In August 2026, healthcare and pharmaceutical giant McKesson was hit by a ShinyHunters “pay or leak” extortion campaign. The attackers later released a large corpus of data they attributed to the company, containing roughly 6.4 million unique email addresses plus additional personal and corporate attributes. The exposed records span marketing recipients, patients, staff, and healthcare provider contacts.
McKesson’s own disclosure attributed the incident to unauthorized access to certain third-party applications and data exfiltration tied to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units, while stating it had reasonable assurance of no ongoing unauthorized activity.
What to take away: breaches involving exposed corporate email addresses and staff contact data feed directly into credential-stuffing, phishing, and targeted social-engineering campaigns against identity systems. Organizations connected to McKesson should watch for follow-on phishing, enforce MFA, and audit access to third-party integrations that can serve as an initial foothold.