ISO27K

McKesson breach came through third-party applications

September 1, 2026. From issue 4 of The Compliance Brief, one story for teams running an ISO 27001 or ISO 42001 management system.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Issue 4 of The Compliance Brief was published on September 1, 2026. One of its 5 stories bears on ISO 27001, ISO 42001 and supplier risk, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: BleepingComputer

McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The ShinyHunters extortion group claims it took 284 million patient records, a figure that comes from the attackers and not from McKesson.

Our take, in short

Ignore the record count, which is unverified and usually inflated, and look at the entry point. Connected SaaS applications with broad OAuth scopes keep being the way into large healthcare and finance environments, which is exactly the risk your prospect is thinking about when they classify you as a critical vendor.

Read the full take on traztech.ca

Also in issue 4

Outside ISO 27001, ISO 42001 and supplier risk, but in the same email:

Older: issue 2 All issues on ISO27K Newer: issue 5