GetSOC2

McKesson tells the SEC it was hit through third-party applications

September 8, 2026. From issue 5 of The Compliance Brief, 2 stories for companies buying a SOC 2 audit.

Last reviewed 2026-09-08Written by Jacob Masse, TrazTech Inc.

Issue 5 of The Compliance Brief was published on September 8, 2026. 2 of its 5 stories bear on SOC 2 audits, auditors and vendor reviews, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Help Net Security

McKesson disclosed a cybersecurity incident in which attackers got into third-party applications and stole data, with the intrusion detected on August 25, 2026. The SEC filing says the investigation is in its early stages and the company has not determined the incident is material or likely to be material.

Our take, in short

Read that filing from the other side of the table. You are the third-party application in somebody's stack, and when a customer of yours writes their own version of this disclosure, your name goes in it.

Read the full take on traztech.ca

An ID verification vendor appears to be the source of 153 million licence scans

Source: Krebs on Security

A new dark web identity theft service is selling digital scans of more than 153 million driver's licences belonging to people in the United States and Canada. Interviews with affected individuals suggest the images were siphoned from a widely used identity verification company based in Louisiana.

Our take, in short

Anyone doing KYC has an identity verification vendor, and most founders I talk to have never asked that vendor how long it keeps the document images after the check comes back clean. Retention is the control that would have made this a much smaller story, and it costs nothing to shorten.

Read the full take on traztech.ca

Also in issue 5

Outside SOC 2 audits, auditors and vendor reviews, but in the same email:

Older: issue 4 All issues on GetSOC2 Newer: issue 6