McKesson Hit by ShinyHunters Extortion Campaign, 6.4M Emails Leaked
In a recent cybersecurity incident, healthcare giant McKesson was targeted in an extortion campaign by the threat actor group ShinyHunters last month. The breach resulted in the exposure of 6.4 million email addresses, including those from marketing campaigns, patients, and staff.
The leaked data was subsequently published, with 66% of the exposed emails already linked to LinkedIn profiles and third-party services. While the full scope of the breach remains under investigation, the incident highlights the ongoing risks of data extortion and the potential for widespread exposure of sensitive information.
McKesson, a major player in healthcare distribution and services, has not yet issued a detailed public statement on the breach’s impact or mitigation efforts. The incident underscores the persistent threat posed by cybercriminal groups like ShinyHunters, which frequently target large organizations for financial gain.
Source: https://www.linkedin.com/feed/update/urn:li:activity:7503692380789760000
McKesson cybersecurity rating report: https://www.rankiteo.com/company/mckesson
"id": "MCK1789021407",
"linkid": "mckesson",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Patients, staff, and marketing '
'campaign recipients',
'industry': 'Healthcare',
'name': 'McKesson',
'size': 'Large',
'type': 'Healthcare distribution and services'}],
'data_breach': {'data_exfiltration': 'Published',
'number_of_records_exposed': '6.4 million',
'personally_identifiable_information': 'Email addresses',
'sensitivity_of_data': 'Moderate (66% linked to LinkedIn '
'profiles and third-party services)',
'type_of_data_compromised': 'Email addresses'},
'description': 'In a recent cybersecurity incident, healthcare giant McKesson '
'was targeted in an extortion campaign by the threat actor '
'group ShinyHunters last month. The breach resulted in the '
'exposure of 6.4 million email addresses, including those from '
'marketing campaigns, patients, and staff. The leaked data was '
'subsequently published, with 66% of the exposed emails '
'already linked to LinkedIn profiles and third-party services. '
'While the full scope of the breach remains under '
'investigation, the incident highlights the ongoing risks of '
'data extortion and the potential for widespread exposure of '
'sensitive information.',
'impact': {'brand_reputation_impact': 'Potential widespread exposure of '
'sensitive information',
'data_compromised': '6.4 million email addresses'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain',
'threat_actor': 'ShinyHunters',
'title': 'McKesson Hit by ShinyHunters Extortion Campaign, 6.4M Emails Leaked',
'type': 'Extortion'}