← Knowledge Center
Breach

McKesson breach exposes 6.4M accounts in ShinyHunters extortion campaign

In August 2026, healthcare and pharmaceutical giant McKesson was hit by a ShinyHunters “pay or leak” extortion campaign. The attackers later released a large corpus of data they attributed to the company, containing roughly 6.4 million unique email addresses plus additional personal and corporate attributes. The exposed records span marketing recipients, patients, staff, and healthcare provider contacts.

McKesson’s own disclosure attributed the incident to unauthorized access to certain third-party applications and data exfiltration tied to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units, while stating it had reasonable assurance of no ongoing unauthorized activity.

What to take away: breaches involving exposed corporate email addresses and staff contact data feed directly into credential-stuffing, phishing, and targeted social-engineering campaigns against identity systems. Organizations connected to McKesson should watch for follow-on phishing, enforce MFA, and audit access to third-party integrations that can serve as an initial foothold.

Primary source

Have I Been Pwned

Read at haveibeenpwned.com ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.