CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ShinyHunters expose 6.4M in attack on medical supplier McKesson

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6991

As cited

Copy frozen at (site build).

breaches incidents

ShinyHunters expose 6.4M in attack on medical supplier McKesson

ShinyHunters claimed responsibility for a cyberattack on medical supplier McKesson that exposed data for approximately 6.4 million individuals, according to Have I Been Pwned. The breach, which occurred in August 2026, represents one of the largest healthcare supply chain incidents on record. ShinyHunters is a known threat group that targets organizations across multiple sectors for extortion.

Why it matters: Healthcare providers, hospitals, and pharmacies relying on McKesson for supplies and services should assume customer and patient data may have been compromised and prepare breach notification responses; security teams should monitor for exposed credentials and personally identifiable information being sold or used in follow-on attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary