McKesson, the pharmaceutical and medical-supply distributor that serves most hospitals and pharmacies in North America, has confirmed unauthorized access to third-party applications supporting its Oncology and Multispecialty and Medical-Surgical business units. The extortion group ShinyHunters has claimed responsibility, saying it exfiltrated 284 million data records, including patient names, birth dates, Social Security numbers, Medicaid details, medical record numbers and medication information. ShinyHunters told reporters its initial access came through vishing calls that tricked McKesson staff into handing over credentials for the company’s Okta single sign-on, then pivoted into Salesforce and Snowflake environments. Francisco Fraga, McKesson’s Executive Vice President, Chief Information Officer and Chief Technology Officer, said in a customer notice that the company has “confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers” in those two business units.

The distinction between McKesson’s confirmed subset and ShinyHunters’ 284-million-record claim matters for every healthcare and pharma security leader watching this unfold. McKesson’s statement describes an incident scoped to specific business units and a subset of customers; the headline number comes entirely from the attacker, who has an incentive to inflate it for leverage. That gap is not unique to this breach. It is the same gap CyberTech has argued defines every ShinyHunters disclosure: a self-reported record count is a negotiating position, not a verified fact, until an independent forensic review or a regulator’s own count confirms it.

The one-two of vishing into Okta and then into downstream SaaS platforms is also the recurring pattern this group and its affiliates have used against other healthcare and benefits targets this year, including the slow-surfacing breach disclosure CyberTech covered at Paylogix. The original insight for defenders is not that SSO can be phished, which is not news, but that the attack chain increasingly treats the identity provider as a pivot point into whichever SaaS platform holds the richest data, meaning MFA policy and session controls on Salesforce, Snowflake and similar platforms now need to assume the SSO layer in front of them is not a reliable gate.

Source: McKesson