The technical story behind the McKesson breach is almost aggressively simple, which is exactly why it should worry security teams more than another zero-day writeup would. According to reporting from Help Net Security and CyberInsider, ShinyHunters got its foothold by voice-phishing McKesson employees, then used the credentials it harvested to take over accounts on the company's Okta single sign-on. From Okta, the group pivoted into Salesforce and Snowflake - two systems that, between them, held the customer, patient and internal data that make McKesson a $300bn-revenue healthcare distributor rather than a target worth phoning about at all.
Two calls, four days, a terabyte
The attackers reportedly finished pulling data out of McKesson's environment on 25 August 2026, having spent roughly four days moving through Salesforce and Snowflake once inside. That timeline matters: four days inside two of the most heavily used SaaS platforms in enterprise IT is a long time for nobody to notice unusual data volume moving out, and it's the same pattern that has hit a string of other Salesforce customers over the past two years - identity compromise first, bulk export second, ransom note third.
284 million records is not 284 million patients
ShinyHunters' own figure - 284 million records - is the headline number, and it's also the one that needs the most caution. As several outlets covering the disclosure have noted, the count refers to rows of data, not unique individuals: a single patient can generate dozens of records across appointments, prescriptions, claims and physician notes. That doesn't make the exposure smaller in any way that matters to the people affected, but it does mean "284 million patients" - the version of this story that will circulate regardless - overstates the number of people by an unknown, possibly large, multiple. Precision here isn't pedantry; it's the difference between a notification list and a headline.
What was actually in the export
- Identity data: names, home addresses, dates of birth, Social Security numbers and phone numbers.
- Healthcare identifiers: patient IDs, medical record numbers, Medicaid information.
- Clinical detail: diagnoses, medications, allergies and, per some reporting, doctor-patient email correspondence.
- Business data: physician records, internal Salesforce objects and employee information.
That combination - SSNs sitting alongside clinical detail - is what turns a SaaS misconfiguration story into a durable identity-theft and medical-fraud problem for whoever ends up on the list, long after the news cycle moves on.
"We do not believe any action is required"
McKesson's public statement, attributed to CIO Francisco Fraga, is notably measured: "Based on the information currently available, we do not believe any action is required by our customers." That line will read very differently to two audiences. To customers whose own data sits inside McKesson's Salesforce instance, it may be accurate - McKesson's investigation is still early, and ShinyHunters' claims aren't independently verified. To the patients whose SSNs and medical histories are named in the group's own inventory, it reads like a company managing a disclosure timeline rather than a breach.
The ransom nobody answered
ShinyHunters reportedly demanded $55,236,150 - a startlingly specific figure - with a 72-hour deadline, issued once the group had finished extracting data on 25 August. McKesson, per the group's own account, never responded. Silence is a legitimate strategy against extortion actors with no reliable track record of deleting stolen data regardless of payment, but it also guarantees the data's next stop is a leak site or a resale, which is presumably why McKesson is disclosing now rather than waiting for that to happen on someone else's terms.
- Treat help-desk identity verification as a security control, not an IT convenience - vishing succeeds because it targets the human process around SSO, not the SSO technology itself.
- Apply the same monitoring rigor to Salesforce and Snowflake data-export volumes that you'd apply to a database dump from a core production system.
- Audit which employees and service accounts can bulk-export from your CRM and data warehouse, and whether that access is logged and alerted on in near real time.
- Build your breach notification plan assuming the worst-case interpretation of an attacker's own claims, not the most defensible internal one.
- Review OAuth grants and connected apps in Salesforce and Snowflake tenants - identity compromise upstream is only dangerous because of what it's connected to downstream.
This isn't the first time an extortion group has turned identity compromise into a Snowflake-shaped headline - we covered the fallout from a similar campaign in our piece on the Snowflake breach's MFA lessons. The pattern keeps repeating because the fix - phishing-resistant MFA, verified help-desk procedures, and export monitoring on SaaS platforms - keeps not getting prioritised until after the ransom note arrives. If you'd like help assessing where identity compromise could reach in your own SaaS estate, email sales@halfteck.com.