Hospitals warn staff: That Microsoft Teams ‘IT’ call might be a scam

Advertisement

Omaha, Neb.-based Nebraska Medicine is warning employees about a wave of Microsoft Teams voice calls impersonating IT support staff, becoming the latest health system to sound the alarm on a scam that has hit hospitals across the country over the past year.

The health system’s information security team said Aug. 21 that bad actors are using Teams voice calls to impersonate IT support in an attempt to steal credentials, gain system access or trick employees into approving multifactor authentication requests, installing remote access software or granting access to company systems.

The callers may claim a computer has been compromised, that suspicious activity has been detected on an account, that a security incident requires immediate action, or that a password needs to be reset urgently, Nebraska Medicine said.

“Legitimate IT personnel will never ask for your password, MFA code, or request remote access without following established support procedures,” the health system said in its alert. It advised employees to verify a caller’s identity through a known contact method, never approve MFA prompts they did not initiate, and end the call and contact the help desk directly if anything feels off.

The warning echoes one issued last year at Nashville, Tenn.-based Vanderbilt Health, where staffers received calls that initially appeared to come from a supervisor before the caller ID changed mid-conversation.

“Scammers may push for immediate action such as installing software, accessing files, or sending payments, claiming it’s a time-sensitive issue or emergency,” Vanderbilt said in a June 2025 statement.

The tactic has also drawn attention from federal law enforcement. The FBI issued an alert in May on the Silent Ransom Group, also known as Luna Moth, Chatty Spider and UNC3753, which has impersonated IT support staff through phone calls and phishing emails to target healthcare and other industries since at least 2022.

Separately, cybersecurity firm Sophos has tracked a nearly identical Microsoft Teams impersonation campaign, dubbed STAC4749, that hit dozens of organizations — mostly in the U.S. and Canada, and concentrated in the services, manufacturing, energy, and construction sectors — between February and June. At least three of those intrusions ended in Chaos ransomware deployments, with one moving from the initial phone call to encrypted files in less than 17 hours, Sophos found. No healthcare organization has been named among the campaign’s victims, but the case illustrates how far the same style of attack can escalate once an employee is convinced to hand over access.

For hospital IT and security leaders, the recurrence of these warnings across health systems suggests the help desk impersonation script isn’t going away. The consistent advice from the health systems that have been targeted: Treat unsolicited IT support calls with the same suspicion as phishing emails, verify identity through a separate known channel before taking any action, and never share a password or approve an MFA prompt over the phone.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement