McKesson Data Leak Includes 6.4M Email Addresses After $55.2M Extortion Demand

McKesson breach data includes 6.4 million unique email addresses after ShinyHunters allegedly demanded $55.2 million to keep the records private.

Sep 11, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The scale of McKesson’s data breach is becoming clearer — and 284 million stolen records does not necessarily mean 284 million victims.

Have I Been Pwned (HIBP) says the data published following ShinyHunters’ August extortion campaign contains 6.4 million unique email addresses, along with information tied to patients, employees, healthcare providers, and marketing recipients.

The leaked material reportedly includes personal health information as well as contact and employment data, significantly increasing the potential value of the information for phishing, identity fraud, and other follow-on attacks.

How ShinyHunters allegedly got to McKesson’s data

ShinyHunters reportedly began by tricking McKesson employees. That gave the attackers a legitimate-looking foothold, letting them access services available to those employees rather than breaking through McKesson’s systems directly.

As is typical of its pay-or-leak methods, ShinyHunters, a data extortion hacking group, told The Register it demanded $55.2 million to keep the stolen data unpublished. But it now appears that the demand went unmet.

The leaked data include names, email and physical addresses, genders, dates of birth, phone numbers, and employer details. Per The Register, it also includes appointment dates and notes, as well as personal health information like the locations of patients’ cancers because McKesson operates an oncology arm supporting 3,300 oncology providers.

ShinyHunters also alleged it stole Social Security numbers, but such data was missing from what HIBP listed on its site.

The constant exploitation of identity and trust

The McKesson incident reflects a pattern that keeps appearing in major breaches: attackers increasingly target people and trusted access, rather than relying solely on software vulnerabilities. Once an attacker compromises a legitimate account, security tools can struggle to distinguish the attacker from the employee.

That makes identity protection as important as perimeter security, particularly as businesses connect more cloud services.

ShinyHunters has repeatedly used this model. The pattern has also appeared beyond ShinyHunters, touching several enterprise security compromises that make headlines.

That is where the supply-chain risk comes in. A company’s security can be undermined not only through its own employees or systems, but through a trusted third-party service that already has access to its data. When attackers compromise that trust relationship, they can move through an environment and scale their attacks, as seen in the 6.4 million individuals impacted by McKesson.

Advertisement

Here is what you should do

Start by checking the HIBP database to see whether your email address appears in the McKesson breach. Also, if you use multiple email addresses, use this opportunity to check each one to see whether any appear in other breaches.

However, don’t treat an HIBP result as a complete picture of what was exposed. McKesson has said it is still investigating the incident. The company also said it will provide credit monitoring, identity protection, and a dedicated communication channel to those who were affected by the breach. 

Watch McKesson’s official cybersecurity updates and follow any instructions it provides when it begins direct notification.

Until direct notifications arrive, treat unexpected emails, calls, and text messages claiming to come from McKesson, a healthcare provider, insurer, or pharmacy with extra caution.

Names, phone numbers, addresses, and health-related information can make phishing messages unusually convincing. Verify requests through an independently obtained official contact method instead of clicking links or calling numbers supplied in an unsolicited message.

Other news: Researchers uncovered DoppelCart, a massive fake-shopping network spanning more than 119,000 domains that impersonate legitimate brands to steal shoppers’ card details and personal information.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.