Hackers Claim the McKesson Breach Could Expose Your Diagnosis, Sexual Orientation, and Prescriptions. How to Protect Yourself

Cybercriminals could use your stolen health data, such as medical records and Medicaid numbers, to launch phishing attacks, commit fraud, and steal your identity.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Security researchers have confirmed a cybersecurity incident involving McKesson, where threat actors have reportedly stolen 284 million records, including highly sensitive data such as medical information, phone numbers, and email addresses.[1]

This puts both present and past McKesson clients at risk, as cybercriminals could use this information to launch highly personalized and elaborate phishing scams, financial fraud, or even complete identity takeovers.

Here’s everything you need to know about the breach and, most importantly, the steps you can take to protect yourself.

In this article
What data was exposed in the breach
The risks of having your health data stolen
What can you do to protect yourself
Bottom line

What data was exposed in the breach

A notorious threat group called ShinyHunters claims to have obtained 284 million records belonging to McKesson, one of the largest healthcare companies in the U.S.

As per ShinyHunters’ claim made to CyberInsider, they accessed McKesson’s systems by using vishing, or voice phishing, to target two of its employees, and then extracting data from Salesforce and Snowflake instances.

Further details on the modus operandi of the breach have not been provided by the group. ShinyHunters says it has stolen the following data:

  1. Patient IDs, Medicaid numbers, and medical record numbers (MRNs) belonging to patients.
  2. Patients’ personally identifiable information, such as phone numbers, email addresses, home addresses, Social Security numbers, full names, and dates of birth.
  3. Information relating to medical conditions, such as illnesses and diagnoses, disabilities, allergies, patient notes, and physician information.
  4. Predictive health data, such as disease-risk assessments and cancer predictions.
  5. Sensitive records, such as sexual orientation, terminal illness information, autopsy and cause-of-death information, and other personal status information.
  6. Prescription and billing records, such as shipment addresses, dates, medication orders, and tracking numbers.
  7. Employee records, including their phone numbers, names, addresses, email addresses, job roles, and department information.
  8. Doctor-patient communications.
  9. Information about clinics and physicians using McKesson, including names, contact details, and addresses.

The source says the 284 million records are linked to tens of millions of patients, but the exact number of people affected is not yet known.

Following the breach, ShinyHunters have demanded a ransom of $55,236,150 to prevent the files from being released. However, ShinyHunters says McKesson has not responded to the request yet. 

A spokesperson said to CyberInsider, “McKesson is in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data. Upon discovery, we immediately activated our incident response protocol, launched an investigation, and engaged leading cybersecurity experts.”

It’s worth noting that Qantas’s recent data breach was also the result of a social engineering vishing (voice phishing) scam — and there too the cybercriminals targeted unsuspecting employees for a way in.

The risks of having your health data stolen

The breached data includes both personal information and private medical records, giving threat actors plenty of ways to target victims.

Most concerningly, cybercriminals could use the stolen data to target individuals with highly personalized phishing emails or messages. These communications might contain information such as your name, Medicaid number, or other medical record references, which might make them look compelling and genuine.

For example, you could receive an email that appears to come from your insurer and claims that you need to click a link to view an updated medical report or verify information related to a recent prescription.

The link could be malicious, either installing malware on your system or taking you to a fake website controlled by the attacker, where any credentials you enter could be stolen.

Other ways hackers could exploit your data:

  1. Medical Identify theft: Threat actors can impersonate you and file bogus insurance claims in your name. This could not only drain your insurance benefits but also clutter your medical file with fake diagnoses and treatments, which could complicate your care and coverage for years to come.
  2. Financial fraud: The stolen data, such as names, email addresses, SSNs, and phone numbers, could be used to open new lines of credit in your name or take out payday loans. Victims often don’t find out about this until they’re denied credit or hit with collection calls.
  3. Employee-targeted secondary attacks: Since the data also includes employee records such as roles, departments, and contact information, malicious parties may use the information to orchestrate secondary attacks on employees to attempt deeper intrusions at McKesson or its partners.

What can you do to protect yourself

A data breach involving a healthcare company can be especially concerning because it can expose both your personal information and sensitive medical records.

While you have virtually no way to stop a third-party company from leaking your data — that’s up to the company’s vigilance and protection — you can follow a few cyber hygiene habits to tie up loose ends.

  1. Use a third-party antivirus program: A good antivirus can not only flag and remove malware you download from a phishing link, but it can also prevent you from clicking on suspicious links and visiting dangerous websites in the first place. Antiviruses with web protection can display a warning saying that the link you’re about to click might be suspicious, keeping you safe from potential phishing attacks.
  2. Place a credit freeze: Consider placing a credit freeze with all three major bureaus: Equifax, Experian, and TransUnion, since scammers may use your SSN and date of birth to open new lines of credit in your name. It’s free, reversible, and blocks lenders from accessing your credit reports until you lift the freeze yourself.
  3. Use multi-factor authentication (MFA): Multi-factor or two-factor authentication (2FA) adds an extra layer of protection to your online accounts. This will make it harder for attackers to misuse your stolen credentials, since they’d need a secondary authentication factor even after having your password.
  4. Check your medical records: Review your insurance statements and medical records regularly. Keep an eye on your Explanation of Benefits (EOB) statements and medical records for prescriptions, treatments, or procedures, and immediately flag anything you don’t recognize. Catching any inconsistencies early could prevent your medical file from becoming corrupted with fraudulent entries.
  5. Change your passwords: Immediately change your passwords for sensitive accounts such as banking, crypto wallets, or social media accounts. Consider using a password manager that not only suggests strong, unique passwords for all your accounts but also stores all of your credentials securely and even autofills them for you, saving you the trouble of remembering them.
  6. Use an identity theft protection service: These tools scan online databases as well as the dark web to look for your personally identifiable information and alert you if they find anything. They also typically offer identity theft restoration services, which may help you restore your identity following a data breach incident such as this.

Bottom line

McKesson’s incident response team is still active and assessing the damage from the data breach. Meanwhile, the company has yet to comment on the ransom demanded by ShinyHunters.

It’s also unclear if it would be providing any assistance to affected clients following the data breach. This means the best way to protect yourself is to take proactive steps to prevent your stolen data from being misused.

The top solutions include not clicking on any suspicious links in emails that seem to come from legitimate senders, such as insurers, using an antivirus program to block phishing attempts in their tracks, changing your account passwords, and getting an identity theft protection service.

4.8
Editorial Rating
Get Deal
On LifeLock's website
2026 Editors’ Choice
Best ID Theft Service for Comprehensive Monitoring
Identity Protection
LifeLock
  • ID theft protection with U.S.-based restoration specialists and data removal services included on every plan
  • ID theft insurance on all plans, with the Total plan covering up to $3M
  • Dark web, home title, and social media monitoring available, with coverage expanding by plan tier

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] ShinyHunters claims McKesson data breach exposing 284 million patient records