// Alert

Okta threat report

// OktaCRITICAL

ShinyHunters used voice-phishing (vishing) to compromise Okta SSO credentials at McKesson Corporation, then pivoted to Snowflake and Salesforce to steal approximately 284 million patient records including names, SSNs, dates of birth, medical information, and Medicaid numbers between August 21–25, 2026. McKesson confirmed the breach on August 28. The group demanded $55.2 million ransom and has executed similar Okta-to-cloud-data attacks against multiple organizations in 2026, establishing a pattern where compromised SSO credentials enable large-scale data exfiltration.

// Get alerts for Okta