Skip to content
tag — okta

grep -rl "okta" ./articles

#okta

3 articles

A terabyte left over four days, and nothing in the chain was a vulnerability

2026-09-10Security

McKesson's 8-K describes roughly one terabyte exfiltrated between 21 and 25 August 2026, detected on the last day. The chain was vishing to Okta SSO to Salesforce and Snowflake — no CVE, no exploit, no patch. And the claimed 284 million records are database rows, by the attackers' own account.

It is not 284 million patients — and the people who stole the data are the ones saying so

2026-08-31Security

McKesson has confirmed a breach involving third-party applications. ShinyHunters claims a terabyte and 284 million records including Social Security numbers and medical histories, and demanded $55.236 million. The group has also clarified that the figure counts records, not individuals. Nobody knows how many people are affected, including them.

They phoned a security company, used real employees' names, and got in

2026-08-25Security

ShinyHunters registered a fake ReliaQuest SSO page and rang staff one by one, each time impersonating a named colleague from the security team. One person typed their password and approved the push. ReliaQuest says the attackers got view-only access to an Okta dashboard and nothing else — and the interesting part is which controls held.