McKesson Breach: How the Okta Vishing Attack Happened

An Okta vishing attack — a phone call, not a piece of malware — is how the extortion group ShinyHunters claims it broke into US healthcare and pharmaceutical distribution giant McKesson. McKesson has confirmed unauthorized access to third-party applications and data exfiltration, but has not confirmed the attack path itself: according to ShinyHunters’ own account, employees were called, impersonated IT support convinced them to hand over credentials or approve fraudulent single sign-on requests, and from there the group says it walked straight into McKesson’s Salesforce and Snowflake environments.
What Happened
ShinyHunters says it ran voice-phishing calls against multiple McKesson employees, using the calls to either extract login credentials directly or trick staff into approving fraudulent Okta single sign-on access requests. From there, the group claims it fully compromised McKesson’s Salesforce environment, including internal support cases, and exfiltrated roughly 1TB of data from the connected Snowflake data warehouse over four days, between August 21 and August 25, 2026 — a chain McKesson has not independently confirmed in this level of detail. The group also claims approximately 284 million records were taken, most likely a count of database rows rather than unique patients, and describes the data as including information on deceased and terminally ill patients, prescription and medication shipment records, billing data, employee records, internal Salesforce communications, and details on the providers and clinics that use McKesson’s services. None of these figures or data categories have been independently verified beyond ShinyHunters’ claims and secondary reporting.
ShinyHunters claims it demanded $55,236,150 from McKesson with a 72-hour deadline to respond; McKesson has not confirmed this figure, any negotiation, or any payment. McKesson’s own disclosure describes the incident as unauthorized access to third-party applications and data exfiltration affecting a subset of customers in its Oncology & Multispecialty and Medical-Surgical businesses. Separately, McKesson’s CTO has said customers may experience intermittent service degradation believed to be related to the incident, though the company says customers do not need to take action. No ransomware encryption has been reported in the sources reviewed, consistent with a data-theft extortion case rather than a locked-systems ransomware event.
Why It Matters
This Okta vishing attack is the second 2026 case DIESEC has tracked of an attacker defeating identity controls with a phone call instead of code, after the August 4 STAC4749 campaign that used Microsoft Teams impersonation to deploy Chaos ransomware within 17 hours. Both cases exploit the same underlying assumption: that a login approval request or credential reset arriving through a familiar-looking internal channel, from someone who sounds like a colleague or IT support, is safe to act on. For any DACH Mittelstand organization running Okta, Salesforce or Snowflake — an increasingly standard combination — the McKesson incident is a direct preview of what a successful social-engineering campaign against your own helpdesk and SSO provider looks like end to end.
What You Should Do Now
- Move Okta (or any SSO provider) away from push-approval MFA toward phishing-resistant, number-matching or FIDO2 hardware-key authentication wherever administratively feasible.
- Require mandatory callback verification through a known internal phone number before acting on any IT-support-initiated credential reset or access-approval request — never trust the number or identity the caller provides.
- Set up anomaly alerting for new device enrollments or session grants tied to helpdesk contact windows, and for unusual bulk data pulls from Salesforce or Snowflake shortly after an SSO session is established.
- Review your incident response playbook for vishing-specific scenarios; most tabletop exercises still assume a technical exploit as the initial access vector, not a phone call.
DIESEC Perspective
On ShinyHunters’ own account, every technical control in this story worked as designed — Okta authenticated the session, Salesforce and Snowflake granted access to an authenticated identity. The attack exploited weaknesses in human verification and identity workflows, not a technical flaw, and it is the kind of failure that no patch, no CVE fix and no software update will ever close. This also connects to the pay-or-not decision DIESEC covered in our May 20 post on Grafana and Instructure — the extortion ecosystem around brands like ShinyHunters is now a governance question every organization needs a pre-agreed answer to, before the 72-hour clock starts.
Not sure whether your helpdesk and SSO approval processes would withstand a determined vishing attempt? Contact DIESEC for a rapid identity-and-access social-engineering exposure review.
Sources: McKesson SEC 8-K disclosure | BleepingComputer | Cybernews
Published: 2026-09-02 | Category: Ransomware & Extortion | ~4 min read

