McKesson breach started with vishing against Okta SSO, then reached Salesforce and Snowflake
ShinyHunters social-engineered McKesson employees from a lookalike domain, took their Okta credentials, and used the SSO session to reach Salesforce and Snowflake. The group claims roughly 284 million records and demanded 55 million dollars.
McKesson disclosed on August 28, 2026 that attackers gained unauthorized access to third-party applications and stole data. Reporting indicates the entry point was voice phishing against multiple employees from the lookalike domain mckesson[.]claims, matching a documented ShinyHunters pattern, with the callers impersonating help desk and IT staff. That yielded employee Okta credentials, and the resulting SSO session opened Salesforce, including support cases, and Snowflake. Exfiltration ran August 21 to 25 and totalled roughly one terabyte; McKesson discovered it on August 25. ShinyHunters claims about 284 million records, a raw row count rather than unique individuals, and demanded 55.2 million dollars.
Why it matters
Nothing was exploited here. A human answered the phone, and single sign-on did the rest, which is the trade every SSO deployment makes: one credential, many downstream systems, and a blast radius equal to the union of them. Healthcare distribution makes the data unusually sensitive, but the mechanics are identical to the Scattered Spider help desk playbook and to the Snowflake 2024 campaign. The controls that would have changed the outcome are known: phishing-resistant MFA so a relayed code is worthless, a help desk identity-verification procedure that does not rely on caller-supplied facts, step-up authentication on data-platform access, and egress monitoring on SaaS connectors sized to catch a terabyte moving over four days.
Source: BleepingComputer
Related on Start with Identity
- BlogThe Snowflake attacker pleaded guilty, two years after stale credentials did the work
Connor Riley Moucka pleaded guilty in Seattle federal court on August 6, 2026 to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the
- BlogOkta ships Agent SSO, making AI agents first-class identities instead of static API keys
Okta made Agent SSO generally available on August 24, 2026, registering AI agents in Universal Directory with short-lived governed tokens and pushing Cross App
- BlogShinyHunters claims an Ernst & Young breach that started with someone else's stolen credentials
The extortion group says it used credentials obtained through a supply-chain attack, source undisclosed, to reach EY's Jira, GitHub, and Azure environments, and
- BreachOkta's 2023 support-system breach: when your IdP gets phished
How attackers used a stolen credential to read Okta support cases and harvest session tokens, why HAR files were the weak link, and what it taught the industry
- RankingBest Enterprise SSO & SCIM Platforms for B2B SaaS: Top 5
The best enterprise SSO and SCIM platforms for B2B SaaS in 2026: WorkOS, SSOJet, Auth0, FusionAuth, and Keycloak, ranked for teams that already have core auth a
- ArticleEnterprise Readiness for B2B SaaS: SSO, SCIM, and Audit Logs
The identity features that turn a B2B SaaS product into one enterprises will buy: SAML and OIDC single sign-on, SCIM provisioning, audit logs, role-based access