McKesson Data Breach: 6.4 Million Email Addresses Are Out. What Do You Do Now?

McKesson Data Breach: 6.4 Million Email Addresses Are Out. What Do You Do Now?

Somewhere in this file is a woman who finished treatment at a cancer clinic last year. Her name, her email address, her date of birth, her phone number and her home address sit in one row, and by the attackers’ account so do her diagnosis and her medication list. The next email she gets “from her clinic” about a billing problem or a prescription change will know things she has told nobody but her doctor. She has probably not heard of McKesson. McKesson supplies her clinic.

Confirmation: confirmed by the company. McKesson told the SEC and its customers that an unauthorised party accessed third-party applications and took data. The 6.4 million figure is Have I Been Pwned’s count of unique email addresses in the data the attackers published. The larger figures in circulation are the attackers’ claims and are disputed.

What happened

On 10 September 2026, Have I Been Pwned loaded 6,404,340 email addresses from data the ShinyHunters group published after McKesson declined to pay a ransom. McKesson is one of the largest distributors of medicines and medical supplies in the United States, and the affected units serve oncology and specialty clinics and medical-surgical customers.

The timeline, from BleepingComputer’s reporting and McKesson’s own notices:

  • 21 to 25 August. By the attackers’ account, they phoned McKesson employees while posing as the company, using a lookalike domain, and talked their way into single sign-on accounts. From there they say they pulled about 1TB of data out of cloud applications over four days. McKesson has confirmed unauthorised access to “certain third-party applications” but has not named which ones.
  • 25 August. McKesson says it discovered the intrusion.
  • 28 and 29 August. McKesson posted a notice and an update for customers, describing “the exfiltration of certain data” tied to “a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units,” and said it had “reasonable assurance of no ongoing unauthorized activity.” In its SEC filing it said it had not yet determined the incident to be material.
  • 31 August. TechCrunch reported the attackers’ claim of millions of rows of patient data. McKesson’s spokesperson would not say how many people were affected.
  • After the deadline passed. The attackers demanded a ransom of roughly fifty-five million US dollars with a 72-hour deadline. McKesson did not respond, and the group published the data.
  • 10 September. Have I Been Pwned added the data set, verified, with 6.4 million unique email addresses.

The count is disputed. Early reporting repeated a figure of 284 million “patient records.” The attackers later clarified that this is a count of rows, not people, and that they do not know how many individuals are in the data. Have I Been Pwned’s 6.4 million is a count of distinct email addresses, and it includes marketing campaign recipients, staff and healthcare provider contacts as well as patients. Neither number is a confirmed count of patients, and McKesson has not published one.

McKesson says it will offer complimentary credit monitoring and identity protection services and a dedicated information line, with updates at McKesson.com/cybersecurity.

What was exposed

Have I Been Pwned lists names, email addresses, dates of birth, genders, employers, phone numbers, physical addresses and personal health data in the published files. The attackers claim more, and reporters who saw samples describe Social Security numbers, patient and medical record numbers, Medicaid numbers, medication and allergy lists, appointment records, prescriptions and physician details. Treat the first list as confirmed and the second as likely for some people in the file.

What each item is worth to a criminal:

  • Your email address plus your clinic. A generic “your account has a problem” email is easy to ignore. One that names your oncology practice, your medication or your appointment date is not. This is the value of the file.
  • Your date of birth, address and phone number. The identity checks most call centres use. Together with a Social Security number, enough to open credit or file a fraudulent tax return.
  • Your health data. A fake bill, a fake prescription refill, a fake insurer letter, each written with details that make it read as real. It also does not expire the way a password does.
  • A Social Security number, if yours is in the claimed data. Long-term identity theft. A credit freeze answers most of it, and it is free.

No passwords leaked here. Have I Been Pwned does not list them, and McKesson’s applications held records, not logins. So the risk is not that someone can walk into your accounts with this file. It is that someone will use it to talk you into opening the door.

What to do now

Most of this has nothing to do with OptMsg, and most of it takes an evening.

1. Check whether your address is in it. Search your email address at haveibeenpwned.com. The McKesson entry is listed there as of 10 September. 2. Expect the follow-up phish to look like your clinic, your pharmacy, your insurer or McKesson. A bill, a prescription change, a “your data was in a breach, click to enrol in credit monitoring.” Do not follow links in them. Go to the clinic’s website or phone the number on your paperwork. McKesson’s real credit monitoring offer will be at McKesson.com/cybersecurity and through its information line, not a link in an email. 3. Freeze your credit at Equifax, Experian and TransUnion. It costs nothing, it takes about fifteen minutes, and it stops a new account being opened in your name with a leaked Social Security number. Lift it when you need to apply for something. 4. Read the explanation-of-benefits statements from your insurer. A claim for a visit you did not make is medical identity theft, and it shows up there first. 5. Turn on the strongest sign-in each account offers, starting with your email account. It is the reset route into your patient portal, your bank and everything else. A passkey where available, an authenticator app otherwise, and a password manager so every account has its own password. 6. Expect the phone to ring. Your number is in the file. Your clinic does not need your date of birth read back to it by text. 7. If you have already clicked or shared anything, change the password on the account concerned from a device you trust, then check its sign-in history.

How OptMsg changes this exposure

Honestly, and at its real size: OptMsg would not have prevented this breach. It happened at McKesson, in applications McKesson’s staff were tricked into opening. What an opt-in inbox changes is what happens to you next.

Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. OptMsg’s patent-pending opt-in technology means the fake “billing problem” email from a lookalike domain lands in Trash, where you are not reading it under time pressure. Your real clinic reaches your Inbox because you approved it as a sender. Only people you approve can reach your inbox. Everyone else goes to Trash. And if a message in Trash comes from a sender many other OptMsg users have opted in to, you get a push alert so that a genuine message is not lost.

Then the password point, which is smaller here than usual because no password leaked. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. When someone pairs an email address from this file with a password from some older breach and tries it against the inbox, the pair opens nothing at OptMsg, because there is no password on the account to match. That is what keeps the reset route into your other accounts shut.

What that does not cover: a text or a phone call to your number, a phishing page you open yourself, a leaked Social Security number, or someone with your unlocked phone. Those are the steps above.

If you want the next breach’s follow-up mail to land in Trash instead of in front of you, see how Simple by Design works, or read why your inbox should not care about a leaked password.

Ready for an inbox that stays quiet after a breach? Create Your Account.

Your Inbox. Your Rules.

Frequently asked questions

How do I know if I am in the McKesson data breach? Search your email address at haveibeenpwned.com. The McKesson data set was added on 10 September 2026 with 6.4 million addresses. McKesson has not published a list of affected clinics or a count of patients, and says it will offer credit monitoring and an information line through McKesson.com/cybersecurity.

Was my Social Security number exposed? Possibly. Have I Been Pwned confirms names, email addresses, dates of birth, phone numbers, addresses and health data. Social Security numbers are in the attackers’ claim and in samples reporters saw, but not in the verified list. A free credit freeze covers the risk either way.

Were passwords leaked in the McKesson breach? No. The published data holds records, not logins. The risk is phishing and identity theft, not someone signing in to your accounts with a leaked password.

Is the 284 million figure right? No. The attackers said it is a count of rows, not people, and that they do not know how many individuals are in the data. Have I Been Pwned counts 6.4 million distinct email addresses, which include staff and provider contacts as well as patients.

Would OptMsg have stopped this? No. The breach happened at McKesson. What OptMsg changes is the aftermath: unapproved senders go to Trash rather than your Inbox, and there is no password on an OptMsg account for a leaked credential to match.

Sources

Scroll to Top