Troy Hunt of HaveIBeenPwned has reported that the data allegedly stolen from McKesson included 6.4 million unique email addresses from marketing campaigns, patients, staff members, and other individuals.
ShinyHunters added McKesson to its data leak site, and the listing claims that 284 million patient data records were exfiltrated.
McKesson announced the incident on August 28, 2026, explaining that an investigation had been launched following “a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data.”
According to the SEC filing, the cybersecurity incident was first detected on August 25, 2026.
ShinyHunters claims that the stolen data includes names, contact information, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, medication/allergy information, diagnoses, appointment information, and other sensitive data.