Sep 20, 2026

News

No Malware, No Phishing Email: How a Phone Call to the Help Desk Breached McKesson and Baxter

Every healthcare data breach we've covered so far involved a phishing email, a malicious link, or malware. The wave of attacks now hitting McKesson, Baxter International, Medtronic, and a growing list of healthcare organizations required none of that. It required a phone call — someone confident enough to talk an IT help desk into resetting a password.

What Actually Happened

On August 25, 2026, McKesson — one of the largest pharmaceutical and medical supply distributors in the country — discovered that attackers had spent several days pulling data out of its systems. By the time the company disclosed the incident on August 28, the extortion group ShinyHunters was already claiming to have stolen roughly a terabyte of data, including patient names, addresses, dates of birth, medical record numbers, diagnoses, medications, insurance and Medicaid/Medicare IDs, billing codes, and in some cases Social Security numbers and payment card details (HIPAA Journal, Bleeping Computer). The group demanded more than $55 million not to leak it.

McKesson isn't an isolated case. Baxter International, another major healthcare supplier, had 7.1 million records exposed after its own ransom deadline passed without payment. Medtronic, iRhythm, DentaQuest, One Medical, AdaptHealth, and Hims & Hers have all been linked to the same campaign (Health-ISAC, healthsystemcio.com). None of these organizations were broken into with malware or a phishing email an alert employee could have spotted sitting in an inbox.

Here's how the group actually gets in: they research an employee, spoof a phone number to look internal, and call posing as IT support or legal. They talk the target through what looks like a routine password reset or MFA re-enrollment — in some cases relaying a real login page in real time so they can capture the one-time code as it's read aloud. Once inside, they use that one set of credentials to log into the company's identity system (Okta, Microsoft Entra), see every application that employee can reach, and start pulling data from cloud platforms like Microsoft 365, Salesforce, Dropbox, and Google Drive — often before anyone notices (Health-ISAC).

Why This Matters

We've already covered phishing emails and AiTM attacks that hijack a login session in real time. This is a different animal, and in some ways more unsettling: there's no link to click and no attachment to scan. The entire attack happens over a voice call, and it isn't aimed at the average employee — it's aimed specifically at whoever has the power to reset someone else's access: a help desk technician, an IT administrator, a practice manager.

That's a deliberate choice. Help desks exist to be fast and helpful. Almost none were built to treat "a stressed-sounding person who needs their MFA reset right now" as a potential threat.

What This Means If You're a South Florida Practice

Your practice almost certainly doesn't run its own internal help desk — but you have the equivalent. It might be an office manager who calls your EHR vendor's support line to reset a login. It might be your outsourced IT provider, who can reset your practice's Microsoft 365 or EHR credentials with a phone call. Either one is a plausible entry point for exactly this kind of attack, and neither has anything to do with how well your staff can spot a suspicious email.

The uncomfortable question worth sitting with this month: if someone called your IT provider claiming to be you, in a hurry, needing a password or MFA reset right now — what would actually stop them? If the honest answer is "probably nothing, they'd just do it," that's a gap worth closing before it gets tested for real.

Practical Takeaways

  • Ask your IT provider (and your EHR or practice-management vendor) what their identity verification process is before they make a password or MFA change over the phone — and confirm that calling back a number already on file, not one the caller provides, is part of it.

  • Put it in writing: no password reset or MFA re-enrollment gets completed on the first call, regardless of how urgent it sounds.

  • Require a second person's sign-off — a manager or practice owner — before any privileged account (admin logins, EHR system access) is reset.

  • Move administrator and other high-privilege accounts to phishing-resistant MFA (security keys or passkeys), which can't be captured over a phone call the way a spoken one-time code can.

  • Add vishing to your staff's security awareness training alongside email phishing — whoever fields IT calls for your practice needs to know this tactic exists.

These attacks don't succeed because someone was careless. They succeed because they target the one process almost every organization — including plenty of enterprise IT departments — still assumes is safe by default: the phone call to get help.

Get expert clarity

Asked questions:

What services do you offer?

We provide IT consulting, cloud setup, security, and automation solutions.

Do you provide ongoing support?

Yes, we offer continuous monitoring, updates, and technical support.

What is your typical project timeline?

Most projects are completed within 2–3 weeks based on scope.

Can you customize solutions for our business?

Yes, all solutions are tailored to your goals and system requirements.

How do you ensure data security?

We use advanced security protocols, monitoring, and compliance practices.

Get expert clarity

Asked questions:

What services do you offer?

We provide IT consulting, cloud setup, security, and automation solutions.

Do you provide ongoing support?

Yes, we offer continuous monitoring, updates, and technical support.

What is your typical project timeline?

Most projects are completed within 2–3 weeks based on scope.

Can you customize solutions for our business?

Yes, all solutions are tailored to your goals and system requirements.

How do you ensure data security?

We use advanced security protocols, monitoring, and compliance practices.

Start your journey

Build smarter systems and grow with confidence

Start your journey

Build smarter systems and grow with confidence