World Report Network
  • Home
  • Blog
  • About Us
  • Contact
Font ResizerAa
World Report NetworkWorld Report Network
  • Home
  • Blog
  • About Us
  • Contact
Search
  • Home
  • Blog
  • About Us
  • Contact
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Technology

A phone call, a single sign-on, and four days: inside the McKesson breach claim

Hailey King
Last updated: 2 September 2026 23:30
Hailey King
Share
Racks of servers in a data centre
Credit: National Institutes of Health (U.S.). Division of Computer Research and Technology (Public domain). Illustrative image.
SHARE

The extortion group ShinyHunters says it took roughly a terabyte of data from McKesson, the largest pharmaceutical distributor in the United States, over four days in late August. It puts the figure at 284 million records and has demanded $55,236,150.

Contents
What is confirmedWhat is claimed but not verifiedHow they say they got inWhy a distributor holds patient data at allWhat follows for people whose data may be involvedWhat to be sceptical ofWhat to watchWhy voice phishing works, and why training does not stop itWhat made the data reachable once they were insideHow to read an 8-KIf you may be affected

McKesson has confirmed an intrusion. It has not confirmed that number. The gap between those two statements is where this story sits — and it is worth being precise about, because attacker claims are routinely reported as findings.

What is confirmed

McKesson discovered a cybersecurity intrusion on 25 August 2026 and disclosed it publicly in an SEC Form 8-K filing on 28 August, with an operational update on 29 August and further detail on 31 August.

Francisco Fraga, McKesson’s Executive Vice President and Chief Information and Technology Officer, said on 31 August that unauthorised access to certain third-party applications and the exfiltration of certain data “was associated with a subset of customers.” He added: “We do not believe any action is required by our customers” at that stage.

The company had not, as of that date, determined whether the incident is “material” under SEC disclosure rules.

What is claimed but not verified

ShinyHunters asserts:

  • Approximately 1 terabyte of data taken between 21 and 25 August.
  • Roughly 284 million records.
  • Data drawn from McKesson’s Oncology & Multispecialty and Medical-Surgical business units.
  • Content including names, addresses, dates of birth, Social Security numbers, Medicaid numbers, medical record numbers, medication and allergy information, physician data and internal employee records.

These figures come from the people who carried out the attack, and they have an obvious incentive to inflate. Security outlets covering the incident, including HIPAA Journal and Help Net Security, have flagged the 284 million figure as the group’s claim rather than a confirmed count. This publication has not located an independent verification and does not present it as established.

The caution runs both ways. McKesson’s “subset of customers” is also not a number, and an investigation five days old is not a final account. Treat both characterisations as provisional.

How they say they got in

This is the part with practical value, because there is no exotic technology in it.

According to ShinyHunters, the sequence was:

  1. Voice phishing. Phone calls to McKesson employees, impersonating internal IT support, to obtain credentials.
  2. Single sign-on. Those credentials were used against Okta SSO accounts.
  3. Lateral reach. From SSO, access to the Salesforce and Snowflake environments.
  4. Bulk export. Data pulled from those platforms over four days.

No malware. No zero-day. A phone call.

Single sign-on is the pivot that turns one credential into many systems — which is its purpose, and also its risk profile. It reduces password fatigue and centralises control; it also means the blast radius of one compromised login is the whole federated estate. That trade-off is well understood in security teams and rarely visible to the people answering the phones.

ShinyHunters has used this pattern repeatedly, with claimed breaches at Ticketmaster, Salesforce customers, Medtronic, Abbott Laboratories and the Instructure/Canvas learning platform. The method’s persistence is the story: organisations keep investing in technical controls while the reliable entry point remains a human being under time pressure.

Why a distributor holds patient data at all

McKesson is not a hospital. It is a wholesaler, moving pharmaceuticals and medical supplies between manufacturers and pharmacies, clinics and hospitals.

But specialty distribution — oncology in particular — involves patient-level information. Drugs are dispensed against specific prescriptions, reimbursement runs through insurers, and patient support programmes are administered by the distributor. That work generates records with names, diagnoses, medications and insurance identifiers.

The result is a concentration point. A hospital breach exposes that hospital’s patients. A breach at a distributor serving thousands of providers has a different shape, which is why the claimed number is large enough to be plausible even if unverified.

What follows for people whose data may be involved

Medical data does not expire the way a card number does. A cancelled card is worthless in a week. A date of birth, a Social Security number and a diagnosis remain usable for years — for insurance fraud, for identity theft, and for targeted scams that are persuasive precisely because the caller knows a real medical detail.

Several US plaintiffs’ firms, including Migliaccio & Rathod, Ademi LLP and Emery Reddy, announced breach investigations by 31 August. That is the customary precursor to consumer class actions, and its presence indicates lawyers expect individual notifications to follow.

Formal notification letters and any HIPAA breach-notification response would normally be expected in the weeks after an investigation of this kind. Whether such notifications had been issued as of early September could not be confirmed.

What to be sceptical of

Three things, in the coverage of any incident like this:

  • The record count. It is the attacker’s number until someone else counts. Records are not people — one individual can generate many rows — so a record count is not a headcount.
  • “No evidence of misuse.” A standard phrase that means the investigation has not found misuse, not that none occurred.
  • Silence about payment. Companies rarely disclose whether they paid. Absence of a statement is not evidence either way.

What to watch

  • A materiality determination from McKesson under SEC rules, which would put a confirmed scale on the incident.
  • Individual notifications and any HIPAA breach report, which are how affected people find out.
  • Whether the data appears on leak sites — the usual next step when a ransom deadline passes unpaid.
  • Whether SSO and helpdesk verification practices change, at McKesson and elsewhere. This vector will keep working until they do.

Why voice phishing works, and why training does not stop it

The instinct is to treat this as a training failure. Someone gave away credentials over the phone; teach staff not to. That framing misunderstands the attack.

Vishing works because it exploits things organisations deliberately cultivate. Employees are told to be helpful and responsive. IT support genuinely does call staff. Password resets genuinely are handled by phone. An attacker impersonating the helpdesk is not asking someone to do something unusual — they are asking someone to do their job.

The calls that succeed are researched. The caller knows the target’s name, manager, department, the ticketing system in use, and often a genuine ongoing issue. They call during a busy period, reference something real, and create mild time pressure. Nothing in the interaction feels like an attack.

Multi-factor authentication, often assumed to close this door, does not by itself. If the attacker has the password and can keep the target on the phone, they trigger a login and ask the target to read back the code, or approve the push notification, “to verify the reset.” The second factor becomes one more thing to request.

What actually reduces this risk is structural rather than educational: out-of-band verification for any credential action, hardware security keys that cannot be relayed over a phone call, and helpdesk procedures that make identity verification a defined process rather than a judgement call. Awareness training helps at the margin. It does not fix a workflow that permits the outcome.

What made the data reachable once they were inside

Two platforms are named in the claimed sequence, and their presence explains the alleged volume.

Salesforce holds customer relationship data — accounts, contacts, cases, and in healthcare contexts frequently patient-linked records tied to support and reimbursement programmes.

Snowflake is a cloud data warehouse: a platform designed to hold very large datasets and let authorised users query and export them at scale.

A warehouse’s purpose is bulk analytical access. That is what it is for. It also means a single authenticated session can extract volumes that would take a long time to assemble from an operational system record by record. The efficiency that makes the platform useful is the efficiency that makes a compromised account expensive.

The mitigations are known and unglamorous: network policies restricting where a session may originate, query-volume monitoring that flags anomalous extraction, short-lived credentials, and separation between accounts that can query and accounts that can export in bulk.

How to read an 8-K

The SEC filing is the most reliable document in this story, and knowing how to read one is useful beyond this incident.

US-listed companies must disclose material cybersecurity incidents on Form 8-K, generally within four business days of determining materiality. That last word carries the weight: the clock runs from the materiality determination, not from discovery, and companies have latitude in when that determination is made.

Practical consequences for readers:

  • An 8-K is a legal minimum, not a full account. It states what must be stated.
  • “Has not determined materiality” is a real status, not evasion — but it is also the status that keeps the detailed disclosure clock from starting.
  • Later amendments matter. The fuller picture usually arrives in an amended filing or a quarterly report weeks later, when nobody is covering it.

If you may be affected

Nobody can currently say who is in the exposed set. General measures that are proportionate while that is unresolved:

  • Expect targeted approaches. Contact that cites a genuine medication, condition or provider is more persuasive than generic fraud. Treat unsolicited contact as unverified regardless of what the caller appears to know, and call back on a number you obtained independently.
  • Watch insurance statements, not just bank statements. Medical identity theft shows up as claims for care you did not receive, and it can corrupt your medical record as well as your finances.
  • Consider a credit freeze if Social Security numbers were in scope. It is free in the US and reversible.
  • Read the notification letter if one arrives. It will state what was actually exposed for you specifically, which is far more useful than any figure in the press.

Sources

  • HIPAA Journal, “ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson,” 31 August 2026 — hipaajournal.com
  • Help Net Security, “ShinyHunters claims it stole 284 million patient records from McKesson,” 31 August 2026 — helpnetsecurity.com
  • Malwarebytes, “McKesson confirms cyber incident after ShinyHunters claims patient-data theft,” 31 August 2026 — malwarebytes.com
  • ClassAction.org, “McKesson Corporation Data Breach Reported,” August 2026 — classaction.org
TAGGED:CybersecurityData BreachHealthcareMcKessonPrivacyShinyHunters
Share This Article
Email Copy Link Print
Previous Article High-voltage electricity transmission lines America’s biggest grid operator will start switching off data centres in 2027
Next Article An open-plan office workspace 140,000 tech jobs are gone this year. The AI explanation keeps outrunning the evidence.
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad image

You Might Also Like

Nvidia hardware and corporate imagery
Technology

Nvidia made $96 billion in a quarter. Its CFO used the call to rebut a charge nobody had put to her.

By Hailey King
An open-plan office workspace
Technology

140,000 tech jobs are gone this year. The AI explanation keeps outrunning the evidence.

By Hailey King
High-voltage electricity transmission lines
Technology

America’s biggest grid operator will start switching off data centres in 2027

By Hailey King
World Report Network
Navigation
  • Home
  • Blog
  • About Us
  • Contact
Usefull Links
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • DMCA Policy

© World Report Network. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?