology groups and physician offices in Dallas, Plano, Frisco and McKinney that order from McKesson every week, it was something closer to home. It meant that the contact details, account numbers and billing history attached to their relationship with a major supplier may now sit in a criminal's spreadsheet.
This post walks through what actually happened, what it has cost so far, and the specific risk it creates for a local business that never touched the breach itself. That risk is a fake invoice. Either one arrives in your inbox looking exactly like a supplier you trust, or one leaves your own mailbox after an attacker takes it over and starts billing your clients. Both are forms of business email compromise, and both tend to follow a large, public data theft like this one by weeks, not years.
What Happened at McKesson
According to McKesson's own filings and updates, the company detected unauthorized activity on August 25, 2026, and announced the incident three days later. The company described it as an incident "involving third-party applications" with "unauthorized access and exfiltration of data." Exfiltration is the technical word for data being copied out of a company and taken somewhere else. It is the difference between a burglar who breaks a window and a burglar who leaves with the filing cabinet.
A criminal group called ShinyHunters claimed responsibility and listed McKesson on its leak site, which is a public website where extortion groups post stolen data when a victim does not pay. The group claimed 284 million rows of patient data. That figure counts rows in a database, not unique people, so it overstates the number of individuals involved. A more grounded figure came from Troy Hunt, who runs the breach notification service Have I Been Pwned. He reported that the stolen data included 6.4 million unique email addresses belonging to patients, staff, marketing contacts and others.
On September 8, McKesson published its initial findings. The data potentially taken included names, addresses, phone numbers, email addresses and dates of birth, along with health insurance details, medical information, and, importantly for this post, billing, claims and payment information, including account numbers and financial and banking information. McKesson said the incident appears to involve a subset of customers in its Oncology and Multispecialty and its Medical-Surgical business units.
It is worth noting how ShinyHunters typically gets in. The group is known for voice phishing, often shortened to vishing, which means calling an employee while pretending to be IT support or a vendor and talking them into handing over access. We covered that playbook in detail in our post on the fake IT help desk call. No firewall setting stops a convincing phone call. A trained employee and a verification habit do.
What It Has Cost So Far
The direct costs to McKesson are still being counted, and the company has not yet said whether the incident is material to its finances. Public reporting has described a ransom demand of more than 55 million dollars. Customers were warned to expect intermittent service degradation, which is a polite way of saying that ordering and account systems might be slow or unavailable at times. McKesson said orders were still being accepted and its distribution centers stayed open.
For a local practice, the cost does not show up as a ransom. It shows up three ways. First, your staff spend hours fielding patient calls about breach notification letters, a pattern we described after a Tarrant County hospital incident in what Fort Worth businesses must do after a hospital breach notification. Second, your billing team now works with a supplier whose customer records are in criminal hands, which raises the odds of a convincing fake invoice. Third, the email addresses in that 6.4 million figure include staff and business contacts, which means your own people may start receiving far more targeted phishing than they are used to.
That second cost is the one that turns into real money for a small business, and it is the one most owners are not watching for.
The Fake Invoice That Usually Comes Next
Here is the pattern. When a big supplier has a public incident, criminals who hold or buy pieces of its customer data send emails that look like they come from that supplier. The timing is the trick. Everyone has just read the news, so an email saying "Due to our recent security incident, we have moved to a new bank account. Please update your remittance details before your next payment" sounds completely reasonable. It references something real. It arrives from a lookalike address that differs from the real one by a single letter. It may even quote a real account number or a real past order, because that data was in the theft.
Picture a six-provider specialty practice in Plano. Their office manager pays supply invoices by ACH every two weeks. ACH, short for Automated Clearing House, is the bank network that moves direct deposits and electronic bill payments between US bank accounts. ACH payments feel routine because they are routine, and that is exactly why they are attractive to attackers. A wire transfer often triggers a phone call from the bank. A changed ACH vendor record usually triggers nothing at all. The practice keeps paying the "supplier" for six weeks before the real supplier calls about a past due balance.
We are not saying this has happened to any specific McKesson customer. We are saying this is the most common way a large breach turns into a loss at a small business that was never breached itself, and the data McKesson described is exactly the raw material it needs.
When the Fraudulent Invoice Leaves Your Mailbox
There is a second version that is worse, and it is the one we are called about most often. Instead of impersonating a supplier, the attacker takes over a real mailbox inside your business. Usually they phish one employee's Microsoft 365 password, sign in quietly, and watch. They learn who you bill, how you word your invoices and when payments are due. Then they send your own clients an invoice, from your real address, with new bank details. Because the email genuinely comes from you, every check your client runs on the sender passes.
If that has happened, the first hour matters more than the next week. Have someone reset the compromised account's password and sign it out of every device. Then check the mailbox rules. Attackers almost always create a hidden rule that forwards or deletes replies so you never see your client asking about the new account. Then call the bank that received the money, and call your own bank, and ask both about a recall. Recovery odds drop sharply after the first day or two, which is why our post on recovering money after you paid a fake invoice leads with the phone calls rather than the forensics.
Then you have to talk to your clients, and most owners freeze here. The instinct is to wait until you know everything. Do not. Your clients need a short, plain message today, by phone and from a known good channel, telling them not to pay any invoice with changed bank details and to confirm payment instructions by calling a number they already have. We wrote the actual wording in a fraudulent invoice just left your mailbox and what to tell clients today. Being first to warn them protects the relationship. Letting them find out from their own accountant does not.
Finally, find out what the attacker actually saw. That question decides whether you have a notification obligation under Texas law or, for a medical practice, under HIPAA, the federal law that governs patient health information. Answering it properly means reviewing sign-in logs and mailbox activity, which is the work our digital forensics team does. Guessing wrong in either direction is expensive. Over-notifying alarms every patient you have. Under-notifying invites a regulator.
What a North Texas Owner Should Do This Week
None of this requires a large budget. It requires a few habits, put in place before the email arrives.
Start with a call-back rule. Any request to change a vendor's bank details, from any supplier, gets verified by phone using a number from your own records or a past invoice, never a number from the email asking for the change. Write that rule down, tell your billing staff it is not optional, and tell them you will back them up if it delays a payment by a day. Most losses we see happened because one person did not feel allowed to slow down.
Next, review every change to vendor payment records made since August 25. If anyone updated a McKesson record or any other supplier's banking details in that window, confirm the change by phone now. If you buy from McKesson's oncology or medical-surgical lines, watch the mail for a notification letter and keep an eye on your account statements.
Then look at your own email. Turn on multifactor authentication, which means a second proof of identity like a code on a phone in addition to the password, for every mailbox, including the shared billing inbox nobody thinks about. Ask whoever runs your IT to set alerts for new forwarding rules and for sign-ins from unusual locations. Our email security service handles both, and it also flags lookalike sender domains before they reach an employee.
It also helps to know whether your staff addresses are already in circulation. With 6.4 million email addresses reportedly in this one data set, a dark web monitoring check tells you which of your people are most likely to be targeted next, so you can warn them by name rather than sending a generic reminder that everyone ignores.
If you have one IT person, or an outside provider who handles computers and printers but not security incidents, be honest about who answers the phone on a Saturday when a client says your invoice looks strange. A co-managed IT arrangement keeps your current person in place and adds a team that owns the response, so nobody is guessing about whose job it is.
Why This Matters More in Collin County Than It Looks
North Texas has one of the densest concentrations of independent medical practices, specialty clinics and pharmacies in the state, and McKesson is a neighbor, not a distant name. Many of the practices we work with from our office in McKinney and across Plano and Frisco buy through the same handful of national distributors. When one of those distributors has a breach, the local ripple is not theoretical. It lands in accounts payable inboxes in Collin County within weeks.
The businesses that come through these events with no loss are not the ones with the most expensive technology. They are the ones where a billing clerk felt comfortable calling a supplier to double check, and where somebody noticed a strange mailbox rule on a Tuesday instead of a client noticing a missing payment a month later.
If you are not sure where your business stands, our free security assessment looks at your email setup, payment approval process and mailbox rules in plain language. If you think a fake invoice has already gone out or come in, do not wait for a scheduled meeting. Call us at 512-518-4408 or reach us through our contact page, and we will help you work through the first hour.
Frequently Asked Questions
Was my business affected by the McKesson data breach?
McKesson has said the incident appears to involve a subset of customers in its Oncology and Multispecialty and Medical-Surgical business units, and its review is still ongoing. If you buy from those lines, assume your account and contact details could be involved and watch for a notification letter. Either way, treat any request to change McKesson payment details as suspicious until you confirm it by phone.
What should I do if a supplier emails new bank details after a breach?
Do not reply to the email and do not use any phone number it contains. Call the supplier using a number from your own records or a past invoice and confirm the change with someone you know. If the request turns out to be fake, report it to your bank and forward the email to your IT or security provider so they can block the sender.
Can ACH payments to a fraudster be recovered?
Sometimes, but speed decides it. Call your bank immediately and ask them to contact the receiving bank about a recall or reversal, and file a report with the FBI Internet Crime Complaint Center. Payments flagged within the first day or two have a far better chance of being frozen than payments discovered weeks later.
How do I know if someone is inside our company email?
Common signs include replies you never received, clients asking about invoices you did not send, and forwarding rules nobody remembers creating. Check the mailbox rules and recent sign-in locations, or have your IT provider do it today. If you find anything unexpected, reset the password, sign the account out everywhere and get help reviewing what the attacker could read.
Need Help With This?
Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.
Mark Sullivan
Innovation Network Design
With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.
Ready to Secure Your Business?
Get a free security assessment and find out where your organization stands.