The week of 31 August to 6 September 2026 was defined by identity and access failures, not exploited software. McKesson confirmed attackers reached patient data after a voice-phishing call compromised an Okta single sign-on session. Berlin’s state government confirmed data theft from a network segment that had no multi-factor authentication on its VPN. A Thomson Reuters court-management vendor breach exposed personal data across a dozen US state judiciaries plus Ontario. French regulator CNIL fined a hospital 500,000 euros for letting one compromised credential reach every patient’s record. And a dark-web listing offering more than 153 million driver’s license images drew an FBI investigation into an identity-verification vendor’s infrastructure. In four of these five incidents, the attacker’s path in was a missing, bypassed, or overly broad access control rather than a new exploit.
1. McKesson confirms breach after ShinyHunters vishing attack reaches Okta SSO
Overview: McKesson Corporation, the healthcare distribution and technology giant, confirmed on 31 August 2026 that attackers exfiltrated data from a subset of customers in its Oncology and Multispecialty and Medical-Surgical business units, after the extortion group ShinyHunters set a 1 September deadline for ransom negotiations.
Impact: ShinyHunters claims theft of 284 million patient and customer records, including personally identifiable information, protected health information, medical records, prescriptions, and billing data; McKesson has not confirmed this total, and it should be treated as an attacker claim rather than a verified count. ShinyHunters reportedly demanded roughly 55 million dollars.
Details: Reporting attributes initial access to a voice-phishing call targeting McKesson’s Okta single sign-on, which gave attackers a path into third-party Salesforce and Snowflake environments where an estimated one terabyte of data moved out between 21 and 25 August 2026. McKesson has not published its own account of the intrusion technique, so this mechanism should be read as reported rather than company-confirmed. It maps to the identity-abuse pattern MITRE ATT&CK tracks as Valid Accounts (T1078): the attacker did not break software, they walked in on a session token.
Remediation guidance: Require phishing-resistant multi-factor authentication, such as FIDO2 hardware keys, on every SSO login that reaches third-party SaaS data stores. Restrict and monitor which SaaS platforms an SSO session can reach without a fresh authentication challenge. Rehearse the vishing pretext specifically with helpdesk and identity teams, since that is the step that failed here.
CISO takeaway: A single Okta session reaching Salesforce and Snowflake meant one successful phone call put 284 million claimed records at risk. Validate what an attacker can actually reach after a social-engineered SSO session, not just what your access policy says they should reach.
2. Berlin state government confirms Rhysida ransomware data theft after week-long detection gap
Overview: Berlin’s Senate Department for Mobility, Transport, Climate Protection and the Environment confirmed on 31 August 2026 that the Rhysida ransomware group stole government data, after compromise occurred between 7 and 12 August and the affected systems were not disconnected from the state network until 14 August.
Impact: Rhysida claims to have exfiltrated 5.79 terabytes across roughly 1.44 million files, including credentials, infrastructure assessments, and government records, and is demanding 30 bitcoin within four days of its claim; Berlin’s government has confirmed that data theft occurred and that personal data exposure cannot be ruled out, but has not verified Rhysida’s itemized inventory. Mayor Kai Wegner has stated the city will not pay. Election data and election infrastructure were not compromised.
Details: Public reporting describes VPN access into the department’s network without multi-factor authentication as the entry point, consistent with Rhysida’s documented pattern of abusing external remote access. That maps to MITRE ATT&CK’s External Remote Services (T1133). The gap between the 7 to 12 August compromise window and the 14 August network isolation, seven days, is the detail that turned a contained intrusion into a confirmed data theft.
Remediation guidance: Enforce multi-factor authentication on every VPN and remote-access path into government or enterprise networks without exception. Cut mean time to isolate a confirmed compromise from days to hours by pre-authorizing network segmentation runbooks. Test remote-access paths for MFA bypass and session-hijack conditions before an attacker finds them first.
CISO takeaway: Seven days between compromise and isolation is roughly the same order of magnitude as the three days it typically takes attackers to weaponize a newly exploited CVE. A continuous testing cadence that checks remote-access authentication weekly rather than annually would have caught the missing MFA long before Rhysida did.
3. Thomson Reuters court-management vendor breach exposes data across a dozen US states
Overview: Thomson Reuters confirmed, in reporting published 2 to 3 September 2026, that an unauthorized party accessed files belonging to C-Track, the case-management platform Thomson Reuters’ court software business sells to judiciaries, exposing personal data tied to appellate courts in at least 12 US states plus the US Virgin Islands and Ontario, Canada.
Impact: Exposed data includes names, Social Security numbers, driver’s license numbers, dates of birth, medical information, and health insurance information, along with confidential, redacted, or sealed court documents; Thomson Reuters has not published a total individual count, and Ontario’s chief justices stated it remains unclear exactly how many people were affected. Unauthorized access occurred from March through June 2026, was discovered by Thomson Reuters on 30 June, and some affected court officials were not notified until 23 July.
Details: Thomson Reuters stated the breach occurred within its own environment and was not caused by the networks, systems, or data security of the affected courts, which is a textbook example of MITRE ATT&CK’s Trusted Relationship (T1199): the courts’ own defenses were irrelevant because the compromise happened one hop upstream, inside a shared vendor platform.
Remediation guidance: Inventory every third-party platform with write or read access to sensitive case or customer data, not just direct network connections. Require breach notification timelines from vendors that match or beat your own regulatory obligations, since a nearly month-long gap between a vendor’s internal discovery and court notification compounds the damage. Test whether vendor-supplied software itself is exposed or exploitable, rather than assuming vendor security is the vendor’s problem alone.
CISO takeaway: A dozen state court systems had their own security postures rendered irrelevant by one vendor’s compromise. Third-party and supply chain exposure is now a bigger determinant of your breach risk than your own perimeter.
4. French regulator fines hospital 500,000 euros after one credential exposed every patient’s record
Overview: France’s data protection authority CNIL announced on 3 September 2026 a 500,000 euro fine against Hôpital Privé de la Loire after finding that a health data breach let one compromised credential access the records of all of the hospital’s patients, because the system did not restrict access by care team.
Impact: The breach and subsequent CNIL investigation covered 524,867 patients and 202,246 trusted third parties, such as independent physicians, for a combined 727,113 individuals; CNIL separately found the hospital failed to notify the 202,246 third parties at all, a distinct breach-notification violation.
Details: CNIL’s investigation found the hospital lacked VPN and multi-factor authentication requirements for external users such as independent physicians, had no access segmentation by care team so one account could reach every patient’s data, and had no real-time monitoring capable of detecting the several days of undetected data extraction. This is a regulator-documented case of MITRE ATT&CK’s Valid Accounts (T1078) succeeding purely because of absent segmentation controls, not a sophisticated exploit.
Remediation guidance: Segment access to patient or customer records by role and care team so that no single external credential reaches the full dataset. Require VPN access plus multi-factor authentication for every external clinician or partner login. Deploy monitoring that flags bulk data access in the short term, not after several days of quiet extraction.
CISO takeaway: A regulator, not an attacker, is now willing to put a price on the gap between having an access control policy and having one that actually holds under test. Validating that access segmentation works in practice is materially cheaper than a 500,000 euro fine plus notification costs for 727,113 people.
5. Dark-web listing offering 153 million driver’s licenses draws FBI probe into identity-verification vendor
Overview: A dark-web marketplace called Nexus launched on a Russian-language cybercrime forum on 31 August 2026 offering more than 153 million US and Canadian driver’s license images for sale, prompting an FBI investigation opened by the New Orleans field office on 1 September, the day the listing was first reported.
Impact: The listing claims more than 153 million driver’s licenses, over 10 million identification cards, more than 3 million travel documents, and more than 579,000 medical cards; identity-verification provider IDScan.net has stated it is investigating the matter but has not confirmed the breach, so this scale should be read as a dark-web seller’s claim under active law enforcement review, not a confirmed company disclosure. The database reportedly grew by roughly 400,000 records within 24 hours of the listing going live, and the Nexus service itself was shut down on 2 September.
Details: Reporting has connected the data’s origin, based on timestamp correlation, to identity-verification services used by companies including a major car rental firm and cannabis dispensaries, but the exact intrusion vector into IDScan.net’s infrastructure has not been disclosed by the company or confirmed by investigators as of this report. Where a disclosure stops short of confirming a mechanism, that gap is itself worth naming rather than papering over.
Remediation guidance: Any organization using a third-party identity-verification or age-verification service should confirm in writing what raw document images that vendor retains and for how long. Demand evidence of independent penetration testing from identity-verification vendors specifically, given how concentrated and high-value their data stores are. Treat an active FBI investigation into a vendor as a trigger to review your own exposure through that vendor today, not after final attribution.
CISO takeaway: A vendor holding scanned government identification for verification purposes is a single point of failure for identity theft at a scale most breaches never reach. Third-party risk review needs to reach the vendors your business quietly depends on for identity and access, not only the vendors with network connections to your environment.
How FireCompass helps
Four of this week’s five incidents trace back to identity and access paths that a policy document said were controlled and that testing would have shown were not: an SSO session with too much reach, a VPN without MFA, a vendor platform nobody validated, and an access model with no segmentation. FireCompass runs AI-native web application and API pentesting continuously, validating whether the access paths your policies describe actually hold under an adversarial test, with exploit-validated findings at a false positive rate under 2 percent, against the 40 to 70 percent typical of scanners. Annual penetration tests, the industry default, cover roughly 20 percent of surface attackers actually probe, leaving the gap that let a single voice-phishing call and a single missing MFA control produce two of this week’s five headlines.
Frequently asked questions
What was the biggest cyberattack this week (31 Aug to 6 Sep 2026)?
McKesson’s confirmed breach was the highest-profile incident, with the extortion group ShinyHunters claiming theft of 284 million patient and customer records after a voice-phishing attack reached the company’s Okta single sign-on on 31 August 2026.
Was McKesson’s breach confirmed or just claimed?
McKesson itself confirmed on 31 August 2026 that attackers exfiltrated data from its Oncology and Multispecialty and Medical-Surgical business units; the 284 million record count is ShinyHunters’ claim and has not been independently confirmed by McKesson.
What happened in the Berlin ransomware attack?
Rhysida ransomware compromised Berlin state government systems between 7 and 12 August 2026, and the affected department was not disconnected from the state network until 14 August, a seven-day gap; Berlin’s government confirmed data theft occurred but has not verified Rhysida’s claimed 5.79 terabyte, 1.44 million file inventory.
How many people were affected by the Thomson Reuters C-Track breach?
Thomson Reuters has not published a total figure; the exposure covers appellate court systems in at least 12 US states plus the US Virgin Islands and Ontario, Canada, with unauthorized access occurring from March through June 2026 and discovered on 30 June.
Why was Hôpital Privé de la Loire fined 500,000 euros?
France’s CNIL fined the hospital on 3 September 2026 after finding that a lack of access segmentation let one compromised credential reach the records of all 524,867 patients, and that the hospital failed to notify 202,246 affected third parties at all.
What is the pattern connecting this week’s incidents?
Four of the five incidents, McKesson, Berlin, the CNIL-fined hospital, and the Thomson Reuters vendor breach, trace back to an identity or access control gap, a bypassed or absent MFA requirement, an oversized SSO session, or an unvalidated vendor platform, rather than a newly exploited software vulnerability.
