NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

McKesson Cyberattack: Stolen Data Includes 6.4 Million Unique Email Addresses

McKesson, a major U.S. wholesale medical supplies & equipment, pharmaceutical distribution, and healthcare technology solutions company, continues to investigate a cybersecurity incident involving unauthorized access and the exfiltration of sensitive data.

The number of individuals affected has yet to be determined; however, on September 8, 2026, McKesson issued an update on the initial findings of its investigation. While the investigation and data review are ongoing, McKesson has confirmed that the information potentially exfiltrated likely included personal and protected health information such as names, addresses, phone numbers, email addresses, patient IDs, and dates of birth, along with one or more of the following data elements:

  • Health insurance information (including Medicaid/Medicare ID numbers)
  • Health and medical information (including dates of service, medical record numbers, providers, diagnoses, medications, test results, medical images, and care/treatment information)
  • Billing, claims and payment information (including claim numbers, account numbers, billing codes, credit/debit card numbers, financial/banking information), payments made, and balances due)
  • Other personal information used to verify identity, such as Social Security numbers.

McKesson said it has implemented additional cybersecurity measures to prevent similar breaches in the future and has engaged third-party cybersecurity experts to monitor its systems, the internet, and other sources for activity related to the incident.

The ShinyHunters threat group claimed responsibility for the attack and, as reported below, claimed to have obtained 284 million rows of raw patient data, but that total was unlikely to relate to 284 million unique patients. While the company has yet to publicly disclose the scale of the data breach, that is now becoming clearer.  Troy Hunt of HaveIBeenPwned has reported that the data allegedly stolen from McKesson included 6.4 million unique email addresses from marketing campaigns, patients, staff members, and other individuals.

August 31, 2026: ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson

The healthcare giant McKesson recently disclosed a cyberattack in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC).  While the investigation is still in its early stages, McKesson has confirmed that data was exfiltrated, although the extent of data theft has yet to be determined.

McKesson is a large, publicly traded U.S. healthcare and pharmaceutical company that supplies hospitals, health systems, pharmacies, and physician offices with medications, medical-surgical equipment, and specialized oncology and prescription technology solutions. McKesson has not disclosed the name of the group behind the attack, but it appears to be the ShinyHunters extortion group. ShinyHunters added McKesson to its data leak site, and the listing claims that 284 million patient data records were exfiltrated. The claim of 284M patient records relates to rows of raw data, not unique patients. Even so, this is clearly a significant data breach.

McKesson announced the incident on August 28, 2026, explaining that an investigation had been launched following “a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data.” Incident response protocols were activated, and leading cybersecurity experts were engaged to assist with the company’s response. The McKesson cybersecurity team and third-party experts are working to minimize the impact on system availability, determine the nature and scope of the unauthorized activity, and the extent of data theft. Customers have been warned that there may be an impact on system availability and business operations, including intermittent service degradation.

McKesson said it does not believe that customers need to take any action, and that the company is not proactively disconnecting systems within its environment. In an August 29 update, McKesson said the company continues to serve customers across all lines of business, orders are being accepted, and its distribution centers remain open, with products continuing to be shipped across its distribution network.

Based on early investigation results, McKesson said the incident appears to involve data relating to a subset of customers of its Oncology & Multispecialty and Medical-Surgical business units. The initial actions to prevent further unauthorized access appear to have been successful, with no further unauthorized activity detected. According to the SEC filing, the cybersecurity incident was first detected on August 25, 2026. The company has yet to determine whether the incident is material and will have a material impact on the company, its financial condition, or the results of operations.

ShinyHunters is a prolific threat group that engages in data theft and extortion, typically gaining access to victims’ systems through voice phishing/vishing and social engineering. Previous healthcare victims include Medtronic, Abbott Laboratories, iRhythm, AdaptHealth, and DentaQuest. In the past few days, ShinyHunters also claimed responsibility for a data theft incident at Baxter International.

According to BleepingComputer, which has been in contact with the group, around 1 terabyte of data was exfiltrated between August 21 and August 25, 2026, and a ransom demand of more than $55 million was issued. ShinyHunters claims that the stolen data includes names, contact information, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, medication/allergy information, diagnoses, appointment information, and other sensitive data. The data appears to relate to its Salesforce environment and Snowflake.

This article has been corrected since publication, as it erroneously stated that ShinyHunters was linked to the incident at Boston Scientific. 

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist