ThreatPaper
Weak Evidence

Attackers vished McKesson staff, took over Okta, and accessed Salesforce and Snowflake

Assessment

This is the attacker's own account, given to BleepingComputer, which "has not independently verified these claims". McKesson has said only that the incident targeted "employee corporate accounts" and involved "third-party applications", which is consistent with the account without confirming any element of it. The circumstantial support is real: the identical sequence was confirmed by ReliaQuest for an attack on 22 August, inside McKesson's window, using the same .claims infrastructure. It remains unconfirmed by the victim.

Where this claim appeared

BleepingComputer · 2026-08-28

https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

McKesson Data Breach: ShinyHunters, One Phone Call, and 284 Million Rows of Patient Data

Think this assessment is wrong? Report an error.