ShinyHunters Vished McKesson Staff, Claims 284M Records

The Register Security · Medium sophistication
Last updated August 31, 2026

Boston Scientific and McKesson disclosed separate cyber incidents impacting healthcare operations and sensitive data. Boston Scientific’s ongoing attack disrupted remote monitoring for some implanted cardiac devices, while McKesson confirmed unauthorized access to third-party apps tied to specific business units after ShinyHunters claimed it stole large volumes of patient data by voice-phishing employees.

Key findings

  • Boston Scientific said an ongoing cyberattack disrupted remote monitoring/activation workflows for some newly implanted cardiac devices, affecting data transmission to remote patient management systems.
  • McKesson confirmed unauthorized access to certain third-party applications and data exfiltration impacting a subset of customers in specific business units.
  • ShinyHunters claimed it accessed McKesson’s Snowflake and Salesforce instances and demanded $55.2M, alleging theft of extensive patient PII and health information.
  • ShinyHunters attributed the initial access to voice phishing of “multiple employees.”

Who’s being targeted

  • Commonly targeted roles: IT Helpdesk, Sales/CRM administrators, Operations teams with access to third-party SaaS apps, Healthcare administrative staff handling patient records, Security awareness training program participants.
  • Affected industries: Medical devices / MedTech, Pharmaceutical distribution and medical supplies, Oncology providers and clinical practices, Healthcare IT / patient data services.
  • Attack channels: vishing.
  • Impersonated: Snowflake or Salesforce support / security team.

Awareness takeaways

  • Treat unexpected ‘support’ phone calls as suspicious, verify the caller through official channels before taking any account actions.
  • Protect cloud business apps (like CRM/data platforms) as if they hold regulated data, because attackers may target them to steal patient information.
  • Don’t accept attacker ‘headline numbers’ or extortion claims at face value, focus on confirmed impact and evidence-driven incident response.

Red flags to watch for

  • Unsolicited phone call pressuring for urgent account verification
  • Request for MFA codes/approvals or credential-related actions over the phone
  • Caller pushes actions that bypass normal internal IT/security processes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

ShinyHunters claims they stole 284 million patient records after voice‑phishing McKesson staff. The call sounds legit: “Hi, this is support for your Snowflake or Salesforce environment. We’re seeing suspicious access and need to verify your account to prevent an outage.” Then they walk you into sharing MFA codes or approving prompts. That’s how they say they got into McKesson’s Snowflake and Salesforce, then exfiltrated data tied to specific business units. One pressured phone call, and suddenly patient PII and health info are flowing out the door. If you get an unexpected Snowflake or Salesforce support call, hang up and call back using our official help desk or vendor contacts. If they’re real, they’ll be there.

Categories

Similar attacks

Vishing + Phishing Drive Major Data Theft Claims

Vishing + Phishing Drive Major Data Theft Claims

This weekly threat bulletin highlights multiple real-world incidents, including a healthcare data breach claim where attackers reportedly used phone-based social engineering (vishing) to compromise identity accounts and access cloud apps. It also describes a large-scale “debt relief” email phishing…

August 31, 2026
Vishing Led to Okta Takeover at McKesson

Vishing Led to Okta Takeover at McKesson

McKesson disclosed a breach tied to unauthorized access of third-party applications and data theft affecting some customers. The ShinyHunters extortion group claims it used phone-based social engineering (vishing) to steal employee credentials, took over Okta single sign-on accounts, and then…

August 31, 2026
Wall Street Hit by Help Desk Impersonation Calls

Wall Street Hit by Help Desk Impersonation Calls

A real campaign of voice-phishing (vishing) calls targeted major hedge funds and private equity firms by impersonating internal IT/help desk staff. Victims were pressured into completing “routine” security steps and were sent to fake login pages that captured usernames, passwords, and MFA codes in…

August 20, 2026
Brinks Home Hit via Microsoft Entra Vishing

Brinks Home Hit via Microsoft Entra Vishing

Brinks Home says it is investigating a cybersecurity incident after the ShinyHunters group claimed it broke in by calling employees and tricking them into approving Microsoft Entra authentication actions. The attacker is threatening to publish data it claims to have stolen, including alleged…

July 31, 2026
BlackFile Vishing Poses as IT Support to Extort Firms

BlackFile Vishing Poses as IT Support to Extort Firms

Researchers say the BlackFile extortion group is actively targeting large financial and other organizations using voice-phishing calls where attackers impersonate IT support to get initial access. Victims are then pressured with multimillion-dollar extortion demands and, in some cases, escalations…

August 17, 2026
Vishing Console + Fake CCleaner Trap Users

Vishing Console + Fake CCleaner Trap Users

This bulletin highlights multiple real-world threats, including voice-phishing (vishing) operations that industrialize account takeovers and a fake CCleaner download site that installs spyware. The items provide concrete, repeatable lures (a vishing-driven takeover workflow and a lookalike software…

August 17, 2026