- What: McKesson disclosed on August 28, 2026 that attackers reached third-party applications and stole data, and ShinyHunters claimed the attack using voice phishing against employees.
- Impact: The group claims roughly 284 million records including names, Social Security numbers, Medicaid numbers, medical record numbers, medications, allergies, and physician details, plus employee data and internal communications.
- Fix / mitigation: There is no patch here: the countermeasure is phishing-resistant MFA on Okta single sign-on, out-of-band verification for help desk identity resets, and query volume alerting on Salesforce and Snowflake.
- Who's at risk: Patients, providers, and pharmacies whose data flows through McKesson, plus any large enterprise where a voice call to the help desk can reset an SSO credential.
On August 25, 2026, McKesson learned that someone had been inside its third-party application estate for four days. No firewall was breached. No zero-day was burned. Someone picked up a phone, called McKesson employees, sounded exactly like the internal help desk, and kept calling until enough people handed over access to their Okta single sign-on accounts. From there the path ran straight into Salesforce and Snowflake, and out the door.
McKesson supplies medicines, medical supplies, technology, and services to healthcare providers and pharmacies across the country. That position makes the company a data aggregator whether it wants to be one or not. The ShinyHunters extortion group says it took roughly 284 million records: names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment details, physician information, plus employee data and internal communications. That is not a marketing list. That is a person's medical life, and unlike a credit card it cannot be reissued.
Four days in August
The timeline is tight and worth memorizing. Data was exfiltrated between August 21 and 25, 2026. McKesson discovered the incident on August 25. Public disclosure came on August 28. Three days from discovery to disclosure is genuinely fast by healthcare industry standards, and McKesson deserves credit for it. Four days of undetected bulk extraction from a SaaS data warehouse is the part that should keep people up at night.
The company's public statement was the expected shape. "We take the security and privacy of our partners, customers and their patients very seriously," McKesson said, adding that upon discovery it "immediately activated our incident response protocols, launched an investigation." That is a correct statement and also a nearly content-free one. The useful details in this story came from the attackers, not the victim, which is a recurring problem in extortion-driven disclosure.
ShinyHunters registered mckesson[.]claims and used it to impersonate the company's help desk and IT teams. A plausible sounding caller plus a plausible looking domain was enough to compromise multiple employee Okta accounts. The technical sophistication in this intrusion lives almost entirely in the pretext, not the payload.
The help desk is the perimeter now
Strip the branding off this incident and you get a chain that any large enterprise running federated identity should recognize immediately:
- A lookalike domain is registered to give the caller a credible landing page and email trail.
- Employees receive voice calls from people claiming to be internal help desk or IT staff.
- Multiple Okta single sign-on credentials are captured, not just one, because volume beats precision.
- Federated SSO turns those credentials into access across connected applications.
- Salesforce and Snowflake, which exist specifically to hold enormous consolidated datasets, are queried and drained over four days.
Every control that would have broken this chain sits outside the traditional vulnerability management program. Nothing here has a CVE. Nothing here gets flagged by a scanner. This is an identity and process failure, and the industry keeps funding it like it is a patching problem.
284 million is a record count, not a headcount
Read the number carefully. ShinyHunters claims approximately 284 million data records. Records are rows, and one patient can generate dozens or hundreds of rows across appointments, prescriptions, and claims. The actual number of impacted patients remains unknown. It is also an attacker-supplied figure, published by a group with an obvious financial incentive to inflate it during an active negotiation. Treat it as an upper bound on the noise, not a confirmed victim count. That said, even a heavy discount on 284 million records still lands somewhere very large.
This is a campaign, not an incident
McKesson is the latest name on a list, not an outlier. ShinyHunters has been tied to claims against Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth. The group found a repeatable formula that works against healthcare organizations specifically: call the humans, collect SSO credentials, pivot into the SaaS platforms where the data was already consolidated for analytics, extract, extort. Healthcare is the target of choice because the data is high value, the vendor sprawl is enormous, and the help desks are large, distributed, and under pressure to unblock clinical staff quickly.
The RedEye take
The uncomfortable truth in this story is that McKesson probably did most things right and still lost four days of data. There is no missed patch to point at, no negligent admin to name. The company built a modern identity stack and a modern data platform, and an attacker with a phone and a $12 domain registration turned both of them into an exfiltration pipeline. If your board asks whether this could happen to you, the answer is yes, and your maturity score will not save you.
The deeper failure is architectural. Salesforce and Snowflake were designed to make it easy to bring everything together and query it fast. That is the product. It also means a single compromised identity gets an attacker the aggregated view that would have taken weeks of lateral movement in a legacy environment. The security industry spent a decade telling enterprises to consolidate data for analytics and then largely failed to ship the detection layer that watches what happens after login. We are now paying that bill in eight-figure ransoms and unresettable patient records.
One more point, stated plainly: McKesson did not respond to the negotiation. That is the right call and it should be said out loud, because non-payment almost certainly means publication. Any organization holding this posture needs to have decided in advance that it will absorb the publication rather than fund the next campaign. If you have not had that conversation with your executive team before an incident, you will have it under a 72-hour clock instead.
ShinyHunters demanded $55,236,150 with a 72-hour response window. McKesson did not respond to negotiations. Assume the data is destined for publication or resale, and plan patient and employee notification, credit monitoring, and inbound fraud handling on that assumption rather than on a hope that the deadline passes quietly.
What defenders should learn
- Treat identity resets as a privileged operation, not a convenience function. Any help desk action that can grant or restore SSO access needs out-of-band verification through a channel the caller did not choose, such as a callback to the number of record or manager attestation. If a voice call alone can move that lever, you have the same exposure McKesson had.
- Phishing-resistant MFA is the control that would have broken this chain. Push notifications and one-time codes are relayable in real time by a caller on the phone with the victim. FIDO2 or hardware-backed passkeys on Okta, enforced without a fallback path, take the vishing playbook off the table entirely.
- Instrument the data platform, not just the login. Four days of bulk extraction from Snowflake and Salesforce should produce a query volume and export anomaly long before an outsider tells you about it. Baseline normal per-user row counts and export sizes, and alert on deviation. Most organizations have zero detections that fire after successful authentication.
- Monitor lookalike domain registrations against your own brand and feed them to the help desk, not just to legal. mckesson[.]claims was a purchasable signal that existed before the calls started. Certificate transparency and registration monitoring are cheap; the gap is that findings usually route to takedown workflows instead of to the people answering the phones.
- Decide your ransom posture now and write it down. McKesson faced a $55,236,150 demand on a 72-hour clock and chose not to engage. Whatever your answer is, it should be a board-ratified policy with a pre-built notification and communications plan behind it, not a decision made at 2 a.m. by whoever is on the bridge call.
Source: BleepingComputer, "McKesson discloses breach after ShinyHunters claims patient data theft," August 28, 2026.
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us