McKesson — one of the largest US distributors of pharmaceuticals and medical equipment, and a significant health-IT supplier — published a notice of data breach dated September 8, 2026, saying it was investigating a cybersecurity incident involving third-party applications and the unauthorized access and exfiltration of data. Because McKesson works as a vendor to healthcare providers, the company noted, the personal information involved can belong to people who received care from those providers rather than customers of McKesson itself.
Two days later, The Register reported that the incident affected roughly 6.4 million individuals, citing the breach-notification service Have I Been Pwned, which had added data leaked by the serial extortion group ShinyHunters. The logged records span patients, staff and providers.
Why it matters
Healthcare data is the most expensive category to have leaked and the least possible to unwind. It combines identifiers that never change with clinical detail that people have strong reasons to keep private, and in the US it sits inside a regulatory regime — HIPAA breach notification — with defined timelines and penalties.
The vendor dimension is the part worth watching. When the breached party is a supplier rather than the provider, the affected individual usually has no direct relationship with the company holding their data, and the provider that does hold the relationship depends on the vendor's forensics to know what to tell patients.
How it works
McKesson's own notice frames the incident around third-party applications, which is the pattern that has defined this year's extortion campaigns: rather than breaking into an enterprise's own network, attackers obtain access to a connected SaaS or integration account and pull data through the trusted channel. From the victim's logs the traffic often looks like an ordinary authorized export.
ShinyHunters, the group whose leaked data Have I Been Pwned ingested, operates as an extortion and data-leak crew rather than a conventional encrypt-and-ransom operation, publishing or selling stolen records when payment does not arrive.
Evidence
McKesson's notice of data breach, dated September 8, 2026, states that the company is investigating an incident involving third-party applications and unauthorized access and exfiltration of data, and explains that affected personal information may belong to individuals who received care from providers McKesson serves. The Register's September 10, 2026 report attributes the figure of approximately 6.4 million individuals to Have I Been Pwned's ingestion of data leaked by ShinyHunters, spanning patients, staff and providers.
What defenders should do
Healthcare organizations should inventory which third-party applications hold identifiable patient data on their behalf, and which of those integrations can export in bulk. Bulk export is the capability that turns a single compromised integration credential into a multimillion-record incident, and it is usually enabled by default.
Practically: scope integration tokens to the minimum data set, require re-authentication for large exports, alert on export volume rather than only on failed logins, and rehearse the notification path with each vendor before an incident, not during one.
What happens next
Expect the affected-individual count to move as forensics continue — it is normal for these numbers to rise — and expect downstream provider notifications, HHS Office for Civil Rights scrutiny and litigation. The broader question for US healthcare is whether integration platforms holding patient data get audited with the seriousness applied to the electronic health record itself.
