The McKesson breach: what is confirmed, and what is only claimed
McKesson found an intrusion on 25 August 2026 and told the SEC that data was taken. The figure doing the rounds — 284 million records — comes from the group claiming the attack, not from the company. Here is where the line sits, and what is worth doing before anyone can tell you whether you are in it.
McKesson discovered a cybersecurity incident on 25 August 2026 and disclosed in an SEC filing that third-party applications were compromised and data was accessed and taken. It has not said what data, whose, or how much. The extortion group ShinyHunters claims it took about a terabyte amounting to 284 million records containing identity and medical details — a count of database rows, not of people, and the group itself says it does not know how many individuals are in there. Nothing has been published, so nobody can check whether they are affected yet, and no letters have gone out. Treat any message offering to tell you today as a scam, and use the wait to freeze your credit file at all three bureaus.
Confirmed by McKesson vs claimed by the attackers
The left column is McKesson’s own disclosure. The right is the account given by the group claiming the attack, which no independent party has verified. Where nobody has said anything, the row says so instead of filling the gap.
| Question | What McKesson has confirmed | What ShinyHunters claims |
|---|---|---|
| That something happened | Yes. McKesson discovered a cybersecurity incident on 25 August 2026 and disclosed it to the SEC in an 8-K filing. The company says third-party applications were involved and that data was accessed and taken out. | The extortion group ShinyHunters says it was behind it and went public the same week the filing appeared. |
| How the intruders got in | Not stated. McKesson has not described the method or named the applications involved. | Phone calls to staff — the caller talks an employee through signing in on a page that is not the real one, then walks in with the code. The group says this got it into single sign-on accounts and from there into two cloud platforms the company uses for customer records and data warehousing. |
| How much was taken | Not stated. The filing says data was exfiltrated. It puts no number on it and does not say whose data it was. | Roughly a terabyte, pulled out over four days between 21 and 25 August, amounting to 284 million records. |
| How many people that is | Not stated. No count of individuals has been published by anyone. | Unknown, and the group says so itself: it has not finished going through the files and does not know how many unique people are in them. A record is a row, and one person is normally many rows. |
| What kind of data | Not stated. McKesson has not described the contents of what was taken, and has not said patient data specifically was involved. | Names, addresses, dates of birth, phone numbers, email addresses, Social Security numbers, patient and medical record identifiers, and clinical details such as medications, allergies and diagnoses. |
| A ransom demand | Not addressed in the filing. | A demand of just over $55 million with a 72-hour deadline, which the group says the company did not respond to. |
| Whether the data is public | Nothing has been published as of 31 August 2026. No set connected to this incident has turned up in public breach databases. | The group has threatened release but has not posted the files. |
| Notification letters | None yet. McKesson describes the investigation as being in its early stages and has not said who will be written to. | Not applicable — attackers do not send notification letters. |
Sources: McKesson’s 8-K filing with the SEC, plus reporting by BleepingComputer, CyberInsider, Cybernews and DataBreaches.net, 28–29 August 2026. Status as of 31 August 2026; this page will be updated if the company publishes a count or begins notifying people.
1. What is established, and what is being repeated
McKesson found an intrusion on 25 August 2026 and filed an 8-K with the SEC three days later. The filing is short. It says third-party applications were compromised, that there was unauthorised access and exfiltration of data, that the investigation is early, that the company has not determined the incident to be material, and that customers may see patchy service while it is dealt with. That is the confirmed part in full. Everything else circulating — the record count, the data types, the method, the ransom — comes from the extortion group ShinyHunters, which contacted reporters with its own account of what it did. Attackers claiming a large number is not evidence of a large number, and a company confirming an incident is not a company confirming their version of it. This page keeps the two apart, because a month from now the letters that go out will be written against the first column, not the second.
2. Why 284 million is the wrong number to carry around
The figure that made the headlines is a count of records, and the group that produced it added a caveat that mostly did not travel with it: it has not finished going through the files and does not know how many unique people are in them. A record is a row. A single course of treatment generates rows in ordering, dispensing and support systems, and the same person turns up again in every one of them. So the number of individuals is smaller than 284 million, by a margin nobody can currently state. It could still be very large — McKesson touches a substantial share of the medicines dispensed in the United States — but large and 284 million are not the same claim. If you see the figure written as patients rather than records, the source has added something.
3. Why this could involve you when you have never heard the name
McKesson is not a consumer brand. It is one of the largest distributors of medicines in the country, and around that it runs services attached to prescriptions and patient support for manufacturers, pharmacies and providers. Individuals end up in those systems through their pharmacy and their clinic rather than by signing up for anything, which is why not recognising the name rules nothing out. It also sets the expectation for how this will reach people if data was in fact taken: not through an account, not through an app, but through a letter that arrives once someone has finished working out whose records were in the files. That step has not started. Our guide to medical data breaches covers why health records need a different response from a leaked password.
4. The impersonation problem, which is already live
One detail from the attackers’ own account deserves more attention than the record count: the operation involved a domain registered to look like a McKesson claims site. Impersonating the company is not a side-effect of this story, it is part of how the intrusion worked, and the same instinct will now be pointed at the public. The conditions are perfect for it — a household-scale name, medical data in the headline, and no way for anyone to check whether they are affected. Expect emails, texts and calls offering to tell you. Treat the route as the test rather than the wording: real notifications arrive by post, do not require a click to find out whether you are affected, and never ask for your Social Security number back. Our breach-letter guide goes through what a genuine one contains.
5. What is worth doing while the facts are still moving
You do not need confirmation to take the two steps that would be asked of you later. Freeze your credit file at Equifax, Experian and TransUnion — separately, online, free — which stops a new account being opened in your name and is the only measure that blocks rather than reports. Then turn on two-factor authentication on your email, because that inbox is the lever anyone holding your personal details reaches for first. If the claims about medical identifiers hold up, add one habit: read the explanation-of-benefits statements your insurer sends and query any treatment you did not receive. Health records cannot be frozen and cannot be reissued, so noticing misuse early is the whole defence. None of this is wasted effort if the McKesson claims deflate — it is the baseline for the next incident too.
6. The lawyer emails arrived within a day
Ademi LLP announced an investigation on 29 August, one day after the disclosure, and more firms will follow — that is the reflex now for any breach with a recognisable name attached. It is worth knowing what the stage means. A firm announcing an investigation is looking for clients. It is not a filed case, not a certified class, and not money waiting to be claimed. If a case is filed and eventually settles, the notice reaches you from a court-appointed administrator, usually by post, and claiming is free. That takes years, not weeks. Until then, anything asking for a fee or for your Social Security number to “register your claim” is a scam that the news cycle handed a script to. Our list of settlements actually taking claims is checked against the official administrator sites.
7. The part that is true whatever the investigation finds
Whether this turns out to be 284 million records or a fraction of that, the thing that made the data valuable was never held only by McKesson. A current address, a phone number and a list of relatives are what turn a stolen identity record into a call somebody believes, and those are published and sold openly by people-search and data-broker sites regardless of who gets breached next. Removing them is the one step here whose effect outlasts the news, and it needs repeating rather than doing once, because brokers rebuild profiles from public records within weeks. For the general version of the response, our post-breach guide covers it in seven steps.
You cannot check this set. You can check the ones that are public.
Nothing from McKesson has been published. What has been published is your address, phone number and relatives, listed by 499 broker and people-search sites — the detail that makes a stolen record usable in the first place. PersProtect finds where you appear, files the removals and keeps checking that they stay down. The scan is free.
Check my exposure — free →The McKesson breach, answered
Is the McKesson breach real?
The incident is real and the company says so itself. McKesson found it on 25 August 2026 and told the SEC that third-party applications were compromised and that data was accessed and taken. What is not established is the part that has been travelling fastest: the scale and the contents. Those come from the group claiming the attack, not from McKesson, not from a regulator, and not from anyone who has seen the files. Both things are true at once — a genuine intrusion, and a set of numbers nobody has verified.
Were 284 million patients affected?
That is not what the figure means, even taken at face value. 284 million is a count of records claimed by the attackers, and the group has said openly that it has not finished analysing the data and does not know how many unique people are in it. Records are rows in a database. One prescription history alone can be dozens of rows, and the same person appears again in every system that touched their care. So the number of people is smaller than 284 million by some unknown margin, and McKesson has published no count of its own. Anyone reporting this as 284 million patients has added a word the source did not.
Why would a drug distributor have my medical information?
Because McKesson sits behind the pharmacy counter rather than in front of it. It is one of the largest distributors of medicines in the United States, and around that business it runs services tied to prescriptions and patient support for manufacturers, pharmacies and clinics. Records about individuals can end up in those systems without anyone ever having heard the name, which is why "I have no relationship with McKesson" does not rule you out. It also means that if data was taken, the people in it would learn about it from a letter rather than from an account they could log into.
How do I check whether my data was in it?
Right now there is no way to check, and that is worth stating plainly because the gap is exactly where scams grow. Nothing has been published, so no breach-checking service — ours included — can search this set. If data was taken and companies are able to identify who is in it, the route is a notification letter by post, and those take weeks to months to arrive because the counting comes after the investigation. Any site or message offering to tell you today whether you are in the McKesson breach is guessing at best.
I got an email about the McKesson breach. Should I click it?
No. The group behind this registered a domain built to look like a McKesson claims site as part of the attack itself, which tells you how central the impersonation angle is here. A story with medical records and Social Security numbers in the headline, and no way for anyone to check whether they are affected, is close to ideal conditions for a phishing wave. Judge a message by how it reached you rather than by how it looks: a real notification arrives by post, explains what happened without needing you to click to find out, and never asks for your Social Security number back.
What should I actually do this week?
Freeze your credit file at Equifax, Experian and TransUnion. It is free, it takes about ten minutes at each, and it blocks a new account being opened in your name, which is what an identity record enables. If the claims about medical identifiers turn out to be accurate, the second habit that matters is reading the statements your insurer sends and querying any care you did not receive, because health data has no bureau to freeze it at. Do those two and you have covered most of what a confirmed letter would ask of you later, without having waited for it.
Law firms are advertising. Is there money to claim?
Not yet, and it is worth understanding what stage this is. Ademi LLP announced an investigation on 29 August, one day after the disclosure. An investigation is a firm looking for clients — it is not a filed case, not a certified class, and not a settlement paying anything out. If a case is eventually filed and settles, notice comes from a court-appointed administrator, usually by post, and claiming costs nothing. That is a process measured in years. Anything asking for a fee or your Social Security number to register a claim today is a scam built on the news.
Should I change my passwords?
It will not hurt, but it is not the point here. Nothing in what has been claimed is a password to your accounts. What is described is identity and health information, which is not used to log in as you — it is used to open credit elsewhere in your name, or to make a call sound legitimate because the person on the line knows your date of birth and your medication. Turning on two-factor authentication on your email is a better use of ten minutes than a password rotation, because your email is what a stranger with your personal details would try to take over first.
Waiting for a letter is not a plan
Whatever this investigation concludes, the address and phone number that make a stolen record usable are already published. See which sites list yours — free, in about a minute.
Run my free exposure scan →