McKesson confirmed a cyber incident after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related records. The attacker claims the initial access came from phone-based social engineering (vishing) against employees to compromise Okta single sign-on accounts, then pivot into third-party systems and demand over $55 million.
Key findings
- McKesson reported “unauthorized access to third-party applications.”
- The extortion group ShinyHunters claimed theft of “roughly 284 million patient-related data records.”
- Attackers claim they used “vishing calls against employees” to compromise “Okta single sign-on accounts.”
- Attackers claim they then pivoted into “Salesforce and Snowflake environments.”
- Attackers demanded “over $55 million” after McKesson allegedly did not respond.
Who’s being targeted
- Commonly targeted roles: All employees, Service desk / IT support, Identity & access management (IAM) admins, Security operations, Executives (incident escalation awareness).
- Affected industries: Healthcare, Pharmaceutical distribution, Health data processors / SaaS (SSO/CRM/data platforms).
- Attack channels: vishing.
- Impersonated: Okta SSO support / internal IT helpdesk.
Awareness takeaways
- Treat unexpected “IT support” calls as untrusted, hang up and call back using a known internal number or the official support portal.
- Never share MFA codes or approve login prompts you didn’t initiate, even if the caller sounds legitimate.
- High-pressure payment/extortion demands are a sign you should escalate immediately to security and legal, not negotiate as an individual.
Red flags to watch for
- Unexpected phone call requesting login verification or MFA codes
- Pressure/urgency to act immediately to avoid account lockout
- Caller claims to be SSO/IT support but can’t be verified via known internal channels
Read the video transcript
Imagine one phone call leading to 284 million patient records at risk. That’s what ShinyHunters say happened to McKesson. The caller says, “Hi, this is IT Okta support, there’s an issue with your single sign-on. Read me that one-time code so we can restore access.” You read it… they own your Okta, then pivot into Salesforce and Snowflake. Here’s the trick: they sound like real IT, they know you use Okta, and they push urgency, “approve that MFA now or your account locks.” That’s exactly how they claim they got into McKesson’s Okta accounts. If anyone calls about Okta or MFA, your move is simple: hang up, then call IT back using our official helpdesk number or portal, never trust the number that called you.