ConfirmedData breach

McKesson: a data breach

In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice , the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".

The record

Organisation
McKesson
Identity
McKessonidentified by its domain in a verified breach record
Records affected
6,404,340 records
Data exposed
Dates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, Physical addresses
Sector
Not recorded
Occurred
2026-08-21
Disclosed
2026-09-10
First recorded here
2026-09-10

Sources (1)

One source so far.

  1. Have I Been PwnedFirst reported

    2026-09-10