Microsoft Threat Intelligence is warning of a large scale, multistage phishing campaign that disproportionately targeted the health care sector, sending “code of conduct” themed emails to lure users into credential theft and token compromise. According to Microsoft, health care was the most targeted industry in the campaign, which reached more than 35,000 users across over 13,000 organizations, primarily in the U.S. The attack leveraged adversary in the middle techniques to intercept authentication tokens in real time, enabling attackers to bypass multifactor authentication and gain direct account access.  

“Phishing attacks are the most frequent and most effective methods of attacking the health care sector,” said Scott Gee, AHA deputy national director for cybersecurity and risk. “Training and vigilance are the keys to preventing these attacks. That training should also emphasize the ‘why.’ It’s not just about loss of protected health information, but the potential for shutting down critical systems and impacting patient care and safety.” 

Microsoft said the campaign underscores the sector’s continued attractiveness to cybercriminals due to sensitive patient data and operational pressures, and it urged hospitals and health systems to strengthen phishing resistant MFA, email security controls and workforce awareness to reduce risk.  

For more information on this or other cyber and risk issues, contact Gee at sgee@aha.org or John Riggi, AHA national advisor for cybersecurity and risk, at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity

Headline
The Cybersecurity and Infrastructure Security Agency May 26 announced a revised schedule for its series of virtual town hall meetings for public input on…
Headline
Microsoft announced May 19 that it disrupted operations of Fox Tempest, a threat actor operating as a malware-signing-as-a-service used by cybercriminals to…
Headline
An AHA Cyber & Risk Intel blog by John Riggi, AHA national advisor for cybersecurity and risk, explores what health care leaders need to consider to reduce…
AHA Cyber Intel
Cyberattacks against hospitals, health systems and mission-critical health care third-party providers have surged in recent years. While these attacks often…
Headline
The Cybersecurity and Infrastructure Security Agency has launched a new initiative for critical infrastructure to defend against cyberattacks through proactive…
Headline
John Riggi, AHA national advisor for cybersecurity and risk, will moderate a webinar May 5 at 1 p.m. ET that will explore how bad actors are leveraging…