HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

McKesson Exposes 6.4 M Email Addresses in ShinyHunters Extortion Breach

In August 2026 ShinyHunters accessed third‑party applications used by McKesson and leaked over 6 million email addresses and health‑related data. The breach underscores the importance of continuous third‑party risk monitoring for audit readiness.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 haveibeenpwned.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
haveibeenpwned.com

McKesson Exposes 6.4 M Email Addresses in ShinyHunters Extortion Breach

What Happened — In August 2026, the ShinyHunters extortion group accessed “certain third‑party applications” used by McKesson and exfiltrated data covering 6,404,340 unique email addresses, dates of birth, health information and other personal attributes. The group later published the data in a “pay‑or‑leak” campaign.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of inadequate third‑party application oversight – a core control‑area that continuous assurance programs must monitor and evidence.
  • Highlights the need for real‑time detection of unauthorized access and a defensible audit trail showing that no further activity is occurring.
  • Aligns with Verisq’s Vendor Risk Management capability, which provides continuous monitoring and evidence collection for third‑party access controls.

Who Is Affected – Healthcare and pharmaceutical providers, their patients, staff, marketing contacts and any business partners whose data were stored in the compromised applications.

Recommended Actions

  • Conduct an immediate third‑party risk review of all applications that integrate with McKesson systems.
  • Deploy continuous monitoring of vendor access logs and enforce least‑privilege principles.
  • Document remediation steps and collect evidence to satisfy audit requirements for data‑handling controls.

Source: Have I Been Pwned – McKesson Breach

Technical Notes – The breach stemmed from unauthorized access to third‑party SaaS tools used by McKesson’s Oncology, Multispecialty and Medical‑Surgical units. No specific CVE was disclosed; the attack vector appears to be credential compromise or mis‑configured vendor access. Data types leaked include email addresses, dates of birth, health information, phone numbers and physical addresses. Source: same as above

📰 Original Source
https://haveibeenpwned.com/Breach/McKesson

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →