Data Breach

McKesson breach tied to ShinyHunters vishing campaign

⏱️ 4 min read📅 8/29/2026👁️ 1 views

McKesson breach linked to ShinyHunters vishing campaign

On August 25 2026 McKesson filed a Form 8‑K announcing that an unauthorized party had accessed several third‑party applications and walked away with data.

Why it matters

The company says the incident is unlikely to be material to its financial condition, but it did warn customers of possible intermittent service degradation – a red flag for any organization that relies on McKesson’s supply‑chain services.

Technical snapshot

ReliaQuest observed that the ShinyHunters group has been leveraging .claims domains to impersonate help‑desk numbers, a tactic that aligns with the vishing (voice‑phishing) campaign reported by Health‑ISAC.

  • Unauthorized access was detected in third‑party SaaS platforms, including Okta, Salesforce and Snowflake.
  • Attackers likely obtained employee credentials through social‑engineering phone calls, then used those accounts to reach into the services.

Unconfirmed claims from ShinyHunters include:

  • Stealing roughly 284 million patient‑related records.
  • Exfiltrating about 1 TB of data over four days (Aug 21‑25).
  • Compromising McKesson’s Salesforce environment and accessing support cases.
  • Using the domain mckesson.claims in the vishing effort.
  • Demanding a $55 million ransom with a 72‑hour deadline.

Who’s at risk

Any McKesson customer who interacts with the affected SaaS tools could see degraded service or, in the worst case, have personal health information exposed. Past ShinyHunters campaigns have hit Medtronic, DentaQuest, iRhythm, OneMedical and AdaptHealth – a pattern that suggests the group is targeting the broader health‑tech ecosystem.

Immediate defensive steps

  1. Audit all privileged accounts on Okta, Salesforce and Snowflake for anomalous logins.
  2. Enforce strict MFA for any remote access, especially for service‑desk or support personnel.
  3. Block or monitor traffic to any *.claims domains and educate users about vishing attempts.
  4. Refresh phishing‑simulation training with a focus on phone‑based social engineering.
  5. Review service‑level agreements with McKesson for breach‑notification clauses and contingency plans.
#McKesson#ShinyHunters#vishing#healthcare#third‑party SaaS#SEC filing