McKesson tells the SEC it was hit through third-party applications
September 8, 2026. From issue 5 of The Compliance Brief, 2 stories for companies buying a SOC 2 audit.
Issue 5 of The Compliance Brief was published on September 8, 2026. 2 of its 5 stories bear on SOC 2 audits, auditors and vendor reviews, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for companies buying a SOC 2 audit.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: Help Net Security
McKesson disclosed a cybersecurity incident in which attackers got into third-party applications and stole data, with the intrusion detected on August 25, 2026. The SEC filing says the investigation is in its early stages and the company has not determined the incident is material or likely to be material.
Our take, in short
Read that filing from the other side of the table. You are the third-party application in somebody's stack, and when a customer of yours writes their own version of this disclosure, your name goes in it.
Read the full take on traztech.ca
An ID verification vendor appears to be the source of 153 million licence scans
Source: Krebs on Security
A new dark web identity theft service is selling digital scans of more than 153 million driver's licences belonging to people in the United States and Canada. Interviews with affected individuals suggest the images were siphoned from a widely used identity verification company based in Louisiana.
Our take, in short
Anyone doing KYC has an identity verification vendor, and most founders I talk to have never asked that vendor how long it keeps the document images after the check comes back clean. Retention is the control that would have made this a much smaller story, and it costs nothing to shorten.
Read the full take on traztech.ca
Related on GetSOC2
- SOC 2 certification in Canada explained
- SOC 2 or ISO 27001 in Canada
- What if we say no to a SOC 2 request?
- Why your customer is asking for SOC 2
Also in issue 5
Outside SOC 2 audits, auditors and vendor reviews, but in the same email:
- Thomson Reuters court software breached in March, disclosed in September
- FTC takes $4.85M from Nuvei over who it let onto its rails
- AI coding agents are pulling packages nobody registered
Older: issue 4 All issues on GetSOC2 Newer: issue 6
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.