284 Million Records Later, McKesson Learns About Voice Phishing

284 Million Records Later, McKesson Learns About Voice Phishing

All it took was two phone calls. Not a zero-day, not a nation-state exploit chain, not a single line of malware — just someone convincing enough on the phone, and a healthcare distribution giant's data is now allegedly for sale.

A Phone Call, Then Salesforce, Then Snowflake

McKesson, one of the largest pharmaceutical and healthcare distribution companies in the country, discovered a cybersecurity incident on August 25 and confirmed it's investigating. The extortion group ShinyHunters claims it voice-phished two McKesson employees and used that access to pull data out of the company's Salesforce and Snowflake environments — no exotic exploit required, just a convincing enough phone call to the right people.

ShinyHunters says the haul includes roughly 284 million records — the group has clarified that's a raw line count, not 284 million unique people — covering names, home addresses, dates of birth, phone numbers, emails, Social Security numbers, patient IDs, medical record numbers, Medicaid numbers, billing details, and doctor-patient messages. The group is demanding $55.2 million to not release the files; as of this week, McKesson hadn't responded to the demand.

Your Firewall Didn't Fail. Your Phone Tree Did

Voice phishing keeps winning against companies with genuinely excellent technical defenses because it doesn't attack the technology at all — it attacks the person answering the phone who just wants to be helpful. No firewall update fixes a support rep who gets talked into resetting the wrong credential.

The Salesforce-and-Snowflake pattern should look familiar — ShinyHunters has run this exact playbook against a string of major companies this year by targeting the cloud platforms everyone trusts by default rather than hardened on-prem systems. If your business treats SaaS platforms as inherently safer than your own servers, this is the breach that argues otherwise.

The scariest part of a voice-phishing breach isn't the technology gap — it's realizing your last line of defense is whether an underpaid employee hangs up the phone.

Locking down cloud platform access and training your team to spot social engineering before it becomes a headline is exactly the kind of gap our security checklist walks through — download it free here.

Source: BleepingComputer