ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

ShinyHunters leak McKesson data exposing 6.4 million after $55.2M extortion demand goes unpaid

highData breachexploited in the wildimportance 78
What's new: Have I Been Pwned ingested the ShinyHunters-leaked McKesson dataset, publicly confirming for the first time that the August 2026 attack affected roughly 6.4 million individuals; previously the only figure was ShinyHunters' claim of 284 million stolen documents.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Have I Been Pwned has added records leaked by ShinyHunters, confirming the August 2026 attack on medical and pharmaceutical supply company McKesson affected roughly 6.4 million individuals; the group published the data after an apparently unpaid $55.2 million…

Have I Been Pwned's addition of data leaked by the extortion group ShinyHunters is the first public indication of the true scale of an August 2026 cyberattack on medical and pharmaceutical supply company McKesson, confirming roughly 6.4 million individuals were affected. ShinyHunters initially claimed to have stolen 284 million documents from McKesson, and demanded $55.2 million; with the demand apparently unpaid before publication, the group released the data. Exposed information includes names, email and physical addresses, dates of birth, phone numbers, employer details, and sensitive health information. ShinyHunters claimed Social Security numbers were among the stolen data, but HIBP found no SSNs in the leaked records. The same coverage notes two other healthcare-sector incidents: Veradigm disclosed that attackers used third-party vendor credentials to access an API and steal roughly 3.5 million patient records, claimed by ransomware group The Gentlemen, and Boston Scientific expects to miss Q3 sales and earnings guidance following its own separate cyberattack.

  • Have I Been Pwned added ShinyHunters' leaked McKesson records, confirming about 6.4 million affected individuals in the August 2026 attack.
  • HIBP's ingestion of the leaked data is the first public indication of the attack's true scale.
  • ShinyHunters initially claimed to have stolen 284 million documents from McKesson.
  • ShinyHunters issued a $55.2 million extortion demand that was apparently unpaid before the data was published.
  • Exposed data includes names, email and physical addresses, dates of birth, phone numbers, employer details, and sensitive health information.
  • Sources disagree on SSNs: ShinyHunters claimed SSNs were stolen, but HIBP found no SSNs in the leaked data.
  • Separately, Veradigm disclosed attackers used third-party vendor credentials to access an API and steal roughly 3.5 million patient records, claimed by ransomware group The Gentlemen.
  • Boston Scientific expects to miss Q3 sales and earnings guidance after its own separate cyberattack.

Coverage timeline

  1. · 6d ago
    The Register · Security· 78
    ShinyHunters expose 6.4M in attack on medical supplier McKesson

    ShinyHunters leaked stolen McKesson data exposing roughly 6.4 million individuals after the medical supplier reportedly declined a $55.2 million extortion demand.

  2. · 6d ago
    DataBreaches.net· 76
    ShinyHunters expose 6.4M in attack on medical supplier McKesson

    Have I Been Pwned data shows ShinyHunters' attack on medical supplier McKesson exposed records of roughly 6.4 million individuals.