The scale of McKesson’s data breach is becoming clearer — and 284 million stolen records does not necessarily mean 284 million victims.
Have I Been Pwned (HIBP) says the data published following ShinyHunters’ August extortion campaign contains 6.4 million unique email addresses, along with information tied to patients, employees, healthcare providers, and marketing recipients.
The leaked material reportedly includes personal health information as well as contact and employment data, significantly increasing the potential value of the information for phishing, identity fraud, and other follow-on attacks.
How ShinyHunters allegedly got to McKesson’s data
ShinyHunters reportedly began by tricking McKesson employees. That gave the attackers a legitimate-looking foothold, letting them access services available to those employees rather than breaking through McKesson’s systems directly.
As is typical of its pay-or-leak methods, ShinyHunters, a data extortion hacking group, told The Register it demanded $55.2 million to keep the stolen data unpublished. But it now appears that the demand went unmet.
The leaked data include names, email and physical addresses, genders, dates of birth, phone numbers, and employer details. Per The Register, it also includes appointment dates and notes, as well as personal health information like the locations of patients’ cancers because McKesson operates an oncology arm supporting 3,300 oncology providers.
ShinyHunters also alleged it stole Social Security numbers, but such data was missing from what HIBP listed on its site.
The constant exploitation of identity and trust
The McKesson incident reflects a pattern that keeps appearing in major breaches: attackers increasingly target people and trusted access, rather than relying solely on software vulnerabilities. Once an attacker compromises a legitimate account, security tools can struggle to distinguish the attacker from the employee.
That makes identity protection as important as perimeter security, particularly as businesses connect more cloud services.
ShinyHunters has repeatedly used this model. The pattern has also appeared beyond ShinyHunters, touching several enterprise security compromises that make headlines.
That is where the supply-chain risk comes in. A company’s security can be undermined not only through its own employees or systems, but through a trusted third-party service that already has access to its data. When attackers compromise that trust relationship, they can move through an environment and scale their attacks, as seen in the 6.4 million individuals impacted by McKesson.
Here is what you should do
Start by checking the HIBP database to see whether your email address appears in the McKesson breach. Also, if you use multiple email addresses, use this opportunity to check each one to see whether any appear in other breaches.
However, don’t treat an HIBP result as a complete picture of what was exposed. McKesson has said it is still investigating the incident. The company also said it will provide credit monitoring, identity protection, and a dedicated communication channel to those who were affected by the breach.
Watch McKesson’s official cybersecurity updates and follow any instructions it provides when it begins direct notification.
Until direct notifications arrive, treat unexpected emails, calls, and text messages claiming to come from McKesson, a healthcare provider, insurer, or pharmacy with extra caution.
Names, phone numbers, addresses, and health-related information can make phishing messages unusually convincing. Verify requests through an independently obtained official contact method instead of clicking links or calling numbers supplied in an unsolicited message.
Other news: Researchers uncovered DoppelCart, a massive fake-shopping network spanning more than 119,000 domains that impersonate legitimate brands to steal shoppers’ card details and personal information.





