Ransomware victim disclosure
← All victimsMcKesson Corporation
Claimed by Shinyhunters · listed 2 days ago
Status timeline
- ListedAug 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 28, 2026
About the victim
AI dossier — public-source company profileMcKesson Corporation is a major American healthcare company primarily engaged in pharmaceutical distribution and healthcare information technology services. The company operates at a national scale as a critical intermediary in the U.S. healthcare supply chain.
- Industry
- Pharmaceutical Distribution & Healthcare Services
Attack summary
Severity: critical — Confirmed exfiltration of regulated sensitive data at massive scale (hundreds of millions of records). Healthcare data and PII together constitute regulated information subject to HIPAA and other privacy laws. McKesson's role in pharmaceutical distribution means compromised records likely include patient, provider, and prescription data.ShinyHunters claims to have compromised hundreds of millions of records containing both personally identifiable information (PII) and protected health information (PHI). The group threatens full publication if the victim does not engage with their extortion demand by 1 September 2026.
Data the group says was taken
AI dossier — extracted from the leak post- Personally identifiable information (PII)
- Protected health information (PHI)
What the group claims
Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

