McKesson Hit via Vishing to Okta Accounts

About DFIR · Medium sophistication
Last updated September 1, 2026

McKesson confirmed a cyber incident after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related records. The attacker claims the initial access came from phone-based social engineering (vishing) against employees to compromise Okta single sign-on accounts, then pivot into third-party systems and demand over $55 million.

Key findings

  • McKesson reported “unauthorized access to third-party applications.”
  • The extortion group ShinyHunters claimed theft of “roughly 284 million patient-related data records.”
  • Attackers claim they used “vishing calls against employees” to compromise “Okta single sign-on accounts.”
  • Attackers claim they then pivoted into “Salesforce and Snowflake environments.”
  • Attackers demanded “over $55 million” after McKesson allegedly did not respond.

Who’s being targeted

  • Commonly targeted roles: All employees, Service desk / IT support, Identity & access management (IAM) admins, Security operations, Executives (incident escalation awareness).
  • Affected industries: Healthcare, Pharmaceutical distribution, Health data processors / SaaS (SSO/CRM/data platforms).
  • Attack channels: vishing.
  • Impersonated: Okta SSO support / internal IT helpdesk.

Awareness takeaways

  • Treat unexpected “IT support” calls as untrusted, hang up and call back using a known internal number or the official support portal.
  • Never share MFA codes or approve login prompts you didn’t initiate, even if the caller sounds legitimate.
  • High-pressure payment/extortion demands are a sign you should escalate immediately to security and legal, not negotiate as an individual.

Red flags to watch for

  • Unexpected phone call requesting login verification or MFA codes
  • Pressure/urgency to act immediately to avoid account lockout
  • Caller claims to be SSO/IT support but can’t be verified via known internal channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine one phone call leading to 284 million patient records at risk. That’s what ShinyHunters say happened to McKesson. The caller says, “Hi, this is IT Okta support, there’s an issue with your single sign-on. Read me that one-time code so we can restore access.” You read it… they own your Okta, then pivot into Salesforce and Snowflake. Here’s the trick: they sound like real IT, they know you use Okta, and they push urgency, “approve that MFA now or your account locks.” That’s exactly how they claim they got into McKesson’s Okta accounts. If anyone calls about Okta or MFA, your move is simple: hang up, then call IT back using our official helpdesk number or portal, never trust the number that called you.

Similar attacks

Vishing + Phishing Drive Major Data Theft Claims

Vishing + Phishing Drive Major Data Theft Claims

This weekly threat bulletin highlights multiple real-world incidents, including a healthcare data breach claim where attackers reportedly used phone-based social engineering (vishing) to compromise identity accounts and access cloud apps. It also describes a large-scale “debt relief” email phishing…

August 31, 2026
Vishing Led to Okta Takeover at McKesson

Vishing Led to Okta Takeover at McKesson

McKesson disclosed a breach tied to unauthorized access of third-party applications and data theft affecting some customers. The ShinyHunters extortion group claims it used phone-based social engineering (vishing) to steal employee credentials, took over Okta single sign-on accounts, and then…

August 31, 2026
Brinks Home Hit via Microsoft Entra Vishing

Brinks Home Hit via Microsoft Entra Vishing

Brinks Home says it is investigating a cybersecurity incident after the ShinyHunters group claimed it broke in by calling employees and tricking them into approving Microsoft Entra authentication actions. The attacker is threatening to publish data it claims to have stolen, including alleged…

July 31, 2026
ShinyHunters Vished McKesson Staff, Claims 284M Records

ShinyHunters Vished McKesson Staff, Claims 284M Records

Boston Scientific and McKesson disclosed separate cyber incidents impacting healthcare operations and sensitive data. Boston Scientific’s ongoing attack disrupted remote monitoring for some implanted cardiac devices, while McKesson confirmed unauthorized access to third-party apps tied to specific…

August 31, 2026
Wall Street Hit by Help Desk Impersonation Calls

Wall Street Hit by Help Desk Impersonation Calls

A real campaign of voice-phishing (vishing) calls targeted major hedge funds and private equity firms by impersonating internal IT/help desk staff. Victims were pressured into completing “routine” security steps and were sent to fake login pages that captured usernames, passwords, and MFA codes in…

August 20, 2026
ReliaQuest Employee Tricked Into Okta SSO Login

ReliaQuest Employee Tricked Into Okta SSO Login

ReliaQuest confirmed an employee was socially engineered into entering their password on a fake SSO page and approving an MFA push, giving attackers a brief “view only” session in the company’s identity dashboard. The attackers allegedly impersonated a named member of the security team over the…

August 25, 2026