In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts.
McKesson - 6,404,340 breached accounts
calendar_today
September 10, 2026
domain
have-i-been-pwned