ShinyHunters Vished McKesson Staff, Claims 284M Records

The Register Security · Medium sophistication
Last updated August 31, 2026

Boston Scientific and McKesson disclosed separate cyber incidents impacting healthcare operations and sensitive data. Boston Scientific’s ongoing attack disrupted remote monitoring for some implanted cardiac devices, while McKesson confirmed unauthorized access to third-party apps tied to specific business units after ShinyHunters claimed it stole large volumes of patient data by voice-phishing employees.

Key findings

  • Boston Scientific said an ongoing cyberattack disrupted remote monitoring/activation workflows for some newly implanted cardiac devices, affecting data transmission to remote patient management systems.
  • McKesson confirmed unauthorized access to certain third-party applications and data exfiltration impacting a subset of customers in specific business units.
  • ShinyHunters claimed it accessed McKesson’s Snowflake and Salesforce instances and demanded $55.2M, alleging theft of extensive patient PII and health information.
  • ShinyHunters attributed the initial access to voice phishing of “multiple employees.”

Who’s being targeted

  • Commonly targeted roles: IT Helpdesk, Sales/CRM administrators, Operations teams with access to third-party SaaS apps, Healthcare administrative staff handling patient records, Security awareness training program participants.
  • Affected industries: Medical devices / MedTech, Pharmaceutical distribution and medical supplies, Oncology providers and clinical practices, Healthcare IT / patient data services.
  • Attack channels: vishing.
  • Impersonated: Snowflake or Salesforce support / security team.

Awareness takeaways

  • Treat unexpected ‘support’ phone calls as suspicious, verify the caller through official channels before taking any account actions.
  • Protect cloud business apps (like CRM/data platforms) as if they hold regulated data, because attackers may target them to steal patient information.
  • Don’t accept attacker ‘headline numbers’ or extortion claims at face value, focus on confirmed impact and evidence-driven incident response.

Red flags to watch for

  • Unsolicited phone call pressuring for urgent account verification
  • Request for MFA codes/approvals or credential-related actions over the phone
  • Caller pushes actions that bypass normal internal IT/security processes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

ShinyHunters claims they stole 284 million patient records after voice‑phishing McKesson staff. The call sounds legit: “Hi, this is support for your Snowflake or Salesforce environment. We’re seeing suspicious access and need to verify your account to prevent an outage.” Then they walk you into sharing MFA codes or approving prompts. That’s how they say they got into McKesson’s Snowflake and Salesforce, then exfiltrated data tied to specific business units. One pressured phone call, and suddenly patient PII and health info are flowing out the door. If you get an unexpected Snowflake or Salesforce support call, hang up and call back using our official help desk or vendor contacts. If they’re real, they’ll be there.

Categories

Similar attacks

Vishing + Phishing Drive Major Data Theft Claims

Vishing + Phishing Drive Major Data Theft Claims

This weekly threat bulletin highlights multiple real-world incidents, including a healthcare data breach claim where attackers reportedly used phone-based social engineering (vishing) to compromise identity accounts and access cloud apps. It also describes a large-scale “debt relief” email phishing…

August 31, 2026
Vishing Led to Okta Takeover at McKesson

Vishing Led to Okta Takeover at McKesson

McKesson disclosed a breach tied to unauthorized access of third-party applications and data theft affecting some customers. The ShinyHunters extortion group claims it used phone-based social engineering (vishing) to steal employee credentials, took over Okta single sign-on accounts, and then…

August 31, 2026
McKesson Hit via Vishing to Okta Accounts

McKesson Hit via Vishing to Okta Accounts

McKesson confirmed a cyber incident after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related records. The attacker claims the initial access came from phone-based social engineering (vishing) against employees to compromise Okta single sign-on accounts, then pivot…

September 1, 2026
Wall Street Hit by Help Desk Impersonation Calls

Wall Street Hit by Help Desk Impersonation Calls

A real campaign of voice-phishing (vishing) calls targeted major hedge funds and private equity firms by impersonating internal IT/help desk staff. Victims were pressured into completing “routine” security steps and were sent to fake login pages that captured usernames, passwords, and MFA codes in…

August 20, 2026
Brinks Home Hit via Microsoft Entra Vishing

Brinks Home Hit via Microsoft Entra Vishing

Brinks Home says it is investigating a cybersecurity incident after the ShinyHunters group claimed it broke in by calling employees and tricking them into approving Microsoft Entra authentication actions. The attacker is threatening to publish data it claims to have stolen, including alleged…

July 31, 2026
Fake IT Support Drives Pix Fraud in Brazil

Fake IT Support Drives Pix Fraud in Brazil

A financially motivated group called Breeze Comet targeted Brazilian financial and retail organizations by impersonating IT support and convincing staff to install remote-access tools. After gaining access, the attackers moved into internal payment systems (like Pix/STR/Boleto) and executed…

September 1, 2026