// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-hibpDTG 0600Z
ColdRecon / Breach Radar / McKesson
Breach Record

McKesson

DISCLOSED 2026-08-21 · STOLEN CREDS · 6,404,340 RECORDS EXPOSED

In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of...

The record

What we know

Disclosed
2026-08-21
Attack vector
Stolen Creds
Records exposed
6,404,340
Domain
mckesson.com
Data classes exposed
Dates of birthEmail addressesEmployersGendersNamesPersonal health dataPhone numbersPhysical addresses
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the McKesson disclosure. It updates if new public reporting emerges. All tracked breaches →

McKesson just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →