Start with Identity
← Blog
News

The McKesson breach resolves to 6.4 million people, not the 284 million claimed

ShinyHunters published the McKesson data after a 55.2 million dollar demand went unpaid. Have I Been Pwned counted 6.4 million unique email addresses, against the group's claim of 284 million records, which were raw rows.

By SWI Community TeamSep 10, 2026Updated Sep 14, 2026

ShinyHunters published the data stolen from McKesson after a 55.2 million dollar extortion demand went unpaid. Have I Been Pwned analysed the dump and counted 6.4 million unique email addresses, covering patients, employees, healthcare providers, and marketing recipients. Exposed fields vary by record and include names, email and physical addresses, gender, date of birth, phone numbers, employer details, and health information. The group's original claim of 284 million patient records counted raw rows, not individuals. McKesson detected the incident on August 25, 2026.

Why it matters

The 44-fold gap between the claim and the count is the reusable lesson. Extortion groups quote row counts because row counts are larger, and the number that reaches the first headline is almost always the attacker's. Anyone sizing an incident from initial reporting, including a board asking how bad it is, should treat the first figure as an upper bound supplied by an interested party, and wait for a deduplicated count from Have I Been Pwned or the regulator filing.

That said, 6.4 million is not a reprieve, and the record contents are worse than the count suggests. Date of birth, address, phone number, and employer in one row is a complete package for the help desk social engineering that started this breach in the first place, which we described in the original coverage: vishing against employees, Okta credentials, then Salesforce and Snowflake through the SSO session. The output of this breach is the input to the next one, and the same week's 153 million driver's licence dump compounds it.

For defenders the action is unchanged and worth restating: knowledge-based caller verification is finished. Verify with something the caller holds, not something they can recite.

Sources: The Register, Have I Been Pwned

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.