← Back to Home

McKesson Data Breach

Verified Breach Sensitive
Aug 20, 2026 Breach Date
6,404,340 Accounts Affected
8 Data Types Exposed
Sep 10, 2026 Added to HIBP
About This Breach
In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice, the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".
Compromised Data Types
Dates of birth Email addresses Employers Genders Names Personal health data Phone numbers Physical addresses
Check If You Were Affected

Were you part of the McKesson breach?

~ digitalchk / breach check

Has your email been exposed in a breach?