Back to Blog
Incident Analysis

One Phone Call, One Terabyte: Why SaaS Became the Target

Plaza Cyber Security TeamSeptember 4, 20266 min read
Two colleagues walking through a darkened corridor lined with illuminated data centre displays
Two colleagues walking through a darkened corridor lined with illuminated data centre displays

The biggest corporate breach disclosed in August 2026 did not begin with a vulnerability. It began with a phone call.

On 25 August, McKesson — one of the largest healthcare supply and pharmaceutical distribution companies in the United States — discovered unauthorised access to third-party applications and confirmed that data had been taken. The extortion group ShinyHunters claimed responsibility and said its members had reached the data by calling McKesson employees, impersonating internal support, and talking them into handing over credentials for the company's Okta single sign-on service. With that login, the group says it reached McKesson's Salesforce and Snowflake environments and pulled roughly a terabyte of data out over four days. It then demanded a ransom of just over $55 million.

The headline figure attached to the story was 284 million records. That number deserves a caveat, and the group itself eventually supplied one: it refers to raw rows in the Snowflake export, not to 284 million distinct patients. The real count of affected people is lower and, at the time of writing, not established. The material is nonetheless serious — names, addresses, Social Security numbers, medical record and Medicaid numbers, prescription and treatment details, and information on healthcare providers and McKesson staff.

Nothing in this attack was technically difficult

That is the part worth sitting with. There was no exploit chain, no custom malware, no novel technique. The entire intrusion consisted of a convincing phone call followed by ordinary, authorised use of cloud platforms the company had bought on purpose.

This is not an isolated case. The same group has been linked to a string of 2026 incidents built on the same template: private data on more than 30 million students and staff taken from the Instructure/Canvas learning platform after voice phishing granted IT access, roughly 40 million customer records from Charter Communications, and about 6 million from Carnival. August produced others in the same family — Manchester Airports Group confirmed a breach affecting 8.8 million people, exposing contact details tied to car park, lounge and Fast Track bookings.

The common thread is not an industry or a company size. It is an architecture that most organisations now share.

Four conditions that make this work

Someone can be talked into giving up a login. Voice phishing works because it exploits helpfulness under time pressure, and because the person on the phone sounds like they belong. Email phishing training does very little to prepare staff for a confident caller who already knows the names of their colleagues and the name of the ticketing system.

Single sign-on turns one credential into many. SSO is good security — it centralises authentication, kills password reuse, and gives you one place to revoke access. It also means that one successfully phished login is not a door into one application. It is a door into whatever that identity is entitled to reach.

The data is not on your network. Salesforce, Snowflake, Microsoft 365, the HR platform, the billing platform — the most sensitive records most companies hold now live on infrastructure they do not own and cannot monitor with traditional tools. A firewall does not see a query run against your own data warehouse by a session that authenticated correctly.

Bulk export is a normal feature. Every one of these platforms is designed to let authorised users extract large volumes of data. That is what they are for. From inside a valid session, mass exfiltration looks like reporting.

Put those four together and you get the shape of the incident: a terabyte leaving over four days, through sanctioned channels, under a legitimate identity, with nothing that a conventional perimeter would flag.

What to actually change

Make the credential insufficient on its own. Phishing-resistant multi-factor authentication — hardware keys or passkeys rather than push notifications or codes — removes the payoff from the phone call. A caller who extracts a password and a one-time code from an employee gets nothing if the second factor is bound to a physical device and an origin.

Give the help desk a script it cannot be argued out of. Most of these intrusions turn on a credential reset or an MFA re-enrolment performed for someone who sounded legitimate. Verification should be out-of-band and identical every time: a callback to the number on record, or confirmation through a manager, with no exceptions for urgency. Make it a documented procedure so that refusing an unusual request is the easy choice rather than a judgement call.

Know which third parties hold your data. Most organisations cannot produce a current list of the SaaS platforms that store their customer or employee records, or say who inside the business can export from each one. That inventory is the prerequisite for everything else, and it is usually a one-afternoon exercise that nobody has been assigned.

Restrict who can extract in bulk. Report-building and mass export rarely need to be available to everyone with a login. Scope those permissions to the handful of roles that genuinely require them, and review the list on a schedule.

Watch the SaaS audit logs. Every major platform emits detailed activity logging — large result sets, new API integrations, OAuth grants to unfamiliar applications, logins from new locations. These logs are usually switched on and almost never read. Four days of sustained extraction is a long window in which an alert on anomalous export volume would have changed the outcome.

Alert on new application connections. A new OAuth integration quietly authorised against your tenant is one of the clearest early signals of an account takeover, and one of the easiest to monitor for.

The uncomfortable summary

Identity is now the perimeter, and the perimeter is staffed by people who can be telephoned. Organisations that have spent a decade hardening their networks often have almost no visibility into the cloud platforms where their data actually sits — who is in them, what those accounts can reach, and what left yesterday.

The attackers have noticed. They have stopped breaking in and started logging in, and they are doing it at a scale that no longer depends on technical sophistication. The defensive answer is unglamorous: phishing-resistant authentication, a help desk that verifies, a real inventory of where the data lives, and someone actually reading the logs those platforms are already writing.

Sources

#saas#identity#social engineering#cloud#incident analysis