SecuritySeptember 1, 202610 min read

What to Do After the McKesson Data Breach

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the McKesson Data Breach

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

If you received cancer care, specialty infusions, or medical-surgical services through a McKesson-serviced provider, treat the August 2026 breach as a full-identity exposure and act now: freeze your credit at all three bureaus, enable app-based two-factor on your email and bank, watch every Explanation of Benefits for medical identity theft, keep an eye out for a notification letter, and remove your personal information from data broker sites so attackers cannot combine it with the leaked records. Below is exactly how to do each step.

What Happened in the McKesson Breach

McKesson — one of the largest healthcare and pharmaceutical distributors in the world — disclosed a cybersecurity incident on August 31, 2026 after the extortion group ShinyHunters publicly claimed responsibility for stealing patient data. According to McKesson's early investigation, an unauthorized actor gained access through a third-party application on or around August 25, 2026 and exfiltrated data belonging to a subset of customers in the company's Oncology & Multispecialty and Medical-Surgical business units.

ShinyHunters claims the theft covers 284 million rows of patient data — a headline number the group later clarified refers to raw rows in the stolen database, not 284 million unique patients. Even with heavy deduplication, security researchers expect the final confirmed count to run into the tens of millions of individuals. The group also claims it demanded a $55 million ransom and gave McKesson 72 hours to respond.

What Information Was Exposed?

According to ShinyHunters' extortion post and independent samples reviewed by security researchers, the stolen data appears to include both PII and protected health information (PHI):

  • Full names
  • Home addresses
  • Dates of birth
  • Phone numbers and email addresses
  • Social Security numbers
  • Patient identifiers and medical record numbers
  • Diagnosis, treatment, and prescription details
  • Billing and insurance information
  • Doctor–patient messages

This Is a Full-Identity Breach

The combination of SSN + date of birth + address + medical history is the exact recipe for medical identity theft, synthetic identity fraud, tax refund fraud, and fentanyl-era prescription fraud. Treat any suspected exposure as if your Social Security number were leaked directly — assume attackers have everything they need to open accounts or file fraudulent claims in your name.

Who Is Affected?

McKesson's early disclosure names two business units: Oncology & Multispecialty (cancer treatment providers, community oncology practices, and specialty infusion partners) and Medical-Surgical (primary-care and long-term-care supply customers). Most consumers never see McKesson's name on a bill — the company sits behind the pharmacies, oncologists, and clinics they visit — so exposure often shows up under a provider name you do recognize. If you have received cancer care, IV infusions, chemotherapy, or specialty medications in the last few years, assume you may be in scope until McKesson's investigation concludes otherwise.

Step 1: Watch for a Breach Notification Letter

McKesson's investigation is in its early stages as of publication, so individual notification letters have not yet started to arrive. Under state breach-notification laws, letters typically go out within 30–90 days of scope confirmation and include (a) what was exposed, (b) a code for free credit and identity monitoring (usually 12–24 months), and (c) instructions for filing under any eventual class action. Do not throw the letter away — you will need it.

Step 2: Freeze Your Credit at All Three Bureaus

Because Social Security numbers appear to be exposed, a credit freeze is the single most effective step you can take. It is free, takes about 15 minutes, and blocks anyone — including you — from opening new credit in your name without lifting the freeze first.

  • Equifax: equifax.com/personal/credit-report-services/credit-freeze/
  • Experian: experian.com/freeze/center.html
  • TransUnion: transunion.com/credit-freeze

Do not skip a bureau. Fraudsters will try the one you missed. Place a fraud alert at any one of the three — it automatically applies to the other two — so lenders take extra steps to verify identity before opening new accounts.

Step 3: Enroll in Free Monitoring When Offered

Once McKesson's notification arrives, use the enrollment code inside to sign up for the offered credit and identity monitoring. Free monitoring is a supplement, not a substitute, for the freeze — it alerts you after suspicious activity occurs, while the freeze prevents new accounts from being opened in the first place. Use both.

Step 4: Watch for Medical Identity Theft

Medical identity theft is harder to catch than credit fraud, and the McKesson data includes exactly the fields criminals need to commit it — patient IDs, diagnoses, prescriptions, and insurance details.

  • Review every Explanation of Benefits (EOB) statement — flag any procedure, provider, medication, or date you do not recognize
  • Request an accounting of disclosures from your health plan under HIPAA to see who has accessed your records
  • Order your free annual medical record from providers you have visited
  • Watch for controlled-substance prescription fraud in your name — a common downstream use of oncology and pain-management records
  • If you spot a fraudulent claim, contact the insurer's fraud line immediately and file a report at IdentityTheft.gov

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 5: Switch Away From SMS-Based 2FA

Full-identity leaks like McKesson's give criminals what they need to convince a mobile carrier to port your phone number to a new SIM (SIM-swap). Once they have the number, SMS-based two-factor codes stop protecting you. Move your email, bank, and healthcare portal 2FA to an authenticator app (Authy, Google Authenticator, 1Password) or a hardware key (YubiKey). Keep SMS as a fallback only.

Step 6: Watch for Targeted Phishing

Attackers who have your full medical profile can craft phishing that looks disturbingly authentic. Expect:

  • Fake McKesson or provider "breach response" emails asking you to "verify identity"
  • Calls from people who know your diagnosis or prescription history and try to "confirm" account details
  • Text messages about co-pays or refills you supposedly owe
  • Emails offering free credit monitoring from a company McKesson did not name

Never click a link in a breach-related email. Go to McKesson's or your provider's official site directly, and only enroll in monitoring through the code printed in your mailed letter.

Step 7: File Complaints if You See Misuse

  • Report identity theft at IdentityTheft.gov to get an FTC recovery plan and affidavit
  • File a HIPAA complaint with the HHS Office for Civil Rights at hhs.gov/hipaa/filing-a-complaint
  • File a police report if fraudulent accounts or prescriptions are opened in your name — you will need the report number to dispute fraud with creditors and pharmacies

Step 8: Remove Your Data From People-Search Sites

Data brokers like Spokeo, BeenVerified, WhitePages, and Radaris publish your name, address, phone, relatives, and employer for free. When combined with the McKesson leak, this gives attackers everything they need to impersonate you, target your family, or trick medical providers and pharmacies into releasing more of your history.

PrivacyOn removes your personal information from 100+ data broker sites, monitors the dark web for exposures like the McKesson leak, and keeps re-submitting removal requests when brokers relist your data — which they routinely do. Reducing your public footprint is the one long-term step that actually stays effective after a breach.

ShinyHunters and the 2026 Healthcare Wave

McKesson is the latest in a wave of 2026 healthcare-adjacent breaches claimed by ShinyHunters and its affiliates — including DentaQuest (up to 23.4 million records in May), Blue Shield of California, Change Healthcare, and Navia Benefit Solutions (2.7 million). Complete medical records sell for 10 to 40 times more than credit card numbers on dark web marketplaces, and pharmaceutical distributors sit on some of the deepest, longest-retained patient files in the industry — making them the highest-value target of the year.

How PrivacyOn Helps After the McKesson Breach

  • Dark web monitoring alerts you when your McKesson data appears for sale or in new dumps
  • Data broker removal pulls your personal information from 100+ people-search sites — reducing the ammunition for identity thieves
  • 24/7 continuous monitoring catches new exposures as they happen, not months later
  • Family plans cover up to 5 people, so your household is protected together
  • Starts at $8.33/month — a fraction of the cost of restoring a stolen identity

Take Action Today

PrivacyOn's dark web monitoring and data broker removal are the long-term protection layer breaches like McKesson require. Start protecting your family today — plans from $8.33/month.

Frequently Asked Questions

How many people were affected by the McKesson data breach?

ShinyHunters claims 284 million rows of patient data were stolen, but the group has clarified that this refers to database rows, not unique patients. McKesson's investigation was still in its early stages when the breach was disclosed on August 31, 2026 — the confirmed unique-patient count will follow in later filings and notification letters.

Was my Social Security number exposed in the McKesson breach?

ShinyHunters lists Social Security numbers as part of the stolen fields, along with names, addresses, dates of birth, contact information, medical record numbers, diagnoses, prescriptions, billing details, and doctor–patient messages. Treat it as a full-identity breach and freeze your credit immediately.

Which McKesson customers are affected?

McKesson's early disclosure names two business units: Oncology & Multispecialty (community oncology, specialty infusion, and cancer-care partners) and Medical-Surgical (primary-care and long-term-care supply customers). Because McKesson usually sits behind the pharmacy or provider you see on your bill, exposure often surfaces under a provider name you recognize. If you have received cancer care, IV infusions, or specialty medications, assume potential exposure.

Has McKesson sent breach notification letters yet?

Not as of publication. Under state breach-notification laws, letters typically arrive within 30–90 days of scope confirmation. Save the letter when it comes — it contains the free-monitoring enrollment code and the details needed to join any eventual class-action lawsuit.

Is McKesson offering free credit monitoring?

McKesson has not yet announced enrollment details, but breached healthcare companies of this size typically offer 12–24 months of free credit and identity monitoring in the notification letter. Enroll when offered — but do not rely on monitoring alone. A credit freeze at all three bureaus is the more powerful step, and it is free.

What is the best long-term protection after a healthcare breach?

Because McKesson's data will circulate on the dark web indefinitely, the highest-value long-term steps are (1) keeping credit frozen except when you actively apply for credit, (2) moving 2FA off SMS and onto an authenticator app or hardware key, and (3) subscribing to a data broker removal service like PrivacyOn that continuously removes your personal information from people-search sites so attackers cannot combine it with the leaked medical data.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families