Start with Identity
← Blog
News

McKesson breach started with vishing against Okta SSO, then reached Salesforce and Snowflake

ShinyHunters social-engineered McKesson employees from a lookalike domain, took their Okta credentials, and used the SSO session to reach Salesforce and Snowflake. The group claims roughly 284 million records and demanded 55 million dollars.

By SWI Community TeamAug 28, 2026Updated Aug 29, 2026

McKesson disclosed on August 28, 2026 that attackers gained unauthorized access to third-party applications and stole data. Reporting indicates the entry point was voice phishing against multiple employees from the lookalike domain mckesson[.]claims, matching a documented ShinyHunters pattern, with the callers impersonating help desk and IT staff. That yielded employee Okta credentials, and the resulting SSO session opened Salesforce, including support cases, and Snowflake. Exfiltration ran August 21 to 25 and totalled roughly one terabyte; McKesson discovered it on August 25. ShinyHunters claims about 284 million records, a raw row count rather than unique individuals, and demanded 55.2 million dollars.

Why it matters

Nothing was exploited here. A human answered the phone, and single sign-on did the rest, which is the trade every SSO deployment makes: one credential, many downstream systems, and a blast radius equal to the union of them. Healthcare distribution makes the data unusually sensitive, but the mechanics are identical to the Scattered Spider help desk playbook and to the Snowflake 2024 campaign. The controls that would have changed the outcome are known: phishing-resistant MFA so a relayed code is worthless, a help desk identity-verification procedure that does not rely on caller-supplied facts, step-up authentication on data-platform access, and egress monitoring on SaaS connectors sized to catch a terabyte moving over four days.

Source: BleepingComputer

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.