Sunday, August 30, 2026
LIVEGiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///
Subscribe
Cyber Security
Independent · Digital
The Hacking Post
CybersecurityAI-assisted

McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records

The extortion group says it moved about a terabyte of data out of Salesforce and Snowflake environments in four days, then demanded $55.2 million.

McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records

McKesson, one of the largest healthcare and pharmaceutical distributors in the United States, disclosed on August 28 that attackers had gained unauthorized access to third-party applications and exfiltrated data, in a filing that followed the standard SEC Form 8-K process for material incidents.

The ShinyHunters extortion group claimed responsibility and gave BleepingComputer a description of how it got in: voice phishing calls that compromised multiple employees' Okta single sign-on accounts. From there, the group says it pivoted into McKesson's Salesforce and Snowflake environments and pulled out close to a terabyte of data over four days, between August 21 and August 25.

The scale of what was allegedly taken is what separates this from a routine vendor breach. ShinyHunters says the haul includes 284 million records covering patient, billing and medical detail, drawn from third-party access rather than McKesson's core systems directly. None of that figure has been independently verified yet, and claims from extortion groups have a well-documented habit of running larger than what eventually gets confirmed. Still, even a fraction of 284 million records would rank among the largest healthcare-adjacent breaches disclosed this year.

The scale of what was allegedly taken is what separates this from a routine vendor breach.
Jason Ford · The Hacking Post

ShinyHunters says it contacted McKesson directly and demanded $55,236,150, giving the company 72 hours to respond. According to the group, McKesson never opened negotiations, and the deadline passed without a reply worth mentioning.

Vishing against SSO accounts, followed by lateral movement into Salesforce and Snowflake, has become close to a signature move for this cluster of threat actors this year, following nearly identical tactics used against other Salesforce customers throughout 2025 and into 2026. The pattern says less about any specific technical flaw in Okta, Salesforce or Snowflake, and more about how consistently a well-run phone call to a help desk still beats most technical defenses put in front of it.

Advertisement

Healthcare distributors sit in an odd spot for breach exposure. McKesson itself does not typically hold the deepest clinical detail on any individual patient, but it touches an enormous volume of billing and prescription-adjacent records that flow through its logistics and pharmacy-services operations. If the 284 million figure holds up even loosely under verification, the incident would sit alongside the largest healthcare-sector breaches disclosed in the United States this year, with the usual downstream consequence: state attorneys general opening inquiries, and a HIPAA breach notification process that, for a company this size, tends to stretch into a multi-year legal tail regardless of how quickly the initial intrusion gets contained.

Based on reporting by BleepingComputer.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories