McKesson is one of the largest healthcare companies in the United States. It distributes pharmaceuticals and medical supplies to hospitals, pharmacies, and clinics nationwide. Like most companies of its size, the data behind all of is stored in enterprise cloud platforms. The recent breach contains approximately 248 million patient-related records.
The Attack Itself Was Surprisingly Simple
The extortion group ShinyHunters told BleepingComputer and TechCrunch that it gained access to McKesson’s cloud environments through voice phishing (vishing) against multiple McKesson employees. The employees disclosed their credentials. ShinyHunters then used those credentials to take over Okta single sign-on accounts, pivoted to McKesson’s Salesforce and Snowflake environments, and spent four days in August exfiltrating roughly one terabyte of data before McKesson detected the intrusion.
The group claims the stolen Snowflake data contains approximately 284 million patient-related records. That figure represents whole database sections rather than confirmed unique patients, and the full scope of who’s affected remains under investigation. What is confirmed is that the data includes names, dates of birth, addresses, Social Security numbers, diagnoses, medications and allergy information, appointment notes, and physician communications.
ShinyHunters subsequently demanded $55,236,150 and gave McKesson 72 hours to respond. McKesson reportedly never answered.
Why It Worked
The breach didn’t start with a technical failure. It started with a conversation. Once they had valid credentials and access to the Okta single sign-on accounts, their activity initially looked like normal employee behavior, because the systems recognized legitimate accounts.
This is social engineering at its best (worst), and it’s consistently one of the most effective attack techniques in use right now. The 2026 Verizon DBIR found that the human element was involved in 62% of all confirmed breaches. ShinyHunters has used this method before. There was Medtronic in April and Exact Sciences in July. They’ve also been publicly linked to some of the largest healthcare breaches of the past two years.
The technique works because it targets something security tools can’t cover: people’s willingness to help when someone calls with a convincing story.
The specific method here is a variant that’s getting more attention because it’s harder to defend against than email phishing. An email has visual cues, like a slightly wrong domain, a suspicious link, or a tone that feels off. A phone call is immediate, personal, and puts the target on the spot. There’s no time to hover over a link before responding. Attackers who are good at this can establish credibility quickly and create enough urgency that an employee hands over credentials before they’ve thought it through.
Social engineering is consistently how attackers get in, and it’s the one thing technical security tools can’t stop on their own. If you want to understand how your employees would respond under pressure, MainNerve offers social engineering assessments that give you a real answer. Let’s talk about what that looks like.
Â
The Reality of Cloud Platforms
Once ShinyHunters had working Okta credentials, the rest followed a pathway we’ve seen in other major breaches, most notably the Snowflake-related wave in 2024 that hit Ticketmaster, AT&T, and others. Compromised credentials opened the door to cloud platforms that hold far more data than any single on-premises system would have.
This is the double-edged reality of modern cloud environments. Consolidating data into platforms like Snowflake and Salesforce makes it easier to analyze, share, and work with across an organization. It also means that a single set of compromised credentials can open a door to a large amount of information.
McKesson’s Salesforce environment held support cases and operational data. Its Snowflake environment held the bulk of the patient records.
The shared responsibility model means cloud providers secure the infrastructure, but customers are responsible for everything inside their accounts, including what happens when an employee’s credentials get stolen. Snowflake and Salesforce won’t call you when someone logs into your environment from an unusual location using credentials they shouldn’t have. That’s your problem to catch.
For healthcare organizations, the exposure isn’t just reputational. Protected health information carries HIPAA obligations regardless of where it lives. A breach of Snowflake-hosted patient data is still a HIPAA breach. Notification requirements, regulatory exposure, and potential fines apply regardless of which cloud service held the data when it was taken.
What This Means Beyond Healthcare
McKesson is a healthcare company, and the data exposed is health data, which makes it a healthcare story. But the attack method is not a healthcare-specific problem.
Any organization that uses cloud-based platforms to store or process significant data, such as Salesforce, Snowflake, or any major SaaS environment, and relies on single sign-on for access is running the same basic architecture that ShinyHunters exploited here. The attack didn’t require knowledge of healthcare systems specifically. It required convincing a handful of employees to hand over credentials, then using those credentials to access whatever they could reach.
Most small and mid-sized businesses now use some combination of cloud-based CRM, accounting software, file storage, HR platforms, and productivity tools. Each application holds significant amounts of customer, employee, or operational data. Each of them is accessible with the right credentials. Each is a target if attackers can obtain those credentials through a convincing phone call or a well-timed phishing email.
The businesses that survive this kind of attack are the ones where stolen credentials don’t open the full door. Multi-factor authentication means a valid username and password isn’t enough; the attacker also needs the second factor, which they typically don’t have. MFA wouldn’t have prevented the social engineering attempt in the McKesson breach, but it would have made the stolen credentials far less useful once obtained.
We say this often, and we’ll keep saying it: MFA on every account that matters is still the single highest-return security action most organizations aren’t taking.
Beyond MFA, the McKesson timeline raises a specific question for your own environment. An attacker was inside McKesson’s cloud platforms for four days before the breach was detected. Four days of data exfiltration. Visibility into what’s happening inside your cloud environments, including who is accessing what data and from where, is what catches this kind of activity early enough to matter.
They’re Not Getting More Creative
ShinyHunters hit Medtronic in April, Exact Sciences in July, and McKesson in August. That’s three major healthcare organizations in five months, all through social engineering and credential theft rather than technical exploits.
The HIPAA Journal noted that McKesson’s stolen data also includes 6.4 million unique email addresses, each one a potential target for follow-on phishing campaigns using the medical information that was just taken.
Healthcare is a particularly attractive target because the data is valuable, the organizations are large and complex, and the human element creates more opportunities for social engineering than almost any other industry. But the technique isn’t unique to healthcare, and the exposure model isn’t either.
The employees who handed over credentials at McKesson probably weren’t careless. They were likely convinced by a caller who had done their homework, used the right terminology, created the right amount of urgency, and made the request sound routine. That’s what good social engineering looks like. It doesn’t feel like an attack until after it’s over.
Training employees to recognize these attempts, pause, verify caller identity through a separate channel before providing any credentials or access, and understand that IT departments and legitimate vendors don’t typically call and ask for logins on the spot is the most direct countermeasure available. It won’t catch every attempt. But it raises the difficulty enough that the attacker looks for another avenue, and it’s the layer of defense no technical tool can replace.
The McKesson breach didn’t require a sophisticated exploit, just a convincing phone call. MainNerve has been helping organizations assess and strengthen their human security layer for over 20 years. If you want to understand how your team would respond under pressure, we’re glad to help. Reach out today to start the process. Or call us at 833-847-3280.