Attackers vished McKesson staff, took over Okta, and accessed Salesforce and Snowflake
Assessment
This is the attacker's own account, given to BleepingComputer, which "has not independently verified these claims". McKesson has said only that the incident targeted "employee corporate accounts" and involved "third-party applications", which is consistent with the account without confirming any element of it. The circumstantial support is real: the identical sequence was confirmed by ReliaQuest for an attack on 22 August, inside McKesson's window, using the same .claims infrastructure. It remains unconfirmed by the victim.
Where this claim appeared
BleepingComputer · 2026-08-28
https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/What “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
McKesson Data Breach: ShinyHunters, One Phone Call, and 284 Million Rows of Patient DataThink this assessment is wrong? Report an error.