The Health Information Sharing and Analysis Center (H-ISAC) Sept. 19 alerted the health sector to an emerging threat that targets senior executives through phishing emails that contain malicious QR codes, also known as quishing. AHA recently received reports from the field that executive leadership at academic medical centers and other entities were receiving highly targeted and convincing quishing emails and worked with the field and H-ISAC to better understand the nature and scope of the threat.
 
“As use of QR codes to access websites and other resources increases, it is not surprising that cyber adversaries are evolving their techniques to include QR codes as the attack vector to compromise user credentials, evade multifactor authentication and deliver malware into organizations,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “If a scanned QR redirects to an unknown website, discontinue use immediately. Do not provide your username and password in response to a QR code unless specifically authorized by your organization.”

Headline
The FBI and the Cybersecurity and Infrastructure Security Agency have released a fact sheet for critical infrastructure organizations on ways to reduce risk…
Headline
The AHA will host a webinar Sept. 30 at 1 p.m. ET on ways healthcare organizations can build an effective, closed-loop cybersecurity program designed…
Headline
New guidance from the Cybersecurity and Infrastructure Security Agency encourages healthcare organizations to consider internal network and internet facing…
Headline
The National Institute of Standards and Technology and the Cybersecurity and Infrastructure and Security Agency have released guidelines to protect…
Headline
The House Energy and Commerce Subcommittee on Health held a hearing Sept. 15 to discuss more than a dozen legislative proposals regarding Medicare provider…
Headline
The National Security Agency has released a best practices guide on effective cyber hygiene for defending against advanced cyber threats, including those…