BREACH

HIBP puts a number on McKesson: 6.4M emails. Company victim headcount: Undisclosed.

Have I Been Pwned added McKesson on Sep 10 from a ShinyHunters leak corpus. McKesson’s own notice confirms an August incident and possible PHI — it has not confirmed the 6.4M figure.

Sep 10, 2026 · 3 min read

Have I Been Pwned listed McKesson on September 10, 2026 with 6.4 million unique email addresses, breach dated August 2026, sourced from a ShinyHunters “pay or leak” dump. HIBP’s compromised-data list covers names, emails, physical addresses, phones, dates of birth, genders, employers, and personal health data. Roles in the corpus, per HIBP: marketing recipients, patients, staff, and healthcare-provider contacts. CyberMerge prints the HIBP email count as 6.4M and the company-confirmed individual headcount as Undisclosed — McKesson has not published that number.

McKesson’s substitute notice (posted September 8) says it learned of a cybersecurity incident on August 25 targeting employee corporate accounts, with unauthorized activity between August 20 and August 25. The company says the review involves third-party applications and that exfiltrated data was associated with a subset of customers in Oncology & Multispecialty and Medical-Surgical units; it offers two years of credit monitoring and says law enforcement was notified. Possible data types in the company notice include identifiers, health insurance, medical, and billing fields — scope per person still under review.

Attribution sheet — sourced only: HIBP 6.4M emails / added Sep 10 / Aug 2026 breach window; ShinyHunters as HIBP’s attributed source; Register reports ShinyHunters claimed ~284M documents and a $55.2M extortion ask (attacker claim — not company-confirmed); HIBP did not list SSNs even though ShinyHunters claimed them. McKesson-confirmed victim total: Undisclosed. Primary links: HIBP McKesson breach page + McKesson Notice of Data Breach.

Sources