09/01/2026
284 million patient records didn't leak through a firewall failure. They leaked through a phone call.
The ShinyHunters group is now claiming responsibility for the McKesson breach. If the claims hold up, initial access came from vishing calls that tricked employees into handing over credentials to Salesforce and Snowflake environments. Not malware. Not an unpatched CVE. A phone call.
For financial institutions, this should sting. Your SOC can have flawless log coverage and still miss this, because the compromise starts in a conversation, not a network. Examiners are increasingly asking how institutions test social engineering resilience, not just technical controls.
Third-party SaaS platforms like Salesforce and Snowflake sit inside plenty of FI tech stacks too. Vendor risk reviews need to ask: who can access these environments, and how would we know if someone got in through the front door instead of the back?
We track incidents like this daily and translate what they mean for banks and credit unions. Sign up for our CTI bulletin to get it in your inbox each morning. https://www2.defensestorm.com/Up-To-Date