{"id":1300,"date":"2026-09-01T12:20:51","date_gmt":"2026-09-01T06:50:51","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1300"},"modified":"2026-09-02T10:17:24","modified_gmt":"2026-09-02T04:47:24","slug":"mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/","title":{"rendered":"McKesson Breach: How a Vishing Call Turned Into an Okta and Salesforce Incident"},"content":{"rendered":"<p>The McKesson breach became public on August 28, 2026, three days after McKesson discovered the incident affecting its information systems. McKesson disclosed it via an SEC filing and confirmed an investigation is underway, but has not named the compromised applications, entry method, or exposed data categories.<\/p>\n<p>ShinyHunters, the <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-cyber-extortion\/\">extortion<\/a> group that claims responsibility for the incident, filled in gaps McKesson left open. It told BleepingComputer it vished multiple employees, hijacked their Okta single sign-on accounts, and used those sessions to reach McKesson&#8217;s Salesforce and Snowflake environments, claiming roughly 1 TB of data was stolen, including 284 million patient-related records.<\/p>\n<p>Security teams should treat the confirmed facts and the attacker&#8217;s claims separately. McKesson has verified the intrusion and <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-data-theft\/\">data theft<\/a>, but not how attackers got in or what they took. That gap holds the real lessons for enterprise identity and SaaS security.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><\/p>\n<h2>What McKesson has confirmed, and what it hasn&#8217;t<\/h2>\n<p>McKesson&#8217;s own statement stays narrow. Here&#8217;s what the company has confirmed:<\/p>\n<ul>\n<li>It discovered the incident on August 25, 2026.<\/li>\n<li>It immediately activated<a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-incident-response-ir\/\"> incident response<\/a> protocols and engaged outside cybersecurity experts.<\/li>\n<li>It describes the incident as unauthorized access to third-party applications that led to <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-data-exfiltration\/\">data exfiltration<\/a>.<\/li>\n<li>It currently tells customers no action is required on their part and says it isn&#8217;t proactively disconnecting systems.<\/li>\n<\/ul>\n<h3>What the company has not confirmed carries equal weight for defenders:<\/h3>\n<ul>\n<li>It hasn&#8217;t named the compromised third-party applications.<\/li>\n<li>It hasn&#8217;t described the intrusion vector.<\/li>\n<li>It hasn&#8217;t specified which data categories left the environment.<\/li>\n<\/ul>\n<p>Every technical detail beyond &#8220;<a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-unauthorized-access\/\">unauthorized access<\/a> and exfiltration&#8221; currently comes from the threat actor, not McKesson.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Real-Time-Threat-Detection-Hexnode-UEM-XDR-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Vulnerability Assessment with Hexnode UEM + XDR<\/h4><p>Real-time threat detection: hunt vulnerabilities before attackers exploit them.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/real-time-threat-detection\/\" aria-label=\"Vulnerability Assessment with Hexnode UEM + XDR\"><\/a><\/div><\/div><\/div>\n<h2>ShinyHunters&#8217; account of the McKesson breach<\/h2>\n<p>ShinyHunters told BleepingComputer it ran voice-phishing calls against multiple McKesson employees, reportedly using a lookalike domain resembling mckesson[.]claims to support the pretext. The group&#8217;s claimed <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-attack-chain\/\">attack chain<\/a> runs like this:<\/p>\n<ul>\n<li>It vished multiple McKesson employees to gain trust and extract credentials or session approvals.<\/li>\n<li>The calls allegedly compromised several employees&#8217; Okta single sign-on accounts.<\/li>\n<li>It pivoted from Okta into McKesson&#8217;s Salesforce environment, including support cases.<\/li>\n<li>It also reached McKesson&#8217;s Snowflake data platform.<\/li>\n<li>It exfiltrated close to 1 TB of data between August 21 and August 25, 2026.<\/li>\n<li>It claims roughly 284 million records, though it has clarified this counts raw data rows, not unique patients.<\/li>\n<\/ul>\n<h3>The group claims the stolen data includes:<\/h3>\n<ul>\n<li>Patient identifiers and Social Security numbers<\/li>\n<li>Medical record numbers and Medicaid numbers<\/li>\n<li>Medication and allergy details<\/li>\n<li>Appointment records and physician information<\/li>\n<li>Internal Salesforce communications<\/li>\n<li>Records tied to deceased and terminally ill patients<\/li>\n<\/ul>\n<p>It also says it contacted McKesson after the theft and demanded $55,236,150, giving the company a 72-hour window to respond. BleepingComputer has not independently verified the stolen-data claims, and McKesson has not confirmed them either.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint.png?format=webp\" class=\"resource-box__image\" alt=\"the cybersecurity blueprint\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"the cybersecurity blueprint\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            The Cybersecurity Blueprint\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Build a strong cybersecurity strategy with key statistics, attack trends, and practical implementation steps for businesses.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/the-cybersecurity-blueprint-how-to-adopt-the-right-cybersecurity-strategy-for-your-business\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Why the Okta-to-SaaS pattern keeps working<\/h2>\n<p>Vishing-driven Okta compromise followed by Salesforce or Snowflake access is now a recurring ShinyHunters signature, not an isolated technique. Recent healthcare-related targets linked in reporting to ShinyHunters data-theft activity include Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth.<\/p>\n<p>The claimed intrusion relied on social engineering rather than a publicly disclosed software exploit.<\/p>\n<ul>\n<li>A convincing phone call gets an employee to approve an <a href=\"https:\/\/www.hexnode.com\/blogs\/single-sign-on-its-relevance\/\">SSO<\/a> session or reset a credential.<\/li>\n<li>The attacker inherits whatever access that identity already has, often across multiple connected SaaS platforms.<\/li>\n<li>Once inside a legitimate SSO session, attackers don&#8217;t need malware to move. They can browse Salesforce objects, query Snowflake tables, and export data using the same interfaces employees use every day.<\/li>\n<\/ul>\n<p>That combination makes detection dependent on spotting anomalous behavior inside trusted sessions, not on catching malicious files.<\/p>\n<h2>Reported attack chain: confirmed vs. claimed<\/h2>\n<table style=\"width: 92.346%;\">\n<thead>\n<tr>\n<th style=\"width: 30.1694%; text-align: left;\">Stage<\/th>\n<th style=\"width: 32.6532%; text-align: left;\">Status<\/th>\n<th style=\"width: 41.264%; text-align: left;\">Response priority<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 30.1694%;\">Employee vishing calls<\/td>\n<td style=\"width: 32.6532%;\">Claimed by ShinyHunters<\/td>\n<td style=\"width: 41.264%;\">High: review helpdesk verification steps<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.1694%;\">Okta SSO account compromise<\/td>\n<td style=\"width: 32.6532%;\">Claimed by ShinyHunters<\/td>\n<td style=\"width: 41.264%;\">Critical: audit recent SSO logins and resets<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.1694%;\">Salesforce and Snowflake access<\/td>\n<td style=\"width: 32.6532%;\">Claimed by ShinyHunters<\/td>\n<td style=\"width: 41.264%;\">Critical: review SaaS access and export logs<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.1694%;\">Data exfiltration (~1 TB)<\/td>\n<td style=\"width: 32.6532%;\">Claimed by ShinyHunters<\/td>\n<td style=\"width: 41.264%;\">High: confirm DLP and egress monitoring coverage<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 30.1694%;\">Third-party app breach and data theft<\/td>\n<td style=\"width: 32.6532%;\">Confirmed by McKesson<\/td>\n<td style=\"width: 41.264%;\">Critical: track official updates for scope changes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Where Hexnode fits into McKesson breach response<\/h2>\n<p>The platform doesn&#8217;t detect this specific incident or confirm ShinyHunters&#8217; claims, but its documented capabilities map onto the exposure this kind of attack creates.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> addresses the access side:<\/p>\n<ul>\n<li>It integrates with identity providers through device compliance\u2013driven Conditional Access, including Okta Device Trust.<\/li>\n<li>Organizations can require a managed, compliant device before an Okta-authenticated session reaches applications protected by Okta SSO.<\/li>\n<li>This reduces the chance that a vished credential alone is enough to reach sensitive systems, since access also depends on device posture.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.hexnode.com\/idp\/\">Hexnode IdP<\/a> addresses the identity layer directly:<\/p>\n<ul>\n<li>It functions as a native Identity Provider, handling SSO, MFA, and login authentication within the Hexnode UEM ecosystem.<br \/>\nAccess decisions factor in real-time device compliance, so a valid login alone doesn&#8217;t guarantee access.<\/li>\n<li>Continuous session verification lets teams revoke access mid-session if a device&#8217;s risk posture changes, rather than relying on a one-time login check.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> addresses the investigation side, for Windows endpoints specifically:<\/p>\n<ul>\n<li>Teams can use the query-based <strong>Investigate<\/strong> tab to search historical process and event telemetry.<\/li>\n<li>Analysts can trace which endpoints a suspicious session or process touched and establish the blast radius of a detection.<\/li>\n<li>If an investigation surfaces a compromised endpoint, teams can isolate it, kill malicious processes, or quarantine files directly from the console.<\/li>\n<\/ul>\n<p>Neither capability replaces identity-provider investigation, Salesforce and Snowflake audit logs, or the forensic work McKesson&#8217;s external experts are running. Hexnode&#8217;s role sits at the endpoint and access layer, narrowing what a compromised identity can reach and helping teams investigate the devices involved once an incident is underway.<\/p>\n<h2>FAQs<\/h2>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is the McKesson breach?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>It&#8217;s a confirmed cybersecurity incident where McKesson found unauthorized access to third-party applications and data exfiltration, discovered on August 25, 2026, and disclosed via an SEC filing.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Did ShinyHunters really steal 284 million records?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>That figure is ShinyHunters&#8217; own claim, referring to raw data rows rather than unique patients. McKesson has not confirmed the volume or categories of stolen data.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can organizations block vishing-driven Okta account takeovers?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No single control eliminates vishing risk, but pairing strict helpdesk verification with device-compliant Conditional Access reduces how far a compromised Okta session can reach.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The McKesson breach shows how a vishing claim can raise serious concerns about access to core SaaS platforms holding sensitive healthcare data. Until McKesson confirms more details, security teams should focus on what they control right now: verifying helpdesk identity procedures, auditing recent Okta sessions and resets, and confirming that SaaS access requires more than a valid token.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stop compromised sessions before they spread.  <\/h5><p>See how device-aware access strengthens your enterprise SaaS security strategy. <\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The McKesson breach became public on August 28, 2026, three days after McKesson discovered the&#8230;<\/p>\n","protected":false},"author":5,"featured_media":1303,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,19],"class_list":["post-1300","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-cloud-and-saas","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>McKesson Breach: Vishing, Okta Compromise, and SaaS Fallout<\/title>\n<meta name=\"description\" content=\"The McKesson breach shows how ShinyHunters allegedly turned vishing into Okta SSO abuse and Salesforce and Snowflake data theft.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"McKesson Breach: Vishing, Okta Compromise, and SaaS Fallout\" \/>\n<meta property=\"og:description\" content=\"The McKesson breach shows how ShinyHunters allegedly turned vishing into Okta SSO abuse and Salesforce and Snowflake data theft.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-01T06:50:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-02T04:47:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/mckesson-breach.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"McKesson Breach: How a Vishing Call Turned Into an Okta and Salesforce Incident\",\"datePublished\":\"2026-09-01T06:50:51+00:00\",\"dateModified\":\"2026-09-02T04:47:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/\"},\"wordCount\":1171,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/mckesson-breach.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Cloud and SaaS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/\",\"name\":\"McKesson Breach: Vishing, Okta Compromise, and SaaS Fallout\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/mckesson-breach.jpeg?format=webp\",\"datePublished\":\"2026-09-01T06:50:51+00:00\",\"dateModified\":\"2026-09-02T04:47:24+00:00\",\"description\":\"The McKesson breach shows how ShinyHunters allegedly turned vishing into Okta SSO abuse and Salesforce and Snowflake data theft.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/mckesson-breach.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/mckesson-breach.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"mckesson breach\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"McKesson Breach: How a Vishing Call Turned Into an Okta and Salesforce Incident\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"McKesson Breach: Vishing, Okta Compromise, and SaaS Fallout","description":"The McKesson breach shows how ShinyHunters allegedly turned vishing into Okta SSO abuse and Salesforce and Snowflake data theft.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/","og_locale":"en_US","og_type":"article","og_title":"McKesson Breach: Vishing, Okta Compromise, and SaaS Fallout","og_description":"The McKesson breach shows how ShinyHunters allegedly turned vishing into Okta SSO abuse and Salesforce and Snowflake data theft.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-01T06:50:51+00:00","article_modified_time":"2026-09-02T04:47:24+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/mckesson-breach.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"McKesson Breach: How a Vishing Call Turned Into an Okta and Salesforce Incident","datePublished":"2026-09-01T06:50:51+00:00","dateModified":"2026-09-02T04:47:24+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/"},"wordCount":1171,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/mckesson-breach.jpeg?format=webp","articleSection":["Identity Abuse","Cloud and SaaS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/","url":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/","name":"McKesson Breach: Vishing, Okta Compromise, and SaaS Fallout","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/mckesson-breach.jpeg?format=webp","datePublished":"2026-09-01T06:50:51+00:00","dateModified":"2026-09-02T04:47:24+00:00","description":"The McKesson breach shows how ShinyHunters allegedly turned vishing into Okta SSO abuse and Salesforce and Snowflake data theft.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/mckesson-breach.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/mckesson-breach.jpeg?format=webp","width":1340,"height":700,"caption":"mckesson breach"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/mckesson-breach-how-a-vishing-call-turned-into-an-okta-and-salesforce-incident\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"McKesson Breach: How a Vishing Call Turned Into an Okta and Salesforce Incident"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1300","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1300"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1300\/revisions"}],"predecessor-version":[{"id":1301,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1300\/revisions\/1301"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1303"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1300"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}