Why MFA Alone Won’t Save You: The Voice Phishing Attack Every Small Business Needs to Understand

Why MFA Alone Won’t Save You: The Voice Phishing Attack Every Small Business Needs to Understand

Published September 7, 2026

Multi-factor authentication has been the go-to answer to “how do we secure our accounts?” for almost a decade now. Turn on MFA, check the box, move on. Except this week, one of the largest healthcare distributors in the country found out the hard way that MFA is not the finish line — it’s one lock on a door that a confident phone call can still talk its way through.

What Happened

In early September 2026, the extortion group ShinyHunters claimed responsibility for a breach at McKesson, the pharmaceutical and healthcare distribution giant. The attackers didn’t exploit a piece of software. They didn’t need a zero-day.  They called the IT help desk, impersonated an employee, and talked their way into resetting access to the company’s Okta single sign-on system, the same system MFA was supposed to protect. From there, they claim to have exfiltrated roughly 284 million records, including patient and prescription data, and are now demanding a $55 million ransom.

No malware. No exploit code. Just a phone call, a convincing story, and a help desk technician trying to be helpful.

This technique is called vishing voice phishing and it’s not new. What’s changed is how effective it has become against organizations that thought MFA had already solved this problem. It’s part of a broader pattern this season: security researchers have also tracked a record surge in QR-code phishing and a separate campaign where attackers posed as Microsoft Teams IT support to target more than 150 employees at once. The common thread in all of it is the same attackers are increasingly skipping the technical defenses entirely and going straight for the human being who has the authority to override them.

Why This Matters More for Small Businesses Than It Does for McKesson

It’s tempting to read a story like this and think, “That’s an enterprise problem — we don’t have 22,000 employees or an Okta deployment.” But that reasoning gets the risk backwards.

McKesson has a security operations center, an incident response team, and a legal department built for exactly this kind of event. A small business typically has none of that. It has an owner, maybe an office manager who also handles IT questions, and a help desk that’s either outsourced or doesn’t formally exist, which usually means whoever picks up the phone becomes the help desk in that moment. That person has never been trained to recognize a pretext call, has no formal identity-verification process to fall back on, and has every incentive to be accommodating, because being accommodating is the job.

Attackers know this.  Small businesses aren’t targeted less because they’re less vulnerable; they’re targeted differently, at higher volume, because the payoff per business is smaller but the defenses are thinner, and the attack is cheaper to run.

What Actually Stops a Vishing Attack

MFA is still worth having it stops the overwhelming majority of automated credential-stuffing and password-reuse attacks. But it was never designed to stop a human being from being persuaded to bypass it on someone else’s behalf. Closing that gap takes a few specific, low-cost steps:

  1. Create a callback verification rule for any access or password change request. If someone calls claiming to need a password reset, MFA re-enrollment, or an urgent permissions change, the person answering the phone hangs up and calls that employee back on a known, pre-existing number, never a number the caller provides. This single habit defeats almost every vishing pretext because the attacker can’t control a callback to a number they don’t own.
  2. Write down who is allowed to approve access changes and make sure everyone knows it’s not “whoever calls and sounds official.” In a small business, this can be one sentence in an employee handbook: “Only [owner/IT contact] can authorize account or password changes, and only after callback verification.” Vague policies get talked around; specific ones don’t.
  3. Treat MFA re-enrollment as a privileged action, not a routine one. If your systems allow it, require a manager or IT approval step before a lost-device MFA reset goes through, rather than letting a help desk (internal or outsourced) push it through on request alone.
  4. Run a five-minute team conversation, not a mandatory training module. Most small businesses don’t need a formal security awareness platform to get value here they need every employee to have heard one real story like the McKesson breach, and know the callback rule exists. A team that’s heard “someone might call pretending to be IT, here’s what we do” will catch it. A team that’s never heard it won’t.
  5. Know what you’d do in the first hour if it happened anyway. Who gets called first? Which accounts get locked? Who talks to customers if data is involved? Having this written down before an incident even three bullet points is the difference between a controlled response and a panicked one.

The Bottom Line

The lesson from the McKesson breach isn’t “add more security software.” It’s that identity verification is a process problem before it’s a technology problem, and it’s one of the few security gaps a small business can close for free this week without buying anything. MFA raises the cost of an attack. A callback policy raises the cost of the attack that gets around MFA. Small businesses that put both in place are no longer an easy call to make.

This post was prepared as part of ongoing security awareness content. If your business doesn’t have a documented process for verifying identity before granting access or resetting credentials, that’s the single highest-leverage fix you can make this month.

Sources