Anatomy of a Breach: What McKesson's $55M Ransom Note Reveals About Healthcare Security

by
Nametag
North Korea Blog Post Header

What Unverified Identity Costs Enterprises Every Year

An industry-by-industry breakdown of what unverified identity costs enterprises every year.

TL;DR

  • What happened: Attackers called McKesson employees, impersonating internal IT staff, and social-engineered their way into multiple Okta SSO accounts. They spent four days pulling data before anyone noticed.
  • Root cause: Authentication confirmed the accounts were valid. Nothing confirmed the humans behind the accounts.
  • What to do now: Six questions every healthcare security team should ask this week.

On August 28, 2026, McKesson disclosed that attacker group ShinyHunters had spent four days inside its systems, pulling out an estimated 1TB of data and claiming 284 million patient records. Their ransom note, sent before disclosure, demanded $55.2 million with a 72-hour deadline. McKesson reportedly never responded.

This was not a sophisticated system exploit. Someone called an employee, sounded like IT, and asked for a reset.

Health Care Security Check-Up

6 questions to ask before you're the next disclosure.

A 5-minute self-assessment covering the exact gap that let McKesson's breach happen. See where your helpdesk stands.

Download the Check-Up

While authentication proves which account is acting, only identity verification proves which human is acting. Healthcare has invested heavily in the former and almost nothing in the latter. And they're a valuable target for bad actors; since they have everything to lose, they almost always pay the ransom.

Healthcare's Health Scare

Healthcare has led every industry in average breach cost for 14 consecutive years, and the 2024 breach at Change Healthcare, which affected 192.7 million people and cost UnitedHealth a $22 million ransom, showed what happens when that gap runs through a single point of failure for the entire industry's claims processing. Nametag's own research puts the ongoing cost of unverified identity at roughly $150,000 a week in breach exposure, helpdesk load, and lost clinical hours for a 15,000-employee health system. And that's before any breach.

That's the math every health system evaluating an identity fix should be running today. At $150,000 a week, the cost of action is almost always lower than the cost of doing nothing.

Healthcare Identity · 2026

What Unverified Identity Costs Healthcare Every Year

Unverified identity costs a 15,000-employee health system millions a year, and it runs by the week. See the math behind all four cost pillars, and what changes once the gap closes.

The Guts of the Breach

The guts of the McKesson breach have been seen time and time again in healthcare data breaches:

  1. Vishing the helpdesk. Attackers called McKesson employees and IT staff, impersonating internal help desk teams to trigger password and MFA resets.
  2. A lookalike domain. A spoofed domain, mckesson[.]claims, supported the impersonation and gave the operation a veneer of legitimacy.
  3. Into Okta SSO. The reset credentials handed attackers a foothold inside McKesson's Okta single sign-on. The account was authenticated, but the human behind it never was.
  4. Salesforce and Snowflake. From inside SSO, attackers pivoted laterally into the systems holding patient and operational data.
  5. Four days, ~1TB exfiltrated. Data moved out between August 21–25, undetected, because the session looked exactly like a verified employee's.
  6. Ransom before disclosure. ShinyHunters demanded payment before McKesson had even told anyone a breach occurred.

Every step after that first phone call happened inside tools that were working exactly as designed. The systems did what they were built to do: confirm a credential was valid. But none of them were built to confirm who was holding the credential.

A Security Pandemic

The same actor, using the same techniques, has hit a slew of other healthcare and medtech companies through 2026, per public reporting:

  • Medtronic — roughly 3.8 million individuals notified after an April 2026 breach of corporate IT systems (HIPAA Journal, BleepingComputer).
  • Baxter International — ShinyHunters claimed 7.1 million Salesforce records, including patient and employee PII (HIPAA Journal).
  • Boston Scientific — a cyberattack disrupted global operations and order processing (BankInfoSecurity).
  • Abbott Laboratories — ShinyHunters claimed data from Abbott and its Exact Sciences business (HIPAA Journal).

This problem isn't specific to McKesson — they were just the most recent company to catch the bug that's going around. It's a healthcare-wide pandemic leveraging the one weakness where every one of these breaches started: the helpdesk.

The Healthcare Security Antidote

MFA, SSO, and background checks all did their jobs, they were simply never designed to answer the one question that mattered: is this the person they claim to be, right now, on this call?

Closing that gap means treating verification as something that happens at the moment of risk, not once at login:

  • Verify the caller, not just their answers. Name, employee ID, and "security questions" are exactly what a social engineer prepares before they call. Bind every high-risk helpdesk request to a verified government ID and a liveness check, so every reset becomes a defensible decision, not a guess.
  • Bind resets to a verified human, not an agent's judgment call. Account recoveries are often based on the agent's read of the situation, and social engineers know it. Make verification automatic and mandatory to remove that judgment call from the process.
  • Reverify at the privileged-access boundary. The breach didn't happen at login — it happened four steps later, when a verified-looking session reached Salesforce, Snowflake, and the systems holding patient data. A checkpoint at the privileged-access boundary stops lateral movement before it reaches the highest-value systems, closing the four-day gap that let McKesson's breach go undetected.
  • Make it a clear pass/fail, not a score someone has to interpret. Employee security training reduces risk, but it doesn't stop a convincing caller or catch a lookalike domain like mckesson[.]claims. Verification should return a decision, not a signal a stressed agent has to judge under pressure.

Healthcare has spent a generation building tools to keep attackers out. What it hasn't built is a way to verify the human once someone's already on the phone.

Download the Health Care Security Check-Up to see the six questions that would have flagged this pattern before McKesson's ransom note ever went out.


Frequently asked questions

How did the McKesson breach happen?

Per ShinyHunters' claims as reported by BleepingComputer, attackers vished McKesson's helpdesk to trigger password and MFA resets, using a lookalike domain (mckesson[.]claims) to support the impersonation. The reset credentials gave them a foothold in McKesson's Okta SSO, from which they pivoted into Salesforce and Snowflake and exfiltrated roughly 1TB of data over four days before McKesson detected it.

What's the difference between authentication and identity verification?

Authentication confirms a credential is valid: the right password, the right MFA response. Identity verification confirms which specific human is behind that credential. McKesson's Okta SSO authenticated the accounts attackers were using; it never verified whether the humans behind them were who they claimed to be.

Is McKesson the only healthcare company this has happened to?

No. The same actor and technique has been tied to breaches at Medtronic, Baxter International, Boston Scientific, and Abbott Laboratories in 2026 alone, per public reporting.

Secure your helpdesk against social engineering and impersonators.
Decline
Accept All Cookies