Full Report
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, […] The post 31th August – Threat Intelligence Report appeared first on Check Point Research.
Analysis Summary
# Incident Report: Multi-Vector Breach of McKesson Healthcare Systems
## Executive Summary
McKesson, a major U.S. healthcare and pharmaceutical company, suffered a significant data breach orchestrated by the threat group "ShinyHunters." The attackers utilized social engineering (vishing) to compromise identity provider accounts, leading to the exfiltration of approximately 1TB of data containing 284 million patient-related records. The incident highlights the critical risk of identity-based attacks on cloud-integrated environments.
## Incident Details
- **Discovery Date:** August 2026 (Reported August 31)
- **Incident Date:** Circa August 2026
- **Affected Organization:** McKesson
- **Sector:** Healthcare / Pharmaceutical
- **Geography:** United States / Global
## Timeline of Events
### Initial Access
- **Date/Time:** August 2026
- **Vector:** Vishing (Voice Phishing)
- **Details:** Attackers targeted employees via phone to solicit credentials or bypass MFA to compromise Okta accounts.
### Lateral Movement
- **Details:** Using compromised Okta (Identity Provider) credentials, the threat actors moved laterally into integrated third-party applications, specifically targeting Salesforce and Snowflake environments.
### Data Exfiltration/Impact
- **Details:** Approximately 1TB of data was exfiltrated. The stolen dataset reportedly contains 284 million records related to patients.
### Detection & Response
- **How it was discovered:** The breach was disclosed following claims by the threat group "ShinyHunters" on public forums/leak sites.
- **Response actions taken:** McKesson confirmed unauthorized access to third-party applications and initiated an investigation into the scope of the data theft.
## Attack Methodology
- **Initial Access:** Vishing (Social Engineering targeting Okta accounts).
- **Persistence:** Use of valid stolen credentials within cloud SaaS environments.
- **Privilege Escalation:** Not explicitly detailed, but involved gaining administrative or high-level access to Salesforce/Snowflake via Identity Provider (IdP) compromise.
- **Defense Evasion:** Use of legitimate credentials to mimic authorized user behavior.
- **Credential Access:** Vishing for Okta credentials and potentially 2FA codes.
- **Lateral Movement:** Cross-application movement from IdP (Okta) to SaaS platforms (Salesforce, Snowflake).
- **Collection:** Gathering patient-related records from cloud databases.
- **Exfiltration:** Transfer of 1TB of data to attacker-controlled infrastructure.
- **Impact:** Massive data breach and unauthorized disclosure of sensitive healthcare information.
## Impact Assessment
- **Financial:** Potentially high due to HIPAA violations, legal fees, and mitigation costs (Specific figures not yet disclosed).
- **Data Breach:** 284 million patient records; 1TB of total data.
- **Operational:** Disruption to data privacy protocols and third-party application security management.
- **Reputational:** Significant impact due to the sensitivity of healthcare data and the scale of the compromise.
## Indicators of Compromise
*Note: Specific technical indicators (hashes/IPs) were not provided in the summary report; however, behavioral indicators are noted below.*
- **Behavioral indicators:**
- Unusual login patterns to Okta from unrecognized devices or locations.
- Large-scale data exports from Snowflake or Salesforce originating from single user accounts.
- Employee reports of suspicious phone calls requesting security information.
## Response Actions
- **Containment:** Revocation of compromised Okta sessions and credentials.
- **Eradication:** Securing third-party application integrations and auditing Salesforce/Snowflake access logs.
- **Recovery:** Investigation into the volume of affected patients and legal disclosure processes.
## Lessons Learned
- **Vulnerability of IdPs:** Identity providers like Okta are "single points of failure"; if compromised, the entire SaaS ecosystem is at risk.
- **Human Factor:** Vishing remains a highly effective method for bypassing technical security controls like MFA.
- **Data Centralization Risks:** Storing massive quantities of patient data in cloud environments (Snowflake) requires rigorous monitoring for anomalous egress.
## Recommendations
- **Implement Phishing-Resistant MFA:** Transition from SMS or push-based MFA to FIDO2/WebAuthn hardware keys to mitigate vishing/prompt bombing.
- **Security Awareness Training:** Specifically train employees to recognize voice-based social engineering tactics.
- **Egress Monitoring:** Implement strict alerting for large data transfers (DLP) within Snowflake and Salesforce.
- **Conditional Access:** Enforce strict conditional access policies requiring managed devices for all IdP logins.