McKesson
mckesson.com
About This Breach
McKesson, a healthcare and pharmaceutical company, was targeted by the ShinyHunters group in August 2026, with data later published online exposing 6.8M unique email addresses along with other personal and corporate information relating to patients, staff, healthcare provider contacts, and marketing recipients.
Data Exposed
Breach Details
| Breach Type | Data Breach |
| Searchable | Yes |
| Verified | Yes |
| Sensitive Data | No |
| Reference | No reference available |
Frequently Asked Questions
When did the McKesson data breach happen?
McKesson was breached in Aug 2026. The breach was added to the XposedOrNot index on October 2, 2026.
How many records were exposed in the McKesson breach?
6,832,822 records were exposed, making it the #167 largest of the 787 breaches in our index.
What data was exposed in the McKesson breach?
The exposed data includes: Email addresses, Names, Phone numbers, Physical addresses, Dates of birth, Genders.
What should I do if I was affected by the McKesson breach?
Change your password on the affected service (and anywhere you reused it), turn on two-factor authentication, and set up free breach alerts on XposedOrNot so you know the moment your email appears in a new breach.
Recently Added Breaches
What Should You Do?
Enable Two-Factor Authentication
Add 2FA on all supported accounts using an authenticator app like Google Authenticator or Authy.
Watch for Phishing Calls & SMS
Be cautious of unexpected calls or texts asking for personal information.
Beware of Scam Mail
Be skeptical of unexpected correspondence requesting personal details.
Monitor Your Accounts
Set up login alerts and review account activity regularly for suspicious access.