McKesson: a data breach
In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice , the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".
The record
- Organisation
- McKesson →
- Identity
- McKessonidentified by its domain in a verified breach record
- Records affected
- 6,404,340 records
- Data exposed
- Dates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, Physical addresses
- Sector
- Not recorded
- Occurred
- 2026-08-21
- Disclosed
- 2026-09-10
- First recorded here
- 2026-09-10
Sources (1)
One source so far.
- Have I Been Pwned ↗First reported
2026-09-10