Mind the Breach

McKesson breach: a lesson in sensitive unstructured data risk

Samuel Hill, Product Marketing at MIND

Sep 01, 2026

The most sensitive data in a breach is often the free text nobody classified.

McKesson discovered intruders in its environment on August 25. In a Form 8-K filing with the SEC, the healthcare and pharmaceutical distribution giant confirmed a cybersecurity incident. A separate notice on McKesson's website confirmed it involved third-party applications and the theft of data. The ShinyHunters extortion group claimed the attack, telling BleepingComputer it spent four days inside the company's systems and fully compromised its Salesforce environment, support cases included.

Most of the coverage has focused on the raw count of exposed records. For a security team, the more useful detail sits further down the story. Alongside the database exports, the group claims it took support cases, internal communications and details of medications, allergies and illnesses. Much of that is free text that employees typed while doing their jobs, so it never carried a sensitivity label in the first place.

What happened in the McKesson breach?

The claimed entry point was a phone call rather than an exploit. ShinyHunters told BleepingComputer it ran voice phishing calls against several McKesson employees, impersonating internal IT convincingly enough to compromise their Okta single sign-on accounts. BleepingComputer separately learned the campaign used the domain mckesson[.]claims, matching a pattern ReliaQuest's threat research team documented in which attackers register .claims lookalike domains to pose as company help desks. From the compromised accounts, the group says it reached McKesson's Salesforce environment and fully compromised it, support cases included, alongside a Snowflake warehouse it claims held roughly 284 million patient-related records, a figure the group itself describes as raw lines rather than people.

In total the attackers claim about 1TB taken over four days, with a $55.2 million ransom McKesson reportedly never answered. The attack fits a wave Health-ISAC has warned healthcare organizations about, ShinyHunters social engineering aimed at corporate accounts as the road into cloud and SaaS platforms, as reported by BleepingComputer. None of the claims have been independently verified. McKesson hasn't said publicly what was taken.

Why is unstructured data the hardest part to account for?

Nothing about a support ticket reveals what's inside it until something reads the text. A single case about a delayed medication shipment can hold a diagnosis, a prescription and a home address, typed in plain prose by someone trying to solve a customer's problem quickly. Nobody labels that ticket as regulated data on the way in. Multiply it by years of support history and a CRM becomes one of the larger stores of sensitive information in the company, even though it rarely appears on a data inventory that way.

DLP tools that depend on recognizable patterns read a paragraph describing a patient's illness as ordinary conversation, even though it may be the most sensitive content in the system. This gap is a big part of why breached companies need weeks to say what was actually taken. Answering means classifying everything the attacker touched, after the fact and under pressure.

How do you find sensitive data in free text before attackers do?

This is the problem MIND's classification was built for. MIND connects to the SaaS applications where free text accumulates, Salesforce included. Multi-layer classification reads content and context together, so it recognizes a medical record, a contract or a payroll report even when no pattern fires. In practice that means the system is minding the conversations a data inventory never mentions, so the support queue is mapped and watched long before anyone hostile goes looking. No security team will stop every convincing phone call, so the practical measure of exposure is how much unlabeled sensitive text a stolen session can reach once someone answers one.

MIND allows us to see and protect our data across every vector, endpoints and SaaS, from a single place. It's like having a spotlight that shines where visibility didn't exist before.

Al Faiella

Senior Director of Security Engineering, ThoughtSpot

If your current controls depend on pattern matching, it's worth finding out what sits in your support queues and shared drives beyond their reach. Connect MIND to your environment and see what its classification finds, often the same day. That's Stress-Free DLP. Let's mind what matters.

Tell us what’s on your mind. Get a live demo or just reach out to us.