There is no CVE in this story. There is no patch to schedule, no vendor advisory to read, and nothing for a scanner to flag. That is the entire point of it.
On August 28, 2026, McKesson — the largest pharmaceutical distributor in the United States — disclosed a cybersecurity incident in a Form 8-K filed with the SEC. The company's own words are worth reading precisely: it is "in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data," and has not determined the incident to be material.
McKesson discovered the intrusion on August 25. Data left between August 21 and 25.
The extortion group ShinyHunters claims responsibility, and claims roughly 1TB of data covering 284 million records — pulled, it says, from McKesson's Salesforce and Snowflake environments. It is demanding $55,236,150 and says McKesson has not replied.
Everything after the 8-K is an attacker's claim and should be read as one. But the claimed intrusion path is the part worth your attention, because it is boring, it is repeatable, and it is almost certainly present in your environment right now.
ShinyHunters says it phoned two McKesson employees, impersonated internal support, and walked them into handing over their Okta single sign-on credentials — from which it reached the connected Salesforce and Snowflake instances.
Note what is absent. No zero-day. No malware on an endpoint. No lateral movement through a flat network. No privilege escalation chain. The access was granted, by people, through the front door, in a conversation.
This is not improvisation. Microsoft published a detailed writeup of exactly this playbook on July 13, 2026, in Defending SaaS-based applications against ShinyHunters OAuth abuse. The pattern has two halves:
Microsoft's characterisation of the resulting activity is the sentence to keep: it "appeared indistinguishable from legitimate Salesforce usage." Trusted identity, approved app, authorised integration. There is nothing anomalous to detect, because nothing anomalous happened.
Because the fastest-growing category of "third-party application holding a standing grant into your SaaS" is AI, and nobody is counting them.
Grip Security's analysis of 23,000 SaaS environments, covered by SecurityWeek in March, found that 100% of the organisations studied were running AI-enabled SaaS, averaging 140 AI-enabled SaaS environments each, against a 490% year-over-year rise in public SaaS attacks. Those AI features arrived as product updates to tools already in the estate. Almost none of them went through a fresh security review, because from a procurement standpoint nothing was purchased.
Now add the identity layer. Akamai's State of the Internet: Enterprise AI Usage Risk Report 2026, published August 5, put telemetry behind the thing everyone suspected: 47.11% of enterprise AI conversations run through personal rather than corporate-managed identities, and 16.31% of AI browser and IDE extensions carry known CVEs. Roughly half of the AI activity on corporate devices is happening in accounts your IdP cannot see, cannot log, and — critically for this story — cannot revoke.
Put the two together and the shape of the exposure is clear. An employee signs into a consumer AI assistant with a personal account, connects it to their work Google Drive, work calendar, or work Salesforce through an OAuth consent screen, and creates a standing, long-lived, MFA-bypassing grant into corporate data that exists in no inventory you maintain. It is exactly the object ShinyHunters has spent eighteen months harvesting — except this one was created voluntarily, by a helpful person, for a good reason.
We argued three weeks ago that the ban-it strategy had failed on IBM's numbers. This is the mechanism underneath that failure. A ban does not remove a consent grant. It just removes your ability to ask about it.
Obiguard did not stop the McKesson call and does not claim to. What it addresses is the half of this problem that is growing fastest and is currently unmanaged: the AI surface that keeps generating new connected identities outside your control.
Obichat is a governed multi-model chat workspace built on LibreChat, and the argument for it here is narrower than the usual one. It is not that employees will stop wanting an assistant — they will not. It is that one AI front door your administrators own is a smaller and more revocable surface than several hundred personal accounts holding OAuth grants nobody enumerated.
Concretely, the properties that matter against this specific failure mode:
For the other half of the estate — where AI reaches your applications rather than your people — Governance AI carries the same logic into the machine layer. Allow-lists bind each credential to specific model IDs, tools, external domains and invoking identities, which is a positive-permission answer to the standing-grant problem rather than a monitoring answer. The audit ledger keeps an immutable per-call record of prompt, response, tool calls, model and initiating identity. That is the same argument we made about agents acting outside their authorisation and about moving the inference boundary somewhere you administer: the useful control is not the one that predicts the compromise, it is the one that bounds and records what the compromised thing could reach.
Read the McKesson 8-K again. "Third-party applications." Not our systems. Not our network. The company is describing an incident that happened in the space between its vendors, its identities and its data — the space that appears on no architecture diagram and belongs to no team.
The 284 million figure will move. ShinyHunters itself concedes it is a raw record count and that the number of distinct people is unknown; deduplication will bring it down, and history says it will still be very large. But the number is not the lesson.
The lesson is that the most consequential healthcare data event of the month required no vulnerability at all. It required a phone call to a person who wanted to be helpful, and a set of standing permissions that had been granted long ago and never reviewed. Your AI estate is currently manufacturing more of the second thing every week, and most of it is being created with credentials you do not manage.
Explore Obichat or talk to us about which AI applications currently hold a live grant into your SaaS — and who would have to be called to revoke them.
Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.
See how it works →