McKesson Corporation discovered a cybersecurity incident affecting its information systems on 25 August 2026, and confirmed five days later that hackers had exfiltrated data tied to a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units. McKesson delivers roughly one third of the prescription medicines dispensed to hospitals, pharmacies and clinics across North America, and also runs the Health Mart pharmacy franchise. According to the ShinyHunters extortion group, the intrusion did not begin with a technical exploit. It began with a phone call.
ShinyHunters told reporters it gained its initial foothold by voice phishing, or vishing, multiple McKesson employees, persuading them to hand over or approve access to their Okta single sign-on accounts. Okta is the identity layer that authenticates employees into McKesson's other business systems, so a compromised Okta session functioned as a master key. The group says it used that access to move into Salesforce and Snowflake, the platforms holding McKesson's customer relationship data and its data warehouse, and removed approximately one terabyte of information between 21 and 25 August.
ShinyHunters claims the haul totals around 284 million records, though that figure counts records rather than unique patients, and includes personally identifiable information, protected health information, prescription and billing records, employee data, and details on the physicians and clinics McKesson serves. The group added McKesson to its leak site and set a deadline of 1 September for the company to open ransom negotiations, reportedly demanding close to $55 million. McKesson has confirmed the intrusion and the exfiltration but has not confirmed the scale, the record count, or the ransom figure.
McKesson says its services remain operational, that orders are still being accepted and shipped throughout its distribution network, and it is offering affected individuals complimentary credit monitoring and identity protection. Healthcare data of this kind, personal identity information layered with prescription and treatment detail, is precisely what makes follow-on social engineering effective, more than a generic breach ever could. A caller who knows a patient's prescription history, insurer and billing status can manufacture urgency, posing as a pharmacy, an insurer or a debt collector, in a way a generic phishing attempt cannot. The breach is also the latest in a run of ShinyHunters campaigns this year built on the same technique: a phone call to an employee, framed as internal IT support, used to walk through or bypass an identity check designed to stop exactly that.
The defences that failed here were not weak by conventional standards. McKesson activated its incident response protocols, engaged outside cybersecurity experts, and disrupted the unauthorised activity once it was detected. Okta single sign-on is itself considered a strong identity control, and some form of multi-factor authentication was very likely in place. None of that mattered once an employee, on the phone with someone claiming to be internal IT, approved the access request themselves. The control existed. The verification of who was asking did not.
Approving an Okta single sign-on request that opens Salesforce and Snowflake to a new session is an execution event, not a routine login. Before that kind of access grant can go through, GoFirm sends a real-time push notification to the named authority on the account, IT security leadership, not the employee fielding the call, requiring biometric confirmation on their own registered device. If that confirmation does not arrive, the access request is blocked, regardless of how convincingly the caller impersonates internal IT or how much pressure they apply.
That separates the decision from the phone call entirely. The employee being vished cannot approve the access themselves, and the attacker on the other end of the line has no path to the authority's device. A ShinyHunters operator posing as IT support, however convincing the script, cannot produce that confirmation. The execution boundary holds regardless of how credible the impersonation appears.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Arntz, P. 2026. McKesson confirms cyber incident after ShinyHunters claims patient-data theft. Malwarebytes, 31 August 2026.
2. Arghire, I. 2026. McKesson Confirms Data Breach as Attacker Deadline Looms. SecurityWeek, 31 August 2026 (updated 1 September 2026).
Back to Blog
Case Studies·3 min read
Why did a phone call convince McKesson's Okta account to open Salesforce and Snowflake to ShinyHunters?
By GoFirm
