McKesson Breach: ShinyHunters Claims 284 Million Records from Healthcare's Backbone
McKesson Corporation, the pharmaceutical distributor that moves roughly one-third of all prescription medicines to North American hospitals, pharmacies, and clinics [5], confirmed on August 28, 2026, that attackers exfiltrated customer data from its systems [1]. The breach struck its Oncology & Multispecialty and Medical-Surgical business units [2] [3]. The ShinyHunters extortion group has claimed responsibility, stating it pulled approximately 284 million raw data records from McKesson's Salesforce and Snowflake environments over four days between August 21 and August 25 [1] [4]. ShinyHunters issued a ransom demand of $55,236,150 with a 72-hour response window [2]. McKesson never answered [2]. The group's contact deadline was September 1; its data-publication deadline is September 9 [5].
This is not a breach at a mid-tier SaaS vendor. McKesson is critical healthcare infrastructure. The data categories ShinyHunters describes, including diagnoses, medications, Social Security numbers, Medicaid numbers, and medical record numbers [1] [3], fall squarely under HIPAA. Hospitals, oncology clinics, and surgical centers across the country that rely on McKesson's supply chain and technology platforms are now waiting to learn whether their patients' most sensitive information will be dumped on a dark web marketplace in eight days.
What McKesson Has Confirmed
McKesson's disclosures, delivered through an SEC Form 8-K filing on August 28, 2026, and a public notice on its website, are deliberately narrow [14]:
- The incident was discovered on August 25, 2026 [14].
- Unauthorized access involved certain third-party applications [1] [4].
- Data associated with a subset of customers in the Oncology & Multispecialty and Medical-Surgical units was exfiltrated [2].
- Initial actions to prevent further unauthorized access appear successful, with no further unauthorized activity detected [4].
- Business lines, ordering systems, and distribution centers remain operational, though customers may experience intermittent service degradation [1] [5].
- Complimentary credit monitoring and identity protection services will be offered to affected individuals [5].
What McKesson has not confirmed: the specific data fields taken, the number of affected individuals, the identity of the responsible group, or which third-party applications were involved [1] [5] [7]. McKesson stated that it does not believe customers need to take any action at this time [2]. McKesson's SEC filing states the company "has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations" [14]. McKesson spokesperson Kristina Chang confirmed the company "continues to operate in all lines of business" [7]. McKesson would not answer questions about the ransom demand or how many individuals were affected [7].
What ShinyHunters Is Claiming
ShinyHunters told BleepingComputer, CyberInsider, TechCrunch, and The Register that it voice-phished multiple McKesson employees to compromise their Okta SSO accounts, then used those accounts to access McKesson's Salesforce and Snowflake environments [1] [6] [7] [8]. The group claims approximately 1 terabyte of data was exfiltrated between August 21 and August 25 [4] [6].
The 284 million figure represents raw database rows, not unique individuals [1] [3] [4]. ShinyHunters clarified to both BleepingComputer and CyberInsider that it has not fully analyzed the stolen data and does not know how many unique people are represented, though it stated the records are linked to "tens of millions of patients" [1] [3]. CyberInsider reviewed data samples privately provided by the threat actor and reported they appeared consistent with the described breach claims [3]. TechCrunch independently verified a small subset of the shared data against public records [7].
Claimed stolen data categories include: full names, home addresses, dates of birth, phone numbers, email addresses, Social Security numbers, patient IDs, medical record numbers (MRNs), Medicaid numbers, diagnoses, allergies, medications, disabilities, patient notes, appointment details, prescription and billing records, employee records (including home addresses), internal Salesforce records, physician information, and emails containing private information from doctors to patients [1] [3] [5] [7] [8]. None of the extortion group's claims have been independently verified by McKesson [2].
Two things about the 284 million number need stating directly. First, it is the attacker's claim, unconfirmed by McKesson [17]. Second, the attackers themselves disclaimed it as a patient count. Rows in a data warehouse are transactions, claims, order lines, and appointment records. One patient generates hundreds. Attacker counts inflate further through duplication across tables, staging copies, and historical snapshots [17].
ShinyHunters: The Group Behind the Attack
ShinyHunters is a financially motivated data theft and extortion operation active since at least 2020 [9] [11]. The group is believed to be decentralized and internationally distributed [9]. Known arrested affiliates include French national Sebastien Raoult (arrested in Morocco in 2022, extradited to the U.S.) and at least four additional individuals arrested in France in June 2025 [9]. Despite these arrests, the group remains active and operational as of mid-2026, with law enforcement largely unable to neutralize its decentralized leadership structure [9].
ShinyHunters is part of a broader criminal ecosystem. Push Security describes a "Scattered Lapsus$ Hunters" (SLH) collective whose genealogy traces through a merger of Scattered Spider, Lapsus$, and ShinyHunters, all parts of "the Com," a broader community of English-speaking cybercriminals with international links [20]. Google Threat Intelligence Group (GTIG) and Mandiant track ShinyHunters-linked activity under cluster designations UNC6661, UNC6671, and UNC6240 [9] [10].
The McKesson breach is the latest in a sustained and escalating campaign against healthcare specifically. ShinyHunters hit pacemaker manufacturer Medtronic in April 2026, claiming 9 million records of PII and terabytes of internal corporate data [8] [15]. In July 2026, the group targeted Exact Sciences, a cancer diagnostics company, ultimately publishing 10.9 million unique email addresses alongside names, addresses, phone numbers, and health records [16]. ADT was reportedly compromised in April 2026 using the identical playbook: vishing to Okta SSO, then pivot to Salesforce [12].
Attack Chain: Vishing to Okta to SaaS to Extortion
The McKesson attack follows a consistent kill chain that Mandiant confirmed as an active, ongoing campaign in January 2026 [10].
Initial Access: Voice Phishing (T1566.004)
ShinyHunters operators impersonated IT support staff and called McKesson employees, directing them to enter Okta SSO credentials and MFA codes on custom victim-branded phishing portals [9] [10]. Okta warned that the phishing kits used in this campaign are capable of intercepting user credentials and MFA tokens in real time through adversary-in-the-middle techniques. Obsidian Security documented abnormal Okta authentication sequences consistent with interactive phishing or real-time adversary-in-the-middle operations across observed incidents [13].
Persistence: MFA Manipulation (T1098)
After compromising Okta accounts, ShinyHunters established persistence through MFA enrollment changes, frequently enrolling Okta FastPass on emulated Android devices [13]. Mandiant confirmed attackers enrolled attacker-controlled devices into victim MFA solutions [10]. This means simply resetting the compromised password isn't enough: the attacker's device remains a trusted MFA factor.
Lateral Movement: SSO Pivoting to SaaS (T1078, T1078.004)
With valid Okta SSO credentials, the group pivoted into McKesson's Salesforce and Snowflake environments [1] [6]. Obsidian Security documented immediate post-authentication access expansion including broad SSO application enumeration [13]. The pattern was consistent across observed incidents: compromise an Okta account, establish persistence through MFA changes, pivot across SSO-connected applications, and steal data [13].
Data Exfiltration (T1530)
Approximately 1 TB of data was exfiltrated over four days [4] [6]. Obsidian Security observed files downloaded within seconds of one another, strongly suggestive of automated collection and exfiltration rather than ordinary interactive browsing [13]. Unit 42 has documented these groups moving from initial compromise to complete data exfiltration in under an hour [20].
Extortion
ShinyHunters contacted McKesson after finishing the theft on August 25 and demanded $55,236,150, giving the company 72 hours to respond [2]. McKesson never answered [2]. The group then set a September 1 contact deadline and a September 9 data-publication deadline [5]. This follows their standard "pay-or-leak" model: no encryption, no ransomware payload, just stolen data and a countdown [9] [11].
IOC Table
| Type | Value | Context | Source |
|---|---|---|---|
| Domain | mckesson.claims |
Phishing domain used by ShinyHunters in the McKesson attack campaign | [1] |
| Domain | bless-invite.com |
Okta-themed phishing domain reused by ShinyHunters across multiple hosts | [11] |
| Domain | azurenetfiles.net |
C2 and staging domain disguised as cloud storage, used in ShinyHunters PeopleSoft attacks | [11] |
| Filename | meshagent32-azure-ops.exe |
MeshCentral agent renamed to masquerade as cloud-operations tool | [11] |
| Filename | meshagent64-azure-ops.exe |
MeshCentral agent renamed to masquerade as cloud-operations tool | [11] |
| Filename | meshagent64-v2.exe |
MeshCentral agent renamed to masquerade as cloud-operations tool | [11] |
| Filename | meshctrl.js |
MeshCentral command-line tool used for C2 command execution | [11] |
| Filename | README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT |
Extortion marker file dropped on compromised PeopleSoft servers | [11] |
Note: The mckesson.claims domain is directly tied to this incident. The remaining IOCs are from broader ShinyHunters campaigns and should be treated as threat-actor-level indicators.
MITRE ATT&CK Mapping
| ID | Technique | Relevance |
|---|---|---|
| T1566.004 | Phishing: Spearphishing Voice | Vishing calls to McKesson employees impersonating IT support [1] [6] [10] |
| T1078 | Valid Accounts | Stolen Okta SSO credentials used for legitimate login [9] [13] |
| T1078.004 | Valid Accounts: Cloud Accounts | Access to Salesforce and Snowflake via compromised cloud credentials [12] |
| T1098 | Account Manipulation | MFA enrollment changes to establish persistence [13] |
| T1528 | Steal Application Access Token | OAuth token abuse in broader ShinyHunters campaigns [9] [11] |
| T1530 | Data from Cloud Storage Object | Exfiltration from Salesforce and Snowflake environments [1] [4] |
| T1036 | Masquerading | MeshCentral agents renamed to impersonate cloud-operations tools [11] |
| T1537 | Transfer Data to Cloud Account | Data staged and exfiltrated to attacker-controlled cloud storage [12] |
Detection and Hunting
ShinyHunters' playbook is identity-first. There may be no malicious binary in the environment at all [18]. Detection must focus on the identity and SaaS layers.
Okta Log Anomalies
Hunt for these patterns in Okta system logs:
- New MFA factor enrollment (especially Okta FastPass on Android devices) followed by immediate SSO application access across multiple apps [13]
- Authentication events from unusual geolocations or ASNs within minutes of a helpdesk call
- Multiple
user.mfa.factor.activateevents for a single user in a short window - Successful authentication after repeated MFA failures (push fatigue indicator)
index=okta eventType IN ("user.mfa.factor.activate", "user.authentication.sso")
| stats count by actor.alternateId
| where count > 5
Salesforce and Snowflake Bulk Export
Alert on bulk export API calls and anomalous query volumes [18]:
- Salesforce: Monitor
ApiEvent,ListViewEvent, andReportExportEventin Event Monitoring logs for high-volume data access from newly authenticated sessions - Snowflake: Query
SNOWFLAKE.ACCOUNT_USAGE.ACCESS_HISTORYfor unusualQUERY_TYPE=SELECTvolumes, especially from service accounts or recently provisioned users - Files downloaded within seconds of one another indicate automated collection [13]
OAuth and App Consent Grants
Monitor for OAuth consent grants to unrecognized applications in Entra ID, Salesforce, and Snowflake [18]. ShinyHunters has abused stolen OAuth tokens from Salesloft/Drift (August 2025, ~760 downstream Salesforce organizations), Gainsight (November 2025, 200+ Salesforce instances), and Anodot (April 2026) [9] [11].
Sigma Rule: Suspicious Okta MFA Enrollment Followed by Bulk SSO Access
Note: The near temporal correlation operator has limited backend support. Verify compatibility with your SIEM before deployment.
title: Suspicious Okta MFA Enrollment Followed by Rapid SSO Application Access
id: f3a2c1d8-7e45-4b91-a6d3-9c8e2f1b0a47
status: experimental
author: RedSheepSec
date: 2026/09/01
description: Detects new MFA factor enrollment on an Okta account followed by rapid access to multiple SSO-connected applications, consistent with ShinyHunters account takeover tradecraft
logsource:
product: okta
service: okta
detection:
selection_mfa:
eventType: 'user.mfa.factor.activate'
selection_sso:
eventType: 'user.authentication.sso'
timeframe: 15m
condition: selection_mfa | near selection_sso
falsepositives:
- Legitimate IT onboarding or MFA reset followed by normal application access
level: high
tags:
- attack.persistence
- attack.t1098
- attack.t1078
Analysis
The McKesson breach isn't a one-off. It's the third confirmed ShinyHunters operation against a major healthcare target in five months: Medtronic in April (9 million claimed records) [15], Exact Sciences in July (10.9 million unique emails published) [16], and now McKesson. The attack chain is identical every time: vishing to Okta SSO compromise, pivot to SaaS data stores, exfiltration, extortion [12] [13].
The broader ShinyHunters campaign extends well beyond healthcare. Push Security documented the group claiming over 1.5 billion stolen Salesforce records from a campaign targeting more than 1,000 organizations [20]. The 2024 Snowflake campaign compromised over 165 customer environments [20]. The Anodot supply chain compromise in 2026 reportedly produced confirmed breaches at multiple downstream organizations [20].
The downstream HIPAA implications for McKesson are enormous. As a business associate handling PHI on behalf of covered entities, 45 CFR 164.410 requires McKesson to notify those covered entities without unreasonable delay and no later than 60 days from discovery [17]. This creates a "fan-out": one breach determination upstream triggers thousands of independent notification obligations downstream, each carrying its own burden, each recorded separately on a public federal portal [17]. The specifics of exactly whose data was involved may not be clear for weeks.
The stolen data's combination of identity information and healthcare details could make affected individuals targets for convincing scams. Criminals could impersonate a pharmacy, insurer, medical provider, debt collector, or patient-support service using the stolen personal details [6].
Red Sheep Assessment
Confidence: High that McKesson's Salesforce and Snowflake environments were compromised via the vishing-to-Okta chain described. Three independent outlets received and partially verified data samples [3] [7], the attack chain matches Mandiant-confirmed ShinyHunters tradecraft tracked under UNC6661/UNC6671/UNC6240 [10], and McKesson's own disclosure language ("unauthorized access to certain third-party applications and the exfiltration of certain data" [2]) is consistent with the Salesforce/Snowflake compromise claims without explicitly confirming them.
Confidence: Moderate that the actual number of affected unique individuals will be in the low tens of millions rather than 284 million. The attackers themselves disclaimed the 284 million figure as a row count [1] [3]. McKesson's Oncology & Multispecialty and Medical-Surgical units serve a large but bounded population, and data warehouse row counts routinely inflate by 10x to 50x over unique individuals due to transaction-level records, historical snapshots, and cross-table duplication [17].
Contrarian take: McKesson's assertion that the incident is not material [14] is likely to be revised as the investigation progresses and the scope of affected PHI becomes clear. A company that handles PHI for a substantial fraction of U.S. oncology practices and medical-surgical providers, facing a threat actor with a proven track record of publishing stolen healthcare data (Exact Sciences [16]), cannot credibly claim immateriality before completing its investigation. The September 9 publication deadline will force the issue. McKesson's decision not to engage with the ransom demand [2] is defensible from a policy standpoint, but it makes publication highly probable based on ShinyHunters' prior behavior.
Structural observation: ShinyHunters' sustained healthcare focus in 2026 (Medtronic, Exact Sciences, McKesson) suggests deliberate sector targeting rather than opportunism. Healthcare organizations combine high-value regulated data with exactly the kind of sprawling SaaS and cloud identity infrastructure that ShinyHunters has optimized its playbook to exploit [18]. We assess the group understands this attack surface better than many of the organizations defending it [18].
Defender's Checklist
- ▢[ ] Deploy FIDO2 security keys or passkeys for all accounts with SSO and cloud admin access. Push-based and SMS MFA are insufficient against this threat actor. Google and Okta explicitly recommend phishing-resistant authenticators [9] [17].
- ▢[ ] Audit Okta MFA enrollment logs for the past 90 days. Look for new FastPass enrollments on Android devices, especially from users who also received helpdesk calls. Query:
eventType="user.mfa.factor.activate" AND factor.factorType="push"[13]. - ▢[ ] Inventory and revoke orphaned OAuth grants in Salesforce and Snowflake. Disable user consent to unverified apps in Entra ID and require admin consent workflow for all third-party app grants [18].
- ▢[ ] Enable and centralize Salesforce Event Monitoring, Snowflake access history, and IdP audit logs into your SIEM. Alert on bulk export API calls, anomalous query volumes, and files downloaded within seconds of one another [13] [18].
- ▢[ ] Validate your HIPAA breach notification chain. Review and test your BAA notification playbook, ensuring you can identify which vendor relationships involve PHI, extract affected populations by state within 30 days, and file HHS notifications within the 60-day window per 45 CFR 164.410 [17].
References
[1] https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
[2] https://www.helpnetsecurity.com/2026/08/31/healthcare-company-mckesson-data-breach/
[3] https://cyberinsider.com/mckesson-data-breach-exposing-284-million-patients/
[4] https://www.hipaajournal.com/mckesson-data-breach/
[5] https://www.securityweek.com/mckesson-confirms-data-breach-as-attacker-deadline-looms/
[6] https://www.malwarebytes.com/blog/news/2026/08/mckesson-confirms-cyber-incident-after-shinyhunters-claims-patient-data-theft
[7] https://techcrunch.com/2026/08/31/hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson/
[8] https://www.theregister.com/cyber-crime/2026/08/31/healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records/5293537
[9] https://www.huntress.com/threat-library/threat-actors/shinyhunters
[10] https://www.cybersecuritydive.com/news/shinyhunters-tactics-extortion-okta-environ/811112/
[11] https://www.picussecurity.com/resource/blog/the-shinyhunters-domino-effect-one-breach-hundreds-of-victims
[12] https://www.rescana.com/post/adt-salesforce-data-breach-2026-shinyhunters-compromise-okta-sso-via-vishing-attack
[13] https://www.obsidiansecurity.com/blog/behind-the-breach-shinyhunters-2026-voice-phishing-campaign
[14] https://d18rn0p25nwr6d.cloudfront.net/CIK-0000927653/5d76bf4d-9af6-40d2-89cc-6648aa9cbb59.pdf
[15] https://www.paubox.com/blog/shinyhunters-dumps-data-in-mass-leak-as-medtronic-disappears-from-groups-site
[16] https://haveibeenpwned.com/Breach/ExactSciences
[17] https://compliancehub.wiki/mckesson-breach-hipaa-business-associate-notification-cascade-164-410-2026/
[18] https://securityarsenal.com/blog/mckesson-data-theft-extortion-attack-defending-healthcare-saas-and-cloud-data-against-shinyhunters-style-extortion
[19] https://en.wikipedia.org/wiki/ShinyHunters
[20] https://pushsecurity.com/blog/analyzing-the-instructure-breach
Event Timeline
Timeline
Entity Relationships
Entity Graph (6 entities, 6 relationships)
Diamond Model
Diamond Model
Hunt Guide: ShinyHunters Vishing-to-SaaS Extortion Campaign Targeting Healthcare
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If ShinyHunters or affiliated actors (UNC6661/UNC6671/UNC6240) are targeting our environment using their documented vishing-to-Okta-to-SaaS kill chain, we expect to observe anomalous Okta MFA enrollment events, suspicious SSO authentication patterns from unusual ASNs or geolocations, bulk data export activity from Salesforce or Snowflake environments, DNS queries to known ShinyHunters phishing domains (mckesson.claims, bless-invite.com, azurenetfiles.net), and presence of renamed MeshCentral agent binaries on endpoints.
Intelligence Summary: ShinyHunters, a financially motivated data theft and extortion group tracked by Mandiant under UNC6661/UNC6671/UNC6240, has claimed responsibility for exfiltrating approximately 1 TB (284 million raw rows) of patient and employee data from McKesson Corporation's Salesforce and Snowflake environments between August 21–25, 2026. The attack chain involved voice-phishing McKesson employees to compromise Okta SSO accounts, enrolling attacker-controlled MFA devices for persistence, pivoting across SSO-connected SaaS applications, and conducting automated bulk data exfiltration — a playbook identical to confirmed ShinyHunters operations against Medtronic (April 2026) and Exact Sciences (July 2026). McKesson confirmed the breach via SEC Form 8-K but has not confirmed the responsible group, the specific data fields taken, or the number of affected individuals; ShinyHunters issued a $55.2M ransom demand that McKesson never answered, with a September 9 data-publication deadline.
Confidence: High | Priority: Critical
Scope
- Networks: All network segments with access to identity providers (Okta, Azure AD/Entra ID), SaaS platforms (Salesforce, Snowflake), and healthcare data systems. Priority on segments hosting SSO-connected applications and cloud administration endpoints. Include VPN concentrator egress points and cloud proxy infrastructure.
- Timeframe: 90 days retrospective (June 1, 2026 – September 1, 2026) to cover the full ShinyHunters 2026 healthcare campaign timeline, with emphasis on the August 21–25 active compromise window and the preceding 30 days for preparatory reconnaissance/social engineering.
- Priority Systems: Okta SSO infrastructure and all federated identity providers; Salesforce instances (especially Health Cloud, Service Cloud instances containing PHI); Snowflake environments containing patient/healthcare data; IT helpdesk and service desk systems (for vishing correlation); MFA enrollment infrastructure; Any systems in Oncology, Medical-Surgical, or pharmacy supply chain business units; Cloud administration consoles (AWS, Azure, GCP) with SSO integration.
MITRE ATT&CK Techniques
T1566.004 — Phishing: Spearphishing Voice (Initial Access) [P1]
ShinyHunters operators impersonated IT support staff and called McKesson employees, directing them to enter Okta SSO credentials and MFA codes on custom victim-branded phishing portals. The phishing kits are capable of intercepting credentials and MFA tokens in real time through adversary-in-the-middle techniques.
Splunk SPL:
index=corelight sourcetype=corelight_dns query IN ("mckesson.claims", "bless-invite.com", "azurenetfiles.net") | stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip query answers | table first_seen last_seen src_ip query answers count
Elastic KQL:
dns.question.name:("mckesson.claims" OR "bless-invite.com" OR "azurenetfiles.net")
Sigma Rule:
title: DNS Query to ShinyHunters Phishing Infrastructure
id: a1b2c3d4-5e6f-7890-abcd-ef1234567890
status: experimental
author: RedSheepSec
date: 2026/09/01
description: Detects DNS queries to known ShinyHunters phishing domains used in vishing campaigns targeting Okta SSO credentials
logsource:
category: dns
detection:
selection:
query|contains:
- 'mckesson.claims'
- 'bless-invite.com'
- 'azurenetfiles.net'
condition: selection
falsepositives:
- Threat intelligence research platforms querying these domains
level: critical
tags:
- attack.initial_access
- attack.t1566.004
These domains are directly from ShinyHunters campaign reporting. mckesson.claims is tied specifically to the McKesson incident; bless-invite.com and azurenetfiles.net are from broader ShinyHunters campaigns. Any match warrants immediate escalation.
T1098 — Account Manipulation (Persistence) [P2]
After compromising Okta accounts via vishing, ShinyHunters established persistence through MFA enrollment changes, frequently enrolling Okta FastPass on emulated Android devices. Simply resetting the compromised password is insufficient because the attacker's device remains a trusted MFA factor.
Splunk SPL:
index=cloud-azure sourcetype="azure:monitor:aad" OR index=* sourcetype=okta* eventType="user.mfa.factor.activate"
| eval factor_type=coalesce('debugContext.debugData.factor', 'target{}.type')
| stats count earliest(_time) as first_enrollment latest(_time) as last_enrollment values(factor_type) as factors by actor.alternateId
| where count > 2
| sort - count
| table actor.alternateId count first_enrollment last_enrollment factors
Note: Okta logs may be ingested via cloud-azure or a custom index. Verify Okta log ingestion path in your environment.
**Elastic KQL:**
event.dataset:"okta.system" AND eventType:"user.mfa.factor.activate" | Aggregate by actor.alternateId and look for count > 2 in short windows
**Sigma Rule:**
title: Suspicious Okta MFA Enrollment Followed by Rapid SSO Application Access
id: f3a2c1d8-7e45-4b91-a6d3-9c8e2f1b0a47
status: experimental
author: RedSheepSec
date: 2026/09/01
description: Detects new MFA factor enrollment on an Okta account followed by rapid access to multiple SSO-connected applications, consistent with ShinyHunters account takeover tradecraft documented by Obsidian Security and Mandiant
logsource:
product: okta
service: okta
detection:
selection_mfa:
eventType: 'user.mfa.factor.activate'
selection_sso:
eventType: 'user.authentication.sso'
timeframe: 15m
condition: selection_mfa | near selection_sso
falsepositives:
- Legitimate IT onboarding or MFA reset followed by normal application access
level: high
tags:
- attack.persistence
- attack.t1098
- attack.t1078
*Focus on FastPass enrollments on Android devices. Cross-reference with helpdesk ticket timestamps — attackers call victims shortly before MFA enrollment events. The sigma 'near' operator requires specific SIEM support (e.g., Splunk correlation searches). Consider implementing as a Splunk correlation search with transaction or stats commands instead.*
#### T1078 — Valid Accounts (Defense Evasion) [P2]
With stolen Okta SSO credentials, ShinyHunters used valid accounts to authenticate to downstream SaaS applications. Because the credentials are legitimate, this activity may bypass signature-based detection and blend with normal authentication traffic.
**Splunk SPL:**
index=cloud-azure sourcetype="azure:monitor:aad" operationName="Sign-in activity"
| iplocation src_ip |
|---|
| stats dc(src_ip) as unique_ips dc(Country) as unique_countries values(Country) as countries values(src_ip) as source_ips count by user |
| where unique_countries > 1 AND count > 3 |
| sort - unique_countries |
| table user unique_ips unique_countries countries source_ips count |
**Elastic KQL:**
event.dataset:"azure.signinlogs" AND event.outcome:"success" | Look for users authenticating from multiple countries within short timeframes
**Sigma Rule:**
title: Multi-Geographic Authentication Anomaly Indicating Credential Compromise
id: b2c3d4e5-6f78-9012-abcd-ef2345678901
status: experimental
author: RedSheepSec
date: 2026/09/01
description: Detects a single user account successfully authenticating from multiple geographic locations in a short time window, which may indicate credential compromise consistent with ShinyHunters vishing-to-SSO attacks
logsource:
product: azure
service: signinlogs
detection:
selection:
Status.errorCode: 0
condition: selection
# Post-processing required: aggregate by userPrincipalName and check for multiple distinct client IP geolocations within 1 hour
falsepositives:
- VPN usage causing geo-diversity
- Traveling users
- Cloud proxy services
level: medium
tags:
- attack.defense_evasion
- attack.t1078
*This is an anomaly detection that requires baseline tuning. Exclude known VPN egress IPs and cloud proxy ranges. Focus on users with SSO access to Salesforce and Snowflake. Combine with MFA enrollment anomalies for higher fidelity.*
#### T1078.004 — Valid Accounts: Cloud Accounts (Defense Evasion) [P2]
ShinyHunters pivoted from compromised Okta SSO into McKesson's Salesforce and Snowflake environments using valid cloud account credentials. Obsidian Security documented immediate post-authentication access expansion including broad SSO application enumeration.
**Splunk SPL:**
index=cloud-azure sourcetype="azure:monitor:aad" OR index= sourcetype=okta
eventType="user.authentication.sso"
| stats dc(target{}.displayName) as app_count values(target{}.displayName) as apps earliest(_time) as first_access latest(_time) as last_access by actor.alternateId |
|---|
| where app_count > 5 |
| eval time_span_minutes=round((last_access - first_access)/60, 2) |
| where time_span_minutes < 30 |
| sort - app_count |
| table actor.alternateId app_count time_span_minutes first_access last_access apps |
`Note: Adjust Okta log sourcetype to match your ingestion configuration.`
Elastic KQL:
event.dataset:"okta.system" AND eventType:"user.authentication.sso" | Aggregate by actor.alternateId within 30min windows and alert when distinct target app count > 5
Sigma Rule:
title: Rapid SSO Application Enumeration After Authentication
id: c3d4e5f6-7890-1234-abcd-ef3456789012
status: experimental
author: RedSheepSec
date: 2026/09/01
description: Detects a user accessing more than 5 distinct SSO-connected applications within 30 minutes, consistent with ShinyHunters lateral movement via SSO pivoting after Okta account compromise
logsource:
product: okta
service: okta
detection:
selection:
eventType: 'user.authentication.sso'
condition: selection
# Post-processing: aggregate by actor.alternateId within 30m, alert on dc(target.displayName) > 5
falsepositives:
- IT administrators performing application testing
- Automated SSO health checks
level: high
tags:
- attack.defense_evasion
- attack.t1078.004
Tune the threshold based on your environment's normal SSO access patterns. IT administrators and service accounts may legitimately access many applications. The key indicator is rapid sequential access to data-rich applications (Salesforce, Snowflake, data warehouses) by a non-admin user immediately following MFA changes.
T1530 — Data from Cloud Storage Object (Collection) [P2]
Approximately 1 TB of data was exfiltrated from Salesforce and Snowflake over four days. Obsidian Security observed files downloaded within seconds of one another, strongly suggestive of automated collection and exfiltration rather than ordinary interactive browsing.
Splunk SPL:
index=corelight sourcetype=corelight_conn dest_port IN (443, 80)
| stats sum(resp_bytes) as total_bytes_out dc(dest_ip) as unique_dests by src_ip
| eval total_gb=round(total_bytes_out/1073741824, 2)
| where total_gb > 5
| sort - total_gb
| table src_ip total_gb unique_dests
Note: This is a broad sweep for large outbound data transfers. Correlate with identity-layer anomalies for higher fidelity. Adjust threshold based on normal data volumes.
**Elastic KQL:**
source.bytes > 5368709120 AND event.dataset:"zeek.conn" AND destination.port:(443 OR 80)
**Sigma Rule:**
title: Large Outbound Data Transfer Indicating Potential Bulk Exfiltration
id: d4e5f6a7-8901-2345-abcd-ef4567890123
status: experimental
author: RedSheepSec
date: 2026/09/01
description: Detects large outbound data transfers (>5GB) that may indicate bulk data exfiltration from cloud storage objects, consistent with ShinyHunters automated data collection from Salesforce and Snowflake environments
logsource:
category: network_connection
detection:
selection:
dst_port:
- 443
- 80
filter:
dst_ip|cidr:
- '10.0.0.0/8'
- '172.16.0.0/12'
- '192.168.0.0/16'
condition: selection and not filter
# Post-processing: aggregate by src_ip over 24h, alert when total bytes > 5GB
falsepositives:
- Large legitimate file transfers or backups
- Software distribution
- Video conferencing
level: medium
tags:
- attack.collection
- attack.t1530
- attack.exfiltration
- attack.t1537
*This is a volumetric anomaly detection that requires significant tuning. Whitelist known backup destinations, CDN traffic, and legitimate cloud service endpoints. The critical correlation is combining this with identity-layer anomalies (MFA changes, unusual SSO access) to distinguish exfiltration from normal business operations.*
#### T1528 — Steal Application Access Token (Credential Access) [P2]
ShinyHunters has abused stolen OAuth tokens from third-party integrations (Salesloft/Drift, Gainsight, Anodot) to gain downstream access to Salesforce organizations in broader campaigns. Defenders should monitor for OAuth consent grants to unrecognized applications.
**Splunk SPL:**
index=cloud-azure sourcetype="azure:monitor:aad" operationName="Consent to application"
| stats count values(targetResources{}.displayName) as app_name values(initiatedBy.user.userPrincipalName) as user by resultDescription |
|---|
| table _time user app_name resultDescription count |
**Elastic KQL:**
event.dataset:"azure.auditlogs" AND azure.auditlogs.operation_name:"Consent to application"
**Sigma Rule:**
title: OAuth Application Consent Grant in Azure AD
id: e5f6a7b8-9012-3456-abcd-ef5678901234
status: experimental
author: RedSheepSec
date: 2026/09/01
description: Detects OAuth consent grants to applications in Azure AD which may indicate stolen token abuse or illicit consent grant attacks used by ShinyHunters for lateral access to SaaS environments
logsource:
product: azure
service: auditlogs
detection:
selection:
operationName: 'Consent to application'
condition: selection
falsepositives:
- Legitimate application onboarding by IT administrators
- User consent to approved enterprise applications
level: medium
tags:
- attack.credential_access
- attack.t1528
*Review all consent grants against your approved application inventory. ShinyHunters has compromised third-party integrations (Salesloft/Drift, Gainsight, Anodot) to gain downstream access. Any consent grant from a user who recently had MFA changes should be investigated immediately.*
#### T1036 — Masquerading (Defense Evasion) [P1]
ShinyHunters renamed MeshCentral remote management agents to masquerade as cloud-operations tools (meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, meshagent64-v2.exe). The meshctrl.js script was used for C2 command execution.
**Splunk SPL:**
index=sysmon sourcetype=XmlWinEventLog EventCode=1
(OriginalFileName="meshagent" OR OriginalFileName="meshctrl" OR CommandLine="meshagent" OR CommandLine="meshctrl" OR Image="meshagent32-azure-ops" OR Image="meshagent64-azure-ops" OR Image="meshagent64-v2" OR Image="meshctrl.js")
| table _time Computer User Image OriginalFileName CommandLine ParentImage ParentCommandLine |
|---|
**Elastic KQL:**
(process.name:("meshagent32-azure-ops.exe" OR "meshagent64-azure-ops.exe" OR "meshagent64-v2.exe" OR "meshctrl.js") OR process.pe.original_file_name:(meshagent OR meshctrl)) AND event.code:"1"
**Sigma Rule:**
title: ShinyHunters MeshCentral Agent Masquerading as Cloud Operations Tool
id: f6a7b8c9-0123-4567-abcd-ef6789012345
status: experimental
author: RedSheepSec
date: 2026/09/01
description: Detects execution of MeshCentral remote management agents renamed to masquerade as cloud-operations tools, a technique used by ShinyHunters for C2 in PeopleSoft and broader campaigns
logsource:
category: process_creation
product: windows
detection:
selection_filename:
Image|endswith:
- '\meshagent32-azure-ops.exe'
- '\meshagent64-azure-ops.exe'
- '\meshagent64-v2.exe'
selection_meshctrl:
CommandLine|contains: 'meshctrl.js'
selection_original:
OriginalFileName|contains:
- 'meshagent'
- 'MeshService'
filter_legitimate:
Image|contains: '\Program Files\MeshCentral'
condition: (selection_filename or selection_meshctrl or selection_original) and not filter_legitimate
falsepositives:
- Legitimate MeshCentral installations managed by IT
level: critical
tags:
- attack.defense_evasion
- attack.t1036
*MeshCentral is a legitimate open-source RMM tool. Any instance not provisioned by IT should be treated as suspicious. The renaming to include 'azure-ops' is a strong indicator of ShinyHunters activity. Also hunt for the meshctrl.js script being executed via node.js or wscript.*
#### T1537 — Transfer Data to Cloud Account (Exfiltration) [P2]
Data was staged and exfiltrated to attacker-controlled cloud storage. Unit 42 has documented ShinyHunters moving from initial compromise to complete data exfiltration in under an hour in some cases.
**Splunk SPL:**
index=corelight sourcetype=corelight_http
(uri="export" OR uri="download" OR uri="bulk" OR uri="query")
(host=".salesforce.com" OR host=".snowflakecomputing.com")
| stats count sum(response_body_len) as total_bytes by src_ip host uri |
|---|
| eval total_mb=round(total_bytes/1048576, 2) |
| where total_mb > 100 |
| sort - total_mb |
| table src_ip host uri total_mb count |
**Elastic KQL:**
url.domain:(salesforce.com OR snowflakecomputing.com) AND (url.path:export OR url.path:download OR url.path:bulk) AND http.response.body.bytes > 104857600
**Sigma Rule:**
title: Bulk Data Export from SaaS Platform Indicating Exfiltration
id: a7b8c9d0-1234-5678-abcd-ef7890123456
status: experimental
author: RedSheepSec
date: 2026/09/01
description: Detects high-volume HTTP requests to Salesforce or Snowflake export/download endpoints that may indicate bulk data exfiltration by ShinyHunters or similar actors
logsource:
category: proxy
detection:
selection_target:
c-uri|contains:
- '.salesforce.com'
- '.snowflakecomputing.com'
selection_action:
c-uri|contains:
- 'export'
- 'download'
- 'bulk'
- 'queryAll'
condition: selection_target and selection_action
falsepositives:
- Legitimate data integration pipelines (ETL jobs)
- Scheduled report exports by authorized users
level: high
tags:
- attack.exfiltration
- attack.t1537
- attack.collection
- attack.t1530
*Whitelist known ETL/integration service accounts and their source IPs. The critical correlation is whether the user performing the export recently had identity-layer anomalies (MFA changes, unusual authentication). Salesforce Event Monitoring logs (ApiEvent, ReportExportEvent) provide richer context than proxy logs alone.*
### Indicators of Compromise
| Type | Value | Context |
|------|-------|---------|
| domain | `mckesson.claims` | Phishing domain used by ShinyHunters in the McKesson attack campaign for vishing-based credential harvesting |
| domain | `bless-invite.com` | Okta-themed phishing domain reused by ShinyHunters across multiple hosts in vishing campaigns |
| domain | `azurenetfiles.net` | C2 and staging domain disguised as cloud storage, used in ShinyHunters PeopleSoft attacks |
| filename | `meshagent32-azure-ops.exe` | MeshCentral agent renamed to masquerade as cloud-operations tool, used by ShinyHunters for C2 |
| filename | `meshagent64-azure-ops.exe` | MeshCentral agent renamed to masquerade as cloud-operations tool, used by ShinyHunters for C2 |
| filename | `meshagent64-v2.exe` | MeshCentral agent renamed to masquerade as cloud-operations tool, used by ShinyHunters for C2 |
| filename | `meshctrl.js` | MeshCentral command-line tool used by ShinyHunters for C2 command execution |
| filename | `README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT` | Extortion marker file dropped by ShinyHunters on compromised PeopleSoft servers |
**IOC Sweep Queries (Splunk):**
index=corelight sourcetype=corelight_dns query="mckesson.claims" OR query="*.mckesson.claims"
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip query answers |
|---|
| table first_seen last_seen src_ip query answers count |
index=corelight sourcetype=corelight_dns query="bless-invite.com" OR query="*.bless-invite.com"
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip query answers |
|---|
| table first_seen last_seen src_ip query answers count |
index=corelight sourcetype=corelight_dns query="azurenetfiles.net" OR query="*.azurenetfiles.net"
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip query answers |
|---|
| table first_seen last_seen src_ip query answers count |
index=sysmon sourcetype=XmlWinEventLog (EventCode=1 OR EventCode=11 OR EventCode=7)
(Image="meshagent32-azure-ops" OR TargetFilename="meshagent32-azure-ops" OR ImageLoaded="meshagent32-azure-ops")
| table _time Computer EventCode Image TargetFilename CommandLine User |
|---|
index=sysmon sourcetype=XmlWinEventLog (EventCode=1 OR EventCode=11 OR EventCode=7)
(Image="meshagent64-azure-ops" OR TargetFilename="meshagent64-azure-ops" OR ImageLoaded="meshagent64-azure-ops")
| table _time Computer EventCode Image TargetFilename CommandLine User |
|---|
index=sysmon sourcetype=XmlWinEventLog (EventCode=1 OR EventCode=11 OR EventCode=7)
(Image="meshagent64-v2" OR TargetFilename="meshagent64-v2" OR ImageLoaded="meshagent64-v2")
| table _time Computer EventCode Image TargetFilename CommandLine User |
|---|
index=sysmon sourcetype=XmlWinEventLog (EventCode=1 OR EventCode=11)
(CommandLine="meshctrl.js" OR TargetFilename="meshctrl.js" OR Image="meshctrl")
| table _time Computer EventCode Image TargetFilename CommandLine User ParentImage |
|---|
index=sysmon sourcetype=XmlWinEventLog EventCode=11
TargetFilename="README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED"
| table _time Computer TargetFilename Image User |
|---|
### YARA Rules
**ShinyHunters_MeshCentral_Masquerade** — Detects MeshCentral agents renamed to masquerade as Azure/cloud operations tools, consistent with ShinyHunters C2 tradecraft
rule ShinyHunters_MeshCentral_Masquerade {
meta:
description = "Detects MeshCentral agents renamed to masquerade as Azure/cloud operations tools by ShinyHunters"
author = "RedSheepSec"
date = "2026-09-01"
threat_actor = "ShinyHunters"
reference = "https://www.picussecurity.com/resource/blog/the-shinyhunters-domino-effect-one-breach-hundreds-of-victims"
strings:
$meshagent_azure1 = "meshagent32-azure-ops" ascii wide nocase
$meshagent_azure2 = "meshagent64-azure-ops" ascii wide nocase
$meshagent_v2 = "meshagent64-v2" ascii wide nocase
$meshctrl = "meshctrl.js" ascii wide nocase
$mesh_svc1 = "MeshCentralAgent" ascii wide
$mesh_svc2 = "MeshAgentService" ascii wide
$marker = "README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED" ascii wide nocase
condition:
uint16(0) == 0x5A4D and filesize < 50MB and
(any of ($meshagent_azure*, $meshagent_v2) or
($meshctrl and any of ($mesh_svc*)))
}
**ShinyHunters_Extortion_Marker** — Detects the ShinyHunters extortion marker file dropped on compromised servers
rule ShinyHunters_Extortion_Marker {
meta:
description = "Detects ShinyHunters extortion marker file content"
author = "RedSheepSec"
date = "2026-09-01"
threat_actor = "ShinyHunters"
strings:
$marker = "README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED" ascii wide nocase
$shiny = "ShinyHunters" ascii wide nocase
condition:
filesize < 10KB and $marker
}
### Suricata Rules
**SID 9000001** — Detects DNS query to ShinyHunters phishing domain mckesson.claims used in McKesson breach campaign
alert dns $HOME_NET any -> any any (msg:"HUNT ShinyHunters Phishing Domain - mckesson.claims"; dns.query; content:"mckesson.claims"; nocase; classtype:social-engineering; sid:9000001; rev:1; metadata:created_at 2026_09_01, updated_at 2026_09_01;)
**SID 9000002** — Detects DNS query to ShinyHunters Okta-themed phishing domain bless-invite.com
alert dns $HOME_NET any -> any any (msg:"HUNT ShinyHunters Phishing Domain - bless-invite.com"; dns.query; content:"bless-invite.com"; nocase; classtype:social-engineering; sid:9000002; rev:1; metadata:created_at 2026_09_01, updated_at 2026_09_01;)
**SID 9000003** — Detects DNS query to ShinyHunters C2/staging domain azurenetfiles.net disguised as cloud storage
alert dns $HOME_NET any -> any any (msg:"HUNT ShinyHunters C2 Domain - azurenetfiles.net"; dns.query; content:"azurenetfiles.net"; nocase; classtype:trojan-activity; sid:9000003; rev:1; metadata:created_at 2026_09_01, updated_at 2026_09_01;)
**SID 9000004** — Detects TLS SNI to ShinyHunters phishing domain mckesson.claims
alert tls $HOME_NET any -> $EXTERNAL_NET any (msg:"HUNT ShinyHunters TLS SNI - mckesson.claims"; tls.sni; content:"mckesson.claims"; nocase; classtype:social-engineering; sid:9000004; rev:1; metadata:created_at 2026_09_01, updated_at 2026_09_01;)
**SID 9000005** — Detects TLS SNI to ShinyHunters C2 domain azurenetfiles.net
alert tls $HOME_NET any -> $EXTERNAL_NET any (msg:"HUNT ShinyHunters TLS SNI - azurenetfiles.net"; tls.sni; content:"azurenetfiles.net"; nocase; classtype:trojan-activity; sid:9000005; rev:1; metadata:created_at 2026_09_01, updated_at 2026_09_01;)