Healthcare and pharmaceutical distributor McKesson disclosed that unauthorized actors accessed certain third-party applications and exfiltrated data affecting a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. The incident was linked to a purported ShinyHunters “pay or leak” extortion campaign, in which the group allegedly published data after McKesson did not pay.
The published dataset reportedly contains 6.4 million unique email addresses alongside personal and corporate information involving marketing recipients, patients, employees, and healthcare-provider contacts. McKesson said it had reasonable assurance that unauthorized activity was no longer ongoing, while affected organizations should assess potential phishing, credential-stuffing, and impersonation risk arising from the exposed contact data.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
In August 2026, ShinyHunters targeted healthcare and pharmaceutical company McKesson in a purported pay-or-leak extortion campaign. McKesson later identified unauthorized access to certain third-party applications and data exfiltration affecting subsets of customers in its Oncology & Multispecialty and Medical-Surgical units.
Have I Been Pwned added data allegedly leaked from the McKesson incident, providing the first reported estimate that roughly 6.4 million individuals were affected. ShinyHunters also claimed it stole 284 million documents, a claim not independently verified by McKesson.
ShinyHunters allegedly published a dataset claimed to have been taken from McKesson after the company reportedly did not pay. The dataset reportedly included 6.4 million unique email addresses and personal and corporate data relating to marketing recipients, patients, staff, and healthcare-provider contacts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcehaveibeenpwned.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.