Compliance · · 3 min read
McKesson breach linked to 6.4 million unique email addresses
McKesson says an investigation is continuing after attackers accessed and removed data that may include personal and protected health information.
McKesson is investigating a cyberattack in which an unauthorized party accessed its systems and exfiltrated data, with early findings indicating that information from some customers may have been taken. The company has not yet established how many individuals were affected or whether the incident will have a material financial impact.
In an update issued on September 8, 2026, McKesson said the potentially stolen information may include names, home and email addresses, telephone numbers, patient identification numbers and dates of birth. The company also said the data may contain additional medical or identity-related details, although its review is not complete.
The scale of the incident is beginning to emerge. Troy Hunt of HaveIBeenPwned reported that data allegedly taken from McKesson contained 6.4 million unique email addresses. Those addresses reportedly came from marketing campaigns, patients, employees and other people. The figure does not establish that 6.4 million patients were affected, and McKesson has not published a final count of impacted individuals.
What McKesson has disclosed
McKesson first announced the incident on August 28, after detecting the activity on August 25, according to a filing with the US Securities and Exchange Commission. The company said the event involved third-party applications, unauthorized access and the removal of data.
The investigation is focused on identifying how the attackers entered, what information they obtained and the full scope of the activity. McKesson has brought in outside cybersecurity specialists, activated its incident-response procedures and added measures intended to prevent a recurrence. It is also monitoring its systems, the internet and other sources for signs connected with the attack.
The company’s preliminary assessment points to information associated with a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. McKesson said the steps taken to block further access appear to have worked, with no additional unauthorized activity detected so far.
Operations have continued. In an August 29 update, McKesson said its customers could still place orders, distribution centers remained open and products were continuing to move through its network. The company warned, however, that systems could experience intermittent degradation and that business operations might be affected. It has said customers do not currently need to take action and that it is not proactively disconnecting systems in its environment.
Claims about the stolen records
The ShinyHunters extortion group has claimed responsibility and listed McKesson on its data-leak site. The group said it obtained 284 million patient-data records. That number refers to raw rows of data rather than confirmed unique patients, so it cannot be treated as the number of people exposed.
BleepingComputer, as reported by HIPAA Journal, said it had been in contact with the group and that approximately one terabyte of material was allegedly removed between August 21 and August 25, 2026. ShinyHunters reportedly demanded more than $55 million.
The group has claimed that the material includes names, contact details, Social Security numbers, birth dates, medical record numbers, Medicaid numbers, medication and allergy information, diagnoses and appointment details. The data appears to be connected to McKesson’s Salesforce environment and Snowflake. These claims have not been presented by McKesson as a completed, verified account of the breach; the company’s examination is still underway.
Why the incident matters
McKesson is a major publicly traded healthcare and pharmaceutical company. It supplies medicines and medical-surgical products to hospitals, health systems, pharmacies and doctors’ offices, and also provides oncology and prescription-technology services. A breach affecting its systems therefore raises concerns beyond ordinary contact information, particularly because the reported data may include protected health information.
ShinyHunters has previously pursued healthcare organizations through data theft and extortion. Its earlier claimed victims include Medtronic, Abbott Laboratories, iRhythm, AdaptHealth and DentaQuest. The group has also claimed responsibility for a separate incident involving Baxter International in recent days.
McKesson has not officially identified the attackers. The company also has not determined whether the incident is material under securities-reporting requirements. Its investigation and data review will need to establish which records were involved, how many people they relate to and whether any additional disclosures or measures are required.