MCKESSON’S cyberattack, disclosed on 10 September 2026, is reported by Have I Been Pwned (HIBP) to have affected roughly 6.4 million individuals. HIBP’s assessment followed data leakage attributed to the serial extortion group ShinyHunters, which had earlier claimed to have stolen up to 284 million documents from the medical and pharmaceutical supplier.
The extortion attempt reportedly demanded US$55.2 million to prevent release of the data; the post notes that this figure was not paid, given the subsequent publication of the data. The Register is cited as having carried coverage related to the extortion demands and the attack.
HIBP describes the impacted data as involving a range of individuals and roles, including marketing campaign recipients, patients, staff, and healthcare provider contacts. The article does not provide additional technical detail on how the intrusion occurred or on specific systems affected. It emphasises the scale of the exposure as reflected in HIBP’s listing and notes that McKesson is investigating the incident. The piece also references coverage from The Register for broader context.
In practical terms, the report highlights the potential breadth of affected records across patients and colleagues connected to McKesson, with data published by ShinyHunters implying substantial exposure despite the lack of confirmation for the earlier claim of 284 million documents.