McKesson - 6,404,340 breached accounts
Brief
In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6. 4M unique email addresses among other personal and corporate data attributes.
The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts.
In McKesson's disclosure notice , the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".
