McKesson data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
McKesson, the healthcare and pharmaceutical distributor, said an unauthorized party accessed certain third-party applications and took data tied to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. According to its Notice of Data Breach, the activity ran from August 20 to August 25, 2026 and was discovered on August 25. McKesson disclosed the incident in an SEC Form 8-K on August 28, 2026, saying it had not determined the incident was material.
The ShinyHunters extortion group claimed the attack and demanded a ransom. The group says it got in through voice phishing and compromised employee single sign-on accounts; McKesson has said only that the attack targeted employee corporate accounts. After McKesson did not pay, the group published the data. On September 10, 2026, Have I Been Pwned reported that the leak contained 6,404,340 unique email addresses belonging to marketing contacts, patients, staff, and healthcare providers.
McKesson's September 8 notice says affected patients and guarantors (people responsible for a patient's bill) may have had Social Security numbers, health insurance details, medical information, and billing data exposed. McKesson has not published a total count of affected people. The 6.4 million figure counts email addresses in the leak, not confirmed individuals.
Sources
- Notice of Data Breach, McKesson
- Customer Cybersecurity Information Center, McKesson
- McKesson Corporation Form 8-K, August 28, 2026, U.S. Securities and Exchange Commission
- McKesson discloses breach after ShinyHunters claims patient data theft, BleepingComputer
- ShinyHunters expose 6.4M in attack on medical supplier McKesson, The Register
- Have I Been Pwned: McKesson Data Breach
What data was exposed
The following types of personal data were compromised:
- Names
- Email addresses
- Phone numbers
- Physical addresses
- Dates of birth
- Genders
- Employers
- Patient ID numbers
- Health insurance information
- Medical information, such as diagnoses, test results, and treatment
- Billing and payment information
- Social Security numbers (listed as possibly involved in McKesson's notice)
Breach details
| Detail | Value |
|---|---|
| Breach name | McKesson |
| Date | August 20 to 25, 2026 |
| Disclosed | August 28, 2026 (SEC Form 8-K); individual notices from September 8, 2026 |
| Accounts affected | 6,404,340 unique email addresses in the leaked data |
| Domain | mckesson.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by McKesson; it reflects a publicly reported security incident.
For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.
What to do now
Based on the data exposed in this breach, here are the steps you should take:
- If you received a McKesson notice, enroll in the 24 months of free credit monitoring it offers, using the enrollment details in your letter.
- Place a free credit freeze with Equifax, Experian, and TransUnion. McKesson's notice lists Social Security numbers among the data that may have been involved.
- Review Explanation of Benefits statements and provider bills for oncology, specialty, or medical supply charges you don't recognize.
- Treat emails, texts, or calls about McKesson, your treatment, or a "billing update" as possible phishing. The leak pairs names and contact details with health information, which makes scams sound informed.
- For questions, call McKesson's call center at 1-855-760-5202 (Monday to Friday, 9am to 9pm ET) rather than a number from an unexpected message.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- Got a breach email?
- First 48 hours after a data breach
- Dark web vs. data brokers
- What to do after a data breach
- AdaptHealth breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.