McKesson Data Leak Includes 6.4M Email Addresses After $55.2M Extortion Demand
McKesson, a major healthcare company, was hacked by ShinyHunters. The attackers stole 6.4 million email addresses and sensitive patient and employee data, then threatened to leak it unless McKesson paid $55.2 million.
- Report priority
- High
What is known
- Attackers tricked McKesson employees into giving them access to company systems.
- They then stole personal data, including patient health records, emails, and employment details, without breaking in directly.
- The stolen data was later leaked online after McKesson refused to pay the $55.2 million ransom demand.
What to do
If you are a McKesson patient, employee, healthcare provider, or marketing contact, check if your email appears in the leaked data by visiting Have I Been Pwned. If your email is listed, your personal and health information may also have been exposed.
If your data is confirmed as leaked, monitor your accounts for suspicious activity. Enable two-factor authentication on all accounts using your email or personal details from the breach. Watch for phishing emails or calls asking for sensitive information. If you suspect fraud, contact McKesson's privacy team or your bank directly for assistance.
Reported details
This incident involves a credential-based attack where the ShinyHunters group allegedly exploited social engineering to compromise McKesson employee accounts, gaining unauthorized access to internal systems. The breach exposed 6.4 million unique email addresses alongside sensitive data, including patient health records (such as cancer treatment details), employee and provider information, appointment notes, and contact details, enabling phishing, identity fraud, and further exploitation. The leaked data does not include Social Security numbers, though ShinyHunters claimed to have stolen them.
The attack highlights a growing trend of trust-based compromises, where attackers bypass traditional security controls by hijacking legitimate user access rather than exploiting software vulnerabilities. No CVE, CVSS, or patched versions were associated with this incident.