Microsoft Threat Intelligence is warning of a large scale, multistage phishing campaign that disproportionately targeted the health care sector, sending “code of conduct” themed emails to lure users into credential theft and token compromise. According to Microsoft, health care was the most targeted industry in the campaign, which reached more than 35,000 users across over 13,000 organizations, primarily in the U.S. The attack leveraged adversary in the middle techniques to intercept authentication tokens in real time, enabling attackers to bypass multifactor authentication and gain direct account access.  

“Phishing attacks are the most frequent and most effective methods of attacking the health care sector,” said Scott Gee, AHA deputy national director for cybersecurity and risk. “Training and vigilance are the keys to preventing these attacks. That training should also emphasize the ‘why.’ It’s not just about loss of protected health information, but the potential for shutting down critical systems and impacting patient care and safety.” 

Microsoft said the campaign underscores the sector’s continued attractiveness to cybercriminals due to sensitive patient data and operational pressures, and it urged hospitals and health systems to strengthen phishing resistant MFA, email security controls and workforce awareness to reduce risk.  

For more information on this or other cyber and risk issues, contact Gee at sgee@aha.org or John Riggi, AHA national advisor for cybersecurity and risk, at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity

Headline
The Cybersecurity and Infrastructure Security Agency has launched a new initiative for critical infrastructure to defend against cyberattacks through proactive…
Headline
John Riggi, AHA national advisor for cybersecurity and risk, will moderate a webinar May 5 at 1 p.m. ET that will explore how bad actors are leveraging…
Headline
The AHA and Joint Commission May 4 announced the launch of the Cyber Resilience Readiness program, an initiative to help hospitals and health systems assess…
Headline
The Cybersecurity and Infrastructure Security Agency, National Security Agency and international partners have released guidance on adopting agentic artificial…
Headline
A joint advisory released April 23 from U.S. and international cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency, FBI,…
Headline
FBI Co-deputy Director Andrew Bailey discussed a rise in cyber and physical threats impacting health care. He discussed health care as the top critical…