Nobody Broke In. Somebody Logged In and Ran a Query.
On August 25, McKesson discovered that someone had been inside its systems. Three days later, the company filed an 8-K with the SEC describing "a cybersecurity incident affecting its information systems" and stating that it had "not determined that the incident is material." Over the following weekend, McKesson confirmed that data had in fact been exfiltrated, affecting a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units.
McKesson is not a small company. It is the largest pharmaceutical distributor in North America, moving roughly a third of the prescription medicines consumed on the continent. If you filled a prescription this week, there is a reasonable chance McKesson touched it.
Here is what should hold your attention as an executive or director: almost nothing broke. McKesson's chief technology officer, Francisco Fraga, told customers they might see intermittent service degradation, but that they could continue to connect to and use the company's systems as intended — and that McKesson was not proactively disconnecting systems, the step companies normally take to contain a ransomware attack. No encryption. No shutdown. No ransom note taped to a server rack. The attacker did not break the business, because breaking it was never the point.
The Attacker Did Not Need a Vulnerability
The ShinyHunters extortion group told BleepingComputer it was responsible. According to the group's account, the entry point was a series of voice phishing calls — "vishing" — against multiple McKesson employees, which compromised their single sign-on accounts and, from there, opened access to the company's Salesforce and Snowflake environments. BleepingComputer separately reported that the attackers used a lookalike mckesson[.]claims domain, matching a broader ShinyHunters campaign documented by ReliaQuest in which the group registers .claims domains bearing a target company's name in order to impersonate its help desk and IT teams.
The group claims it pulled roughly a terabyte of data over four days, between August 21 and August 25, and that the haul included approximately 284 million records. Two important qualifications on that number. First, it comes from the attacker, not from McKesson. Second, ShinyHunters itself clarified that 284 million is a count of database rows, not of individual patients — the group told reporters it had not finished analyzing the data and did not know how many unique people were represented. Early coverage that described "284 million patients" was wrong, and it is worth being precise, because the difference between a row count and a person count is the difference between a headline and a liability estimate.
The group says it demanded roughly $55 million with a 72-hour clock, then listed McKesson on its leak site and set a September 1 deadline for the company to open negotiations. McKesson has not confirmed the attacker's claims and has not publicly stated what was taken. The company has said it has "reasonable assurance" the intruders are no longer in its systems.
Strip away the details and the shape of this incident is disarmingly simple. A person answered a phone. Someone with a convincing story got access to an account. And then a legitimate credential opened a data warehouse.
The Question Boards Are Not Asking
Most board-level cyber conversations still orbit prevention and recovery. How do we keep them out? How fast can we come back up? Those questions matter, but neither one would have changed this outcome. Prevention failed on a phone call, not at a firewall. Recovery was largely beside the point, because the lights stayed on.
The question that would have changed the outcome is one I rarely hear in a boardroom: why was that much data sitting in one place, queryable by a single credential?
Modern enterprises have spent a decade consolidating data. Customer records, transaction history, clinical detail, employee files — all pulled out of aging siloed systems and centralized into cloud data platforms so analysts and AI models can work across the whole picture. The business case is real. The efficiency gains are real. And the security consequence is almost never priced into the decision: you have converted a hundred small breaches into one enormous one.
A siloed environment is inefficient and frustrating, and it also means an attacker with one stolen credential gets one system's worth of data. A consolidated warehouse means the same stolen credential gets everything. The data-theft extortion groups operating today understand this better than most executives do. They are not hunting for zero-day exploits. They are hunting for the person who can be talked into resetting an account that has query access to the warehouse.
What This Costs When Nothing Broke
McKesson's initial filing said the company had not determined the incident to be material. That may prove accurate under the SEC's standard, which turns on financial condition and results of operations — and if operations were unaffected, the near-term operational impact genuinely is limited.
But directors should understand the shape of the tail. In a data-theft extortion event, the cost does not arrive on the day of the incident. It arrives over the following eighteen to thirty-six months, in the form of notification obligations, regulatory inquiry, credit monitoring, class action exposure, and customer contract renegotiation. McKesson has already said it will provide complimentary credit monitoring and identity protection to affected individuals — a commitment made before the company knows how many individuals there are.
This is exactly the gap I describe in Cyber Risk Is Business Risk between compliance-driven and risk-driven security. A compliance posture asks whether the disclosure was timely and whether the controls were documented. A risk posture asks what the organization's total exposure looks like when data it has been accumulating for a decade becomes an asset in someone else's hands.
What to Ask Your CISO This Week
Four questions, each answerable in a single meeting:
Where is our largest single concentration of sensitive data, and how many credentials can query all of it? You are looking for a number. If nobody can produce one, that is the finding.
What happens when someone calls our help desk claiming to be an employee locked out of their account? Health-ISAC, the healthcare sector's threat-sharing body, has been warning specifically about this attack pattern and recommends out-of-band identity verification, a policy against completing resets on the same call, and phishing-resistant multifactor authentication. Ask whether your organization has all three. Ask when the process was last tested by someone actually trying to defeat it.
If an attacker exfiltrated a terabyte of data from our cloud environment over four days, would we see it? McKesson's intrusion reportedly ran from August 21 to August 25. Detection of large-volume egress from a data warehouse is a different capability from endpoint malware detection, and many organizations that have the second do not have the first.
Who decides whether an incident is material, and what does that person need in front of them to decide well? Materiality is a judgment made under time pressure with incomplete facts, often within days. If your board has not discussed the framework before an incident, it will be improvised during one.
The Reframe
The instinct after a breach like this is to ask how the attackers got in. It is the wrong first question. They got in the way attackers have gotten in for thirty years — by convincing a person to open a door.
The better question is what waited on the other side of that door, and why so much of it was in one room.
Every consolidation decision your organization has made in the past ten years — every data lake, every warehouse, every "single source of truth" — was a security decision that was probably made without a security conversation. Those decisions are not wrong. But they are unexamined, and they determine what a single stolen credential is worth.
Ask what yours is worth. Ask this week.