McKesson Breach Exposes SaaS Identity and Data-Concentration Risk
McKesson is investigating a reported vishing-led compromise involving third-party applications, Okta, Salesforce and Snowflake, with reports of up to 284 million patient records exposed. The incident is still developing and details remain unconfirmed, but it is a high-signal case for evaluating delegated access, SaaS identity containment, data minimization, third-party risk and healthcare concentration risk.
Sources (2)
Updated Sep 1, 2026