MCKESSON CORPORATION
ent_2b56f9705aa72eb464377c74
Disclosures
3
Leak Site · State AG · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
68,767
nationwide · State AG NH
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- MCKESSON CORPORATION
- Normalized
- mckesson— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300WZWOM80UCFSF54
- SEC EDGAR CIK
- 0000927653
- Domain
- connect.mckesson.com
Disclosure history (3)newest first
- GLOBALLeak Siteas victim2026-08-28
Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING
- New Hampshire State AGas victim2007-09-11
McKesson Specialty Arizona Inc. reported the theft of two computers from its Scottsdale, AZ office on July 18, 2007. The stolen devices may have contained personal information of patients enrolled in various Patient Assistance Programs (PAPs), including names, addresses, dates of birth, Social Security numbers, and prescription-related data. McKesson notified the New Hampshire Attorney General and affected individuals, offering credit monitoring advice. No evidence of misuse was found at the time of notification.
- New Hampshire State AGas victim2007-08-30
McKesson Corporation reported the theft of two computers containing personal information on July 18, 2007. The incident affected 68,767 individuals nationwide, including 987 New Hampshire residents. Data exposed included names, addresses, dates of birth, prescriptions, and Social Security numbers. McKesson initiated notifications on August 29, 2007, and implemented remediation measures including security policy reviews and enhanced employee training.