The Health Information Sharing and Analysis Center (H-ISAC) Sept. 19 alerted the health sector to an emerging threat that targets senior executives through phishing emails that contain malicious QR codes, also known as quishing. AHA recently received reports from the field that executive leadership at academic medical centers and other entities were receiving highly targeted and convincing quishing emails and worked with the field and H-ISAC to better understand the nature and scope of the threat.
 
“As use of QR codes to access websites and other resources increases, it is not surprising that cyber adversaries are evolving their techniques to include QR codes as the attack vector to compromise user credentials, evade multifactor authentication and deliver malware into organizations,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “If a scanned QR redirects to an unknown website, discontinue use immediately. Do not provide your username and password in response to a QR code unless specifically authorized by your organization.”

Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international agencies July 29 released joint guidance outlining minimum elements for a…
Headline
John Riggi, AHA national advisor for cybersecurity and risk, shares insights from a conversation with two FBI leaders about the surge of cyberattacks on the U.…
AHA Cyber Intel
Earlier this year, the FBI launched a two-month national campaign, Operation Winter SHIELD (Securing Homeland Infrastructure by Enhancing Layered Defense),…
Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international partners July 22 released an updated advisory on Iranian-affiliated cyber…
Headline
Edward You, former FBI Supervisory Special Agent and founder of EHY Consulting, explains why healthcare organizations must look beyond artificial intelligence…
Headline
The Cybersecurity and Infrastructure Security Agency has issued an alert warning of four Microsoft SharePoint vulnerabilities being exploited by cyber threat…