McKesson disclosed a breach tied to unauthorized access of third-party applications and data theft affecting some customers. The ShinyHunters extortion group claims it used phone-based social engineering (vishing) to steal employee credentials, took over Okta single sign-on accounts, and then accessed Salesforce and Snowflake to exfiltrate roughly 1TB of data before demanding a $55M ransom.
How the Attack Reportedly Unfolded
According to claims from the ShinyHunters extortion group, the intrusion tied to McKesson began with vishing, or voice-based phishing calls, made directly to employees. The attackers reportedly used these calls to obtain login credentials, which were then used to take over Okta single sign-on accounts. From that foothold, the group claims it moved laterally into Salesforce and Snowflake environments and exfiltrated roughly 1TB of data over four days. McKesson has confirmed unauthorized access to certain third-party applications and data exfiltration affecting a subset of customers in specific business units, though the specific extortion claims, including the reported $55,236,150 ransom demand, have not been independently verified.
Why Vishing Works Against SSO Environments
Single sign-on systems like Okta are designed to simplify access, but that convenience becomes a liability once credentials are compromised. A single successful vishing call that captures one set of login details can open the door to multiple connected systems at once. This case illustrates why phone-based social engineering targeting helpdesk or support scenarios remains an effective technique: it exploits trust in a human voice rather than relying on a malicious link or attachment that email filters might catch.
What to Watch For
- Unsolicited phone calls claiming to be IT support or helpdesk staff, especially those asking for passwords or login confirmation
- Urgency or pressure tactics, such as warnings about account lockouts, used to rush a target into compliance
- Callers whose identity cannot be verified through an internal directory or a known callback number
- Requests to "confirm" authentication details over the phone, which legitimate IT support rarely needs to do
These patterns match the pretext described in this incident: a caller posing as IT or SSO support asking employees to confirm login details to avoid being locked out.
Building Resistance to Vishing-Driven Account Takeover
Organizations can reduce the risk of this attack path by reinforcing a few core practices. Employees should be trained to treat any unexpected request for credentials over the phone as suspicious, regardless of how legitimate the caller sounds, and to hang up and call back through a verified internal number. IT and IAM teams should require strict verification and escalation steps for any SSO or account-related change, since a single compromised credential can cascade into access across connected platforms like Salesforce and Snowflake. Just as important is a strong reporting culture: employees who suspect they received a social-engineering call should report it immediately so security teams can investigate and contain any potential exposure before it spreads further across the environment.
Key findings
- McKesson detected the intrusion on August 25, 2026 and said the investigation is in early stages.
- McKesson reported unauthorized access to certain third-party applications and exfiltration of certain data tied to a subset of customers in specific business units.
- ShinyHunters claims initial access came from vishing calls to employees, followed by use of stolen credentials to take over Okta SSO accounts.
- ShinyHunters claims it then accessed McKesson’s Salesforce and Snowflake environments and exfiltrated about 1TB of data over four days.
- The group claims it demanded $55,236,150 with a 72-hour deadline and received no response.
- Alleged stolen data includes sensitive patient information (e.g., SSNs, medical record numbers) and internal Salesforce records; claims are not independently verified.
Who’s being targeted
- Commonly targeted roles: All employees, IT Helpdesk/Service Desk, Identity & Access Management (IAM), Sales Operations / Salesforce users, Data/Analytics teams using Snowflake, Security Operations.
- Affected industries: Healthcare, Pharmaceutical distribution, Medical supplies distribution.
- Attack channels: vishing.
- Impersonated: IT/SSO support (Okta/Company helpdesk).
Red flags to watch for
- Unsolicited phone call asking for passwords or verification details
- Pressure/urgency about account lockouts or security issues
- Caller identity cannot be verified via an internal directory or known callback number
Frequently asked questions
How did attackers reportedly gain initial access at McKesson?
ShinyHunters claims initial access came from vishing calls to employees, followed by use of stolen credentials to take over Okta SSO accounts.
What systems were allegedly accessed after the Okta takeover?
The group claims it then accessed McKesson's Salesforce and Snowflake environments and exfiltrated about 1TB of data over four days.
Has McKesson confirmed the extortion group's claims?
McKesson reported unauthorized access to certain third-party applications and data exfiltration affecting a subset of customers, but the extortion group's specific claims are not independently verified.
What should employees do if they get a suspicious support call asking for login details?
Employees should treat unexpected calls requesting passwords or verification details as suspicious and verify the caller through a trusted internal callback method before sharing anything.
Read the video transcript
A group called ShinyHunters says they breached McKesson with one thing: a fake IT phone call that stole an Okta login. The caller says, “Hi, this is IT support. There’s an issue with your single sign-on, can you confirm your Okta username and password so we don’t have to lock your account?” The moment they shared it, Okta was taken over, then Salesforce and Snowflake, and about a terabyte of data walked out. Here’s the trick: it feels routine, IT, Okta, account lockout, but real support will never ask for your password over the phone. An unsolicited call plus urgency about locking your account is your red flag. If anyone calls about Okta or single sign-on and asks for a password or code, hang up and call your real helpdesk using the number on the intranet, then report the call.