Microsoft warns of phishing emails in healthcare

Advertisement

Healthcare was the most targeted industry in a recent phishing campaign detected by Microsoft, the company said.

From April 14-16, the phishing emails targeted over 35,000 users across more than 13,000 organizations in 26 countries, the majority (92%) in the U.S., according to a May 4 blog post. Healthcare and life sciences accounted for 19% of the hacking attempts.

The emails used display names including “Internal Regulatory COC,” “Team Conduct Report” and “Workforce Communications,” and subject lines such as “Internal case log issued under conduct policy” and “Reminder: employer opened a non-compliance case log.”

Microsoft’s recommendations include investing in user awareness training and phishing simulations, checking for and removing emails with URLs or subject fields similar to known cyber threats, and enabling passwordless authentication where possible.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement