// OktaCRITICAL
ShinyHunters used voice-phishing (vishing) to compromise Okta SSO credentials at McKesson Corporation, then pivoted to Snowflake and Salesforce to steal approximately 284 million patient records including names, SSNs, dates of birth, medical information, and Medicaid numbers between August 21–25, 2026. McKesson confirmed the breach on August 28. The group demanded $55.2 million ransom and has executed similar Okta-to-cloud-data attacks against multiple organizations in 2026, establishing a pattern where compromised SSO credentials enable large-scale data exfiltration.
- McKesson Breach: ShinyHunters Claim 284M Records(opens in a new tab)
- Cyber / Brief — 30 Aug 2026(opens in a new tab)
- ShinyHunters Target McKesson, Boston Scientific Cyberattack, Has(opens in a new tab)
- McKesson Data Breach: ShinyHunters Claims 284M Records(opens in a new tab)
- What We Missed: Did ShinyHunters 'Breach' ReliaQuest?(opens in a new tab)
// Get alerts for Okta