The McKesson breach resolves to 6.4 million people, not the 284 million claimed
ShinyHunters published the McKesson data after a 55.2 million dollar demand went unpaid. Have I Been Pwned counted 6.4 million unique email addresses, against the group's claim of 284 million records, which were raw rows.
ShinyHunters published the data stolen from McKesson after a 55.2 million dollar extortion demand went unpaid. Have I Been Pwned analysed the dump and counted 6.4 million unique email addresses, covering patients, employees, healthcare providers, and marketing recipients. Exposed fields vary by record and include names, email and physical addresses, gender, date of birth, phone numbers, employer details, and health information. The group's original claim of 284 million patient records counted raw rows, not individuals. McKesson detected the incident on August 25, 2026.
Why it matters
The 44-fold gap between the claim and the count is the reusable lesson. Extortion groups quote row counts because row counts are larger, and the number that reaches the first headline is almost always the attacker's. Anyone sizing an incident from initial reporting, including a board asking how bad it is, should treat the first figure as an upper bound supplied by an interested party, and wait for a deduplicated count from Have I Been Pwned or the regulator filing.
That said, 6.4 million is not a reprieve, and the record contents are worse than the count suggests. Date of birth, address, phone number, and employer in one row is a complete package for the help desk social engineering that started this breach in the first place, which we described in the original coverage: vishing against employees, Okta credentials, then Salesforce and Snowflake through the SSO session. The output of this breach is the input to the next one, and the same week's 153 million driver's licence dump compounds it.
For defenders the action is unchanged and worth restating: knowledge-based caller verification is finished. Verify with something the caller holds, not something they can recite.
Sources: The Register, Have I Been Pwned
Related on Start with Identity
- Blog1.6 million RingCentral records leaked, and the entry point was one phone call
ShinyHunters voice-phished a RingCentral employee out of their password in July, took 623GB, and dumped 280GB after the company refused to pay. Have I Been Pwne
- BlogJetBrains was breached through an unpatched copy of its own TeamCity
Attackers exploited CVE-2026-63077 against a JetBrains-run TeamCity server to breach the Cadence cloud service, taking AWS IAM credentials, source code, and sec
- BlogThe Snowflake attacker pleaded guilty, two years after stale credentials did the work
Connor Riley Moucka pleaded guilty in Seattle federal court on August 6, 2026 to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the
- BreachOkta's 2023 support-system breach: when your IdP gets phished
How attackers used a stolen credential to read Okta support cases and harvest session tokens, why HAR files were the weak link, and what it taught the industry
- CVEVault certificate-auth impersonation, public key not CN
Vault's cert auth method bound the entity to the validated public key, not the certificate CN. An attacker who can present a different cert with a reused key im