A major American pharmaceutical giant has just confirmed a breach of its cloud systems. The extortion group ShinyHunters is claiming the exfiltration of approximately 284 million rows of patient data — nearly one terabyte of highly sensitive information.
The ransom demand stands at $55 million, with a deadline set for September 1st. McKesson has not yet confirmed the full scale of the leak, but has filed an SEC Form 8-K, a clear signal that the incident is considered materially significant.
Behind this attack lies a devastatingly effective method: vishing, or voice phishing. An intrusion vector that bypasses even the most sophisticated technical defenses by targeting the human factor directly.
Vishing, Okta, and Snowflake: The Anatomy of a Surgical Attack
McKesson detected the intrusion on August 25, 2025, following unauthorized access to third-party applications between August 21st and 25th. According to ShinyHunters, the attack began with fraudulent phone calls targeting employees, tricking them into handing over their Okta SSO (single sign-on) credentials. Once that access was secured, the attackers pivoted to Salesforce and Snowflake platforms to exfiltrate the data.
This playbook is not new. ShinyHunters used a near-identical approach during the massive Snowflake compromise in 2024, which impacted dozens of enterprise clients including Ticketmaster and Santander. The group systematically exploits the chain of trust between SaaS providers and their enterprise customers, turning every weak link into an entry point.
The data involved originates from McKesson‘s oncology and multi-specialty division, as well as its medical-surgical unit — particularly sensitive records tied to often vulnerable patients. McKesson states it has reasonable assurance that no unauthorized activity is currently ongoing, and that all business lines continue to operate normally.

$55 Million Ransom Demand: A Strong Signal for Web3 and Enterprise Cybersecurity
The $55 million ransom demand illustrates the industrialization of data extortion attacks. ShinyHunters does not encrypt systems — it steals, threatens to publish, and monetizes urgency. A business model that closely mirrors that of stolen data markets on the dark web, where medical records command prices far higher than standard financial data.
For the crypto and Web3 ecosystem, this incident raises a structural question: centralized authentication protocols like Okta SSO represent a critical single point of failure. Several blockchain projects and exchanges have already been compromised through this exact vector. Decentralized identity solutions — such as DIDs (Decentralized Identifiers) or hardware wallets — are precisely designed to eliminate this type of vulnerability.
McKesson filed an SEC Form 8-K in compliance with the new cyber incident disclosure rules imposed by U.S. regulators since December 2023. The company plans to offer credit monitoring and identity protection services to affected individuals. The exact number of compromised records, the precise data types involved, and the full details of the ransom demand have not yet been officially confirmed by the company at this stage.