McKesson Data Exfiltration: Why Voice Phishing Target Healthcare Cloud Systems—and How to Protect Yours
A cybersecurity warning for hospitals, health systems, medical groups, pharmacies, healthcare SaaS providers, laboratories, and business associates
A healthcare cyberattack does not always start with ransomware, malware, or a software vulnerability.
Sometimes, it starts with a phone call.
On August 25, 2026, McKesson discovered a cybersecurity incident affecting its information systems. In its SEC filing, the company said its investigation was in its early stages. McKesson subsequently confirmed unauthorized access to certain third-party applications and exfiltration of data associated with a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units.
The incident has attracted additional attention because the ShinyHunters extortion group claimed responsibility and told reporters that its access began with voice phishing (vishing) against McKesson employees. The group claimed that compromised Okta SSO accounts were then used to access Salesforce and Snowflake environments and that approximately 1 TB of data was exfiltrated. Those specific attack-path, volume, and record-count claims have not been independently confirmed by McKesson.
For healthcare executives, however, the lesson doesn’t depend on whether every attacker claim is ultimately validated.
The real warning is this:
If an attacker can trick one employee into surrendering control of a trusted identity, your cloud applications—and the sensitive healthcare data connected to them—could become the next target. Assess Data-Exfiltration Risk.
What Happened in the McKesson Cybersecurity Incident?
McKesson disclosed the cybersecurity incident through an SEC filing after discovering it on August 25, 2026. The company stated that unauthorized access to certain third-party applications and the exfiltration of certain data were associated with a subset of customers in its Oncology & Multispecialty and Medical-Surgical businesses.
At the time of its disclosure, McKesson had not publicly provided the full scope of the incident, including the amount or precise nature of the data involved.
ShinyHunters subsequently claimed that the intrusion involved voice phishing, compromised Okta single sign-on accounts, and access to Salesforce and Snowflake. The group also claimed approximately 284 million records and roughly 1 TB of data, but these figures should be treated as attacker claims rather than confirmed breach statistics.
Why does this distinction matter?
Because healthcare organizations need to separate:
Confirmed facts
from
attacker claims
from
security lessons that apply regardless of the final investigation.
The confirmed issue—unauthorized access to third-party applications and data exfiltration—is already enough to demonstrate why healthcare organizations need stronger identity, SaaS, data, and monitoring controls. Get a Vishing Risk Assessment.
Why Is Voice Phishing Becoming a Serious Healthcare Threat?
Vishing, or voice phishing, uses phone calls and human interaction to manipulate employees into providing information or performing actions that benefit an attacker.
Traditional phishing might send an employee an email saying:
“Your account has been suspended. Click here to sign in.”
Vishing changes the approach.
An attacker may call and claim:
“I’m from your IT security team. We’ve detected suspicious activity on your account.”
The caller may know:
- The employee’s name
- Their department
- Their job title
- The applications they use
- The organization’s IT terminology
- The identity platform the organization uses
- The names of internal teams
That knowledge can make the call appear legitimate.
The attacker may then attempt to convince the employee to:
- Reveal credentials
- Approve an authentication request
- Reset an MFA method
- Register a new device
- Change account information
- Visit a fraudulent login page
- Install remote-access software
- Provide recovery information
The result is potentially much more dangerous than a stolen password.
The attacker may obtain a legitimate identity session. Get a Healthcare Cyber Risk Assessment.
The Healthcare Attack Chain: From Phone Call to Cloud Data
The reported McKesson attack pattern illustrates a broader risk that healthcare organizations should examine.
1. Social engineering
Attacker → Employee
The attacker establishes trust through a phone call.
↓
2. Identity compromise
Employee → Identity Provider
Credentials, authentication approval, or account-control information is compromised.
↓
3. SSO access
Identity → Cloud Applications
The compromised identity can potentially authenticate to connected applications.
↓
4. Privileged or excessive access
Cloud Application → Sensitive Data
The attacker discovers what the compromised account can access.
↓
5. Data discovery
Sensitive Data → Valuable Records
The attacker searches for information worth stealing.
↓
6. Data exfiltration
Cloud → External Destination
Large quantities of information may be transferred outside the organization.
This is why the modern healthcare security perimeter is no longer simply the firewall.
Your identity layer is part of your security perimeter.
- Your SaaS applications are part of your security perimeter.
- Your APIs are part of your security perimeter.
- Your cloud data warehouses are part of your security perimeter.
- And your helpdesk procedures are part of your security perimeter.
Why SSO Can Increase the Blast Radius of a Compromised Account
Single sign-on is valuable because it simplifies authentication.
One identity can provide access to multiple approved applications.
But that convenience creates a security question:
What happens when the identity itself is compromised?
Suppose an employee has access to:
- Microsoft 365
- Salesforce
- EHR applications
- Cloud storage
- Billing systems
- Analytics platforms
- Data warehouses
- Collaboration tools
- Third-party healthcare applications
If those applications rely heavily on a central identity provider, compromising that identity could potentially provide an attacker with access to multiple environments.
That does not mean SSO is unsafe.
It means organizations need to secure the identity layer as aggressively as they secure their applications.
Healthcare security teams should therefore ask:
- Who can authenticate?
- What can they access?
- From which devices?
- Under what conditions?
- What actions can they perform?
- What happens when their behavior becomes abnormal?
The Biggest Healthcare Cybersecurity Mistake: Stopping at MFA
Many organizations believe they are protected because:
“We have MFA enabled.”
That’s a good starting point—but it isn’t the finish line.
The important question is:
What type of MFA are you using, and can an attacker manipulate the user into completing the authentication process?
Attackers can attempt to exploit:
- Push-notification fatigue
- Social engineering
- Fake authentication pages
- Real-time phishing
- Helpdesk account recovery
- SIM-based attacks
- Stolen session tokens
- Device enrollment processes
Healthcare organizations should prioritize phishing-resistant authentication, particularly for privileged and high-risk identities.
FIDO2 and passkeys:
FIDO2/WebAuthn-based authentication can make conventional credential phishing substantially harder because authentication is cryptographically bound to the legitimate website or service.
Prioritize phishing-resistant authentication for:
- IT administrators
- Helpdesk personnel
- Security teams
- Cloud administrators
- Executives
- Remote-access users
- Privileged SaaS accounts
- Users handling highly sensitive data
Is Your Healthcare MFA Actually Phishing-Resistant?
Synergy IT Solutions Group can assess your current authentication architecture and identify where stronger phishing-resistant MFA, conditional access, privileged identity controls, and account protections should be implemented. Request a Healthcare Identity Security Assessment.
Step-Up Authentication: A Login Is Not the Same as a Data Export
Here’s another critical lesson.
- A user logging into a cloud application is one type of activity.
- A user attempting to export hundreds of thousands of records is another.
Yet organizations sometimes treat both actions as equally trusted because the user successfully authenticated earlier.
That’s dangerous.
High-risk activities should receive additional scrutiny.
Examples include:
- Bulk data exports
- Large database queries
- Downloading sensitive records
- Creating API credentials
- Changing MFA settings
- Adding privileged users
- Modifying data-sharing permissions
- Accessing restricted datasets
- Changing security configurations
The security model should become:
Authenticate → Assess risk → Authorize action → Monitor behavior
not:
Authenticate → Trust everything
Could an employee account export sensitive healthcare data without additional verification?
Synergy IT Solutions Group can help identify high-risk cloud and SaaS actions that should require step-up authentication, approval, or additional monitoring. Assess Your High-Risk Cloud Access.
Least Privilege Must Extend to Healthcare SaaS
Least privilege shouldn’t stop at servers and network infrastructure.
It must extend into SaaS.
Healthcare organizations should review whether users can:
- Export entire datasets
- Access records outside their responsibilities
- Create API tokens
- Add third-party integrations
- Change security policies
- Access administrative functions
- Download sensitive files
- Query large datasets
- Share information externally
A compromised standard user account should not automatically become a pathway to an organization’s most valuable information.
Think in terms of blast radius
If one account is compromised, ask:
- How many systems can it reach?
- How much data can it access?
- Can it create new credentials?
- Can it change MFA?
- Can it export information?
- Can it access another business unit?
The answers determine the organization’s identity blast radius.
Reduce the Blast Radius of a Compromised Account
Get an assessment of your healthcare organization’s identity permissions, privileged accounts, SaaS roles, cloud access, and sensitive-data exposure. Request a Least-Privilege Security Review.
Data Exfiltration: Don’t Just Monitor Who Logs In
Traditional security monitoring asks:
“Did someone access the system?”
Modern healthcare security needs to ask:
“What did they do after accessing it?”
Behavioral monitoring should identify activity such as:
- Unusual login locations
- Impossible travel
- Abnormal login times
- New MFA devices
- New OAuth applications
- Sudden privilege escalation
- Unusual API activity
- High-volume downloads
- Large database queries
- Bulk exports
- Access to previously unused datasets
For example:
Normal behavior:
A billing employee accesses several hundred records.
Potentially suspicious behavior:
The same account suddenly attempts to download hundreds of thousands of records.
The identity may be legitimate.
The behavior may not be.
That’s why identity security + behavioral analytics + DLP + SaaS monitoring need to work together.
Zero Trust: Assume an Identity Could Be Compromised
Zero Trust changes the security question from:
“Is this user inside our environment?”
to:
“Should this specific user, on this specific device, from this specific location, be allowed to perform this specific action against this specific data right now?”
For healthcare organizations, Zero Trust should evaluate:
Identity: Who is requesting access?
Device: Is the device managed and compliant?
Location: Is the location expected?
Application: Is the application authorized?
Behavior: Is the activity normal?
Data: What information is being accessed?
Risk: Has anything changed?
The goal is to prevent a compromised identity from moving freely across the organization.
What Healthcare Organizations Should Do Now
The McKesson incident provides a useful checklist for healthcare CISOs, CIOs, IT directors, security leaders, and compliance teams.
1. Audit privileged identities
Identify:
- Global administrators
- SaaS administrators
- Helpdesk accounts
- Cloud administrators
- Security accounts
- Service accounts
- Third-party accounts
Remove unnecessary privileges.
2. Strengthen authentication
Prioritize phishing-resistant MFA for:
- Administrators
- Helpdesk users
- Remote access
- High-risk SaaS accounts
- Cloud administrators
- Executives
3. Lock down helpdesk processes
Never allow a caller to bypass identity-verification procedures simply because they claim to be an employee.
Require stronger verification before:
- Resetting passwords
- Resetting MFA
- Registering devices
- Changing recovery methods
- Modifying privileged access
4. Review SaaS permissions
Look for:
- Excessive access
- Bulk export permissions
- Dormant accounts
- Third-party integrations
- API credentials
- OAuth applications
- Privileged roles
5. Monitor data movement
Establish alerts for:
- Large downloads
- Bulk exports
- Unusual database queries
- Unusual API activity
- Abnormal geographic access
- Privilege changes
6. Segment sensitive data
Sensitive clinical, financial, employee, and operational data should not be unnecessarily reachable from general-purpose user accounts.
Segmentation reduces the impact of a compromised identity.
7. Test your incident response plan
Ask your security team:
“What happens if our helpdesk employee is socially engineered tomorrow?”
Your response plan should cover:
Detect → Disable → Investigate → Contain → Revoke sessions → Rotate credentials → Analyze data access → Notify stakeholders → Recover
A Healthcare Cybersecurity Architecture Built for Identity-Based Attacks
Healthcare organizations should move toward a layered model:
Phishing-Resistant MFA
↓
Conditional Access
↓
Least-Privilege Identity
↓
Privileged Access Management
↓
SaaS Security Controls
↓
Sensitive Data Segmentation
↓
DLP & Data-Egress Monitoring
↓
Identity Behavior Analytics
↓
24/7 Threat Detection & Response
This creates multiple opportunities to stop an attacker.
- If social engineering succeeds, phishing-resistant controls can help.
- If an identity is compromised, least privilege limits access.
- If suspicious behavior occurs, behavior analytics can identify it.
- If an attacker attempts mass extraction, DLP and egress controls can intervene.
- If something bypasses those layers, 24/7 detection and response provides another opportunity to contain the incident.
The McKesson Lesson for Every Healthcare Organization
The biggest lesson from the McKesson incident isn’t simply that healthcare organizations need better phishing awareness. It is that identity, SaaS, cloud infrastructure, and data security can no longer be treated as separate security problems.
An attack can potentially move through a chain like:
Human trust → Identity → SSO → SaaS → Cloud Data → Exfiltration
Breaking that chain requires more than a firewall.
It requires:
strong identity protection + phishing-resistant MFA + least privilege + Zero Trust + behavioral monitoring + DLP + rapid response.
And healthcare organizations should evaluate these controls before a suspicious phone call becomes a security incident.
Is Your Healthcare Organization Prepared for a Vishing-to-Cloud Attack?
A compromised employee doesn’t have to mean compromised patient data.
The difference comes down to how many security controls stand between the compromised identity and your most sensitive information.
Synergy IT Solutions Group helps healthcare organizations assess and strengthen:
- Identity & MFA security
- Microsoft 365 security
- Cloud security
- SaaS security
- Zero Trust architecture
- Privileged access
- Vulnerability management
- Data Loss Prevention
- Threat detection & response
- Managed cybersecurity monitoring
Don’t wait for the next healthcare breach to test your defenses. Get a Healthcare Cyber Risk Assessment:
FAQs:
What happened in the McKesson cybersecurity incident?
McKesson disclosed a cybersecurity incident discovered on August 25, 2026. The company confirmed unauthorized access to certain third-party applications and exfiltration of certain data associated with a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. The full scope of the incident remains subject to investigation.
Was the McKesson attack caused by voice phishing?
ShinyHunters has claimed that it used voice phishing, or vishing, against McKesson employees to obtain access to identity accounts. McKesson has confirmed unauthorized access and data exfiltration but has not publicly confirmed every detail of the attack path described by the group.
What is vishing in cybersecurity?
Vishing is a form of social engineering in which attackers use phone calls or voice communications to impersonate trusted individuals or organizations and manipulate victims into revealing credentials, approving authentication requests, changing security settings, or providing other information.
Why is vishing dangerous for healthcare organizations?
Healthcare organizations are attractive targets because they manage valuable patient, clinical, financial, employee, and operational information while relying on large workforces, cloud applications, remote access, and third-party services. A successful vishing attack can potentially compromise a trusted identity and create access to connected systems.
How can healthcare organizations prevent vishing attacks?
Healthcare organizations should combine employee security awareness with strict helpdesk verification, phishing-resistant MFA, conditional access, least privilege, privileged access controls, identity monitoring, and procedures that prevent password or MFA resets based solely on phone requests.
What is phishing-resistant MFA?
Phishing-resistant MFA uses authentication mechanisms designed to prevent attackers from successfully replaying stolen credentials or authentication information. FIDO2/WebAuthn security keys and passkeys are examples of technologies that can provide stronger protection against credential-phishing attacks.
Can MFA prevent a healthcare data breach?
MFA can significantly reduce the risk of account compromise, but MFA alone does not eliminate healthcare breach risk. Organizations should combine strong authentication with least privilege, conditional access, SaaS security, data-loss prevention, behavioral monitoring, segmentation, and incident response.
Why is SSO important in healthcare cybersecurity?
SSO centralizes identity authentication across multiple applications. This can improve usability and security, but it also makes protecting the identity provider critical because a compromised account may potentially provide access to multiple connected applications.
How can healthcare organizations reduce the impact of a compromised account?
Healthcare organizations can reduce the blast radius through least privilege, phishing-resistant MFA, conditional access, privileged access management, application segmentation, restricted bulk exports, DLP, continuous monitoring, and rapid session and credential revocation.
How can healthcare organizations detect data exfiltration?
Organizations can monitor abnormal downloads, bulk exports, unusual database queries, high-volume API activity, abnormal login behavior, unusual geographic access, privilege changes, and access to datasets that a user does not normally interact with.
What is Zero Trust in healthcare cybersecurity?
Zero Trust is a security approach that continuously evaluates identity, device, application, location, behavior, and risk instead of automatically trusting users or devices based on network location or previous authentication.
How does Zero Trust help protect PHI?
Zero Trust can limit access to protected health information by enforcing identity-based policies, least privilege, device controls, conditional access, segmentation, and continuous monitoring. This can reduce the amount of PHI accessible to a compromised account.
Should healthcare organizations restrict bulk data exports?
Yes. Healthcare organizations should evaluate whether bulk exports are necessary for each role and consider additional authentication, approval, monitoring, or DLP controls for high-volume exports involving sensitive information.
What should a healthcare organization do after a suspected vishing attack?
The organization should immediately investigate the affected identity, revoke active sessions, reset or rotate compromised credentials where appropriate, review MFA and device changes, examine cloud and SaaS activity, determine whether sensitive data was accessed, preserve logs, and activate its incident-response process.

Leave A Comment