Skip to main content

Social engineering tactics used against medical staff

Graphic on social engineering tactics used against medical staff, co-branded by Paubox and Health-ISAC.

According to the 2024 HC3 presentation titled Social Engineering Attacks Targeting the HPH Sector, “In 2023, an average of 1.99 healthcare data breaches of 500 or more records were reported each day, and an average of 364,571 healthcare records were breached every day.” This statistic shows the vulnerability of healthcare systems to social engineering attacks.

The scale of email-related breaches specifically has reached crisis levels. The Paubox Healthcare Email Security Report reveals that “180 healthcare organizations fell victim to email-related breaches in 2024” alone, highlighting how cybercriminals are increasingly targeting the communication channels that healthcare workers rely on daily.

Health-ISAC Pulled quote

A campaign by the Zeon threat group demonstrated this type of attack: the group targeted 35,000 healthcare addresses by impersonating “legitimate healthcare organizations delivering software solutions focused on patient data.” As Health-ISAC Chief Security Officer Errol Weiss explained, this represents “social engineering at its finest; psychological warfare” because “there are no evil links, no evil attachments; it’s just all text, and they’re able to craft something that scares people and it makes them do things they wouldn’t ordinarily do.” The attackers contacted employees directly, walking them through installations of “legitimate remote access tools” like Zoho and AnyDesk, after which “the bad guys have access to your computer.” This campaign proved so effective that it informed the threat group’s continued targeting of the healthcare sector, demonstrating how vendor impersonation exploits the trust healthcare workers place in legitimate software providers.

Read the full PAUBOX article. Click Here