Vishing Led to Okta Takeover at McKesson

Help Net Security · High sophistication
Last updated September 1, 2026

McKesson disclosed a breach tied to unauthorized access of third-party applications and data theft affecting some customers. The ShinyHunters extortion group claims it used phone-based social engineering (vishing) to steal employee credentials, took over Okta single sign-on accounts, and then accessed Salesforce and Snowflake to exfiltrate roughly 1TB of data before demanding a $55M ransom.

How the Attack Reportedly Unfolded

According to claims from the ShinyHunters extortion group, the intrusion tied to McKesson began with vishing, or voice-based phishing calls, made directly to employees. The attackers reportedly used these calls to obtain login credentials, which were then used to take over Okta single sign-on accounts. From that foothold, the group claims it moved laterally into Salesforce and Snowflake environments and exfiltrated roughly 1TB of data over four days. McKesson has confirmed unauthorized access to certain third-party applications and data exfiltration affecting a subset of customers in specific business units, though the specific extortion claims, including the reported $55,236,150 ransom demand, have not been independently verified.

Why Vishing Works Against SSO Environments

Single sign-on systems like Okta are designed to simplify access, but that convenience becomes a liability once credentials are compromised. A single successful vishing call that captures one set of login details can open the door to multiple connected systems at once. This case illustrates why phone-based social engineering targeting helpdesk or support scenarios remains an effective technique: it exploits trust in a human voice rather than relying on a malicious link or attachment that email filters might catch.

What to Watch For

  • Unsolicited phone calls claiming to be IT support or helpdesk staff, especially those asking for passwords or login confirmation
  • Urgency or pressure tactics, such as warnings about account lockouts, used to rush a target into compliance
  • Callers whose identity cannot be verified through an internal directory or a known callback number
  • Requests to "confirm" authentication details over the phone, which legitimate IT support rarely needs to do

These patterns match the pretext described in this incident: a caller posing as IT or SSO support asking employees to confirm login details to avoid being locked out.

Building Resistance to Vishing-Driven Account Takeover

Organizations can reduce the risk of this attack path by reinforcing a few core practices. Employees should be trained to treat any unexpected request for credentials over the phone as suspicious, regardless of how legitimate the caller sounds, and to hang up and call back through a verified internal number. IT and IAM teams should require strict verification and escalation steps for any SSO or account-related change, since a single compromised credential can cascade into access across connected platforms like Salesforce and Snowflake. Just as important is a strong reporting culture: employees who suspect they received a social-engineering call should report it immediately so security teams can investigate and contain any potential exposure before it spreads further across the environment.

Key findings

  • McKesson detected the intrusion on August 25, 2026 and said the investigation is in early stages.
  • McKesson reported unauthorized access to certain third-party applications and exfiltration of certain data tied to a subset of customers in specific business units.
  • ShinyHunters claims initial access came from vishing calls to employees, followed by use of stolen credentials to take over Okta SSO accounts.
  • ShinyHunters claims it then accessed McKesson’s Salesforce and Snowflake environments and exfiltrated about 1TB of data over four days.
  • The group claims it demanded $55,236,150 with a 72-hour deadline and received no response.
  • Alleged stolen data includes sensitive patient information (e.g., SSNs, medical record numbers) and internal Salesforce records; claims are not independently verified.

Who’s being targeted

  • Commonly targeted roles: All employees, IT Helpdesk/Service Desk, Identity & Access Management (IAM), Sales Operations / Salesforce users, Data/Analytics teams using Snowflake, Security Operations.
  • Affected industries: Healthcare, Pharmaceutical distribution, Medical supplies distribution.
  • Attack channels: vishing.
  • Impersonated: IT/SSO support (Okta/Company helpdesk).

Red flags to watch for

  • Unsolicited phone call asking for passwords or verification details
  • Pressure/urgency about account lockouts or security issues
  • Caller identity cannot be verified via an internal directory or known callback number
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers reportedly gain initial access at McKesson?

ShinyHunters claims initial access came from vishing calls to employees, followed by use of stolen credentials to take over Okta SSO accounts.

What systems were allegedly accessed after the Okta takeover?

The group claims it then accessed McKesson's Salesforce and Snowflake environments and exfiltrated about 1TB of data over four days.

Has McKesson confirmed the extortion group's claims?

McKesson reported unauthorized access to certain third-party applications and data exfiltration affecting a subset of customers, but the extortion group's specific claims are not independently verified.

What should employees do if they get a suspicious support call asking for login details?

Employees should treat unexpected calls requesting passwords or verification details as suspicious and verify the caller through a trusted internal callback method before sharing anything.

Read the video transcript

A group called ShinyHunters says they breached McKesson with one thing: a fake IT phone call that stole an Okta login. The caller says, “Hi, this is IT support. There’s an issue with your single sign-on, can you confirm your Okta username and password so we don’t have to lock your account?” The moment they shared it, Okta was taken over, then Salesforce and Snowflake, and about a terabyte of data walked out. Here’s the trick: it feels routine, IT, Okta, account lockout, but real support will never ask for your password over the phone. An unsolicited call plus urgency about locking your account is your red flag. If anyone calls about Okta or single sign-on and asks for a password or code, hang up and call your real helpdesk using the number on the intranet, then report the call.

Categories

Similar attacks

Vishing + Phishing Drive Major Data Theft Claims

Vishing + Phishing Drive Major Data Theft Claims

This weekly threat bulletin highlights multiple real-world incidents, including a healthcare data breach claim where attackers reportedly used phone-based social engineering (vishing) to compromise identity accounts and access cloud apps. It also describes a large-scale “debt relief” email phishing…

August 31, 2026
ShinyHunters Vished McKesson Staff, Claims 284M Records

ShinyHunters Vished McKesson Staff, Claims 284M Records

Boston Scientific and McKesson disclosed separate cyber incidents impacting healthcare operations and sensitive data. Boston Scientific’s ongoing attack disrupted remote monitoring for some implanted cardiac devices, while McKesson confirmed unauthorized access to third-party apps tied to specific…

August 31, 2026
Brinks Home Hit via Microsoft Entra Vishing

Brinks Home Hit via Microsoft Entra Vishing

Brinks Home says it is investigating a cybersecurity incident after the ShinyHunters group claimed it broke in by calling employees and tricking them into approving Microsoft Entra authentication actions. The attacker is threatening to publish data it claims to have stolen, including alleged…

July 31, 2026
Helix Extortion Hit Uber Freight via Helpdesk Vishing

Helix Extortion Hit Uber Freight via Helpdesk Vishing

Uber Freight is investigating unauthorized access after the Helix extortion group claimed it stole nearly one million files from company cloud and email repositories. Google-linked research says the broader cluster (UNC6671) commonly gets in by calling employees and posing as IT helpdesk staff…

August 12, 2026
BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026