McKesson Exposes 6.4 M Email Addresses in ShinyHunters Extortion Breach
What Happened — In August 2026, the ShinyHunters extortion group accessed “certain third‑party applications” used by McKesson and exfiltrated data covering 6,404,340 unique email addresses, dates of birth, health information and other personal attributes. The group later published the data in a “pay‑or‑leak” campaign.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of inadequate third‑party application oversight – a core control‑area that continuous assurance programs must monitor and evidence.
- Highlights the need for real‑time detection of unauthorized access and a defensible audit trail showing that no further activity is occurring.
- Aligns with Verisq’s Vendor Risk Management capability, which provides continuous monitoring and evidence collection for third‑party access controls.
Who Is Affected – Healthcare and pharmaceutical providers, their patients, staff, marketing contacts and any business partners whose data were stored in the compromised applications.
Recommended Actions
- Conduct an immediate third‑party risk review of all applications that integrate with McKesson systems.
- Deploy continuous monitoring of vendor access logs and enforce least‑privilege principles.
- Document remediation steps and collect evidence to satisfy audit requirements for data‑handling controls.
Source: Have I Been Pwned – McKesson Breach
Technical Notes – The breach stemmed from unauthorized access to third‑party SaaS tools used by McKesson’s Oncology, Multispecialty and Medical‑Surgical units. No specific CVE was disclosed; the attack vector appears to be credential compromise or mis‑configured vendor access. Data types leaked include email addresses, dates of birth, health information, phone numbers and physical addresses. Source: same as above