Breach Database / McKesson

Yes — McKesson was breached.

What happened

In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice, the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".

What data was exposed

What to do right now

  1. Be alert for smishing and SIM-swap attempts. Treat unexpected texts and "carrier" calls with suspicion; add a PIN/port-freeze with your mobile carrier.
  2. Watch for targeted phishing mail. A leaked home address makes postal and doorstep scams more convincing.
  3. Expect convincing phishing emails. Attackers use breached details to write personalized emails. Be suspicious of any message referencing this service.
  4. Check your other accounts on Have I Been Pwned. Your email address may appear in other breaches you don't know about yet.
  5. Monitor the apps you use going forward. Clearly watches the breach record for the companies behind your apps and alerts you the moment one appears.

Breach data from Have I Been Pwned. Listing here means the service appears in the public breach record — not that your personal data was affected.