
What was exposed, when it happened, and which databases confirm it.
- accounts
- 6,404,340
- Breached
- August 21, 2026
- Last Update
- September 10, 2026
Were you caught in this breach?
Search your email, phone number or username against every record CheckLeaked indexes.
What happened
In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice, the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".
Compromised Info
- Dates of birth
- Email addresses
- Employers
- Genders
- Names
- Personal health data
- Phone numbers
- Physical addresses
Attestation
Four independent databases catalog this breach and they do not always agree. Each lane below is one source’s own count.
Sources & Link Methods
- HIBP
FAQ
What was leaked in the McKesson breach?
The McKesson breach exposed: Dates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, and Physical addresses.
When did the McKesson breach happen?
The McKesson breach was disclosed on August 21, 2026 and affected 6,404,340 records.
Am I affected by the McKesson breach?
Search your email, phone or username at checkleaked.cc to find out whether your data appears in the McKesson leak.