The Health Information Sharing and Analysis Center (H-ISAC) Sept. 19 alerted the health sector to an emerging threat that targets senior executives through phishing emails that contain malicious QR codes, also known as quishing. AHA recently received reports from the field that executive leadership at academic medical centers and other entities were receiving highly targeted and convincing quishing emails and worked with the field and H-ISAC to better understand the nature and scope of the threat.
 
“As use of QR codes to access websites and other resources increases, it is not surprising that cyber adversaries are evolving their techniques to include QR codes as the attack vector to compromise user credentials, evade multifactor authentication and deliver malware into organizations,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “If a scanned QR redirects to an unknown website, discontinue use immediately. Do not provide your username and password in response to a QR code unless specifically authorized by your organization.”

Headline
Leaders of the Five Eyes cybersecurity agencies, consisting of Australia, Canada, New Zealand, the United Kingdom and the United States, released a joint…
Headline
President Trump issued a memorandum June 12 on cybersecurity governance for national security systems used by federal agencies. The memo re-establishes and…
Headline
The Cybersecurity and Infrastructure Security Agency and other federal agencies released a fact sheet June 2 on malicious cyber activity targeting U.S.-based…
Headline
The FBI and international agencies have released an alert on Chinese military intelligence services using professional networking sites and online job…
Headline
The White House issued an executive order June 2 on cybersecurity efforts regarding artificial intelligence. The order instructs federal…
Headline
The Health Sector Coordinating Council’s Cybersecurity Working Group has released a guide to help healthcare organizations establish cyber governance…