McKesson breach listed 6.4M email addresses

Published September 10, 2026

McKesson had customer data stolen in a breach affecting 6.4M accounts. The exposed data included Dates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, Physical addresses.

Report priority
High
Involves
McKesson

What is known

ShinyHunters stole and leaked data from McKesson.

What to do

Search your email address in Have I Been Pwned for the McKesson breach. If it appears, treat Dates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, Physical addresses as exposed.

Follow McKesson notices, watch health insurance and identity records for misuse, and replace any reused password tied to the exposed email address.

Reported details

Have I Been Pwned lists the McKesson breach as affecting 6.4M accounts. It attributes the incident to a ShinyHunters pay-or-leak extortion campaign. The listed data classes are Dates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, Physical addresses.