As cited
Citation snapshot as of .
threat intel
Health Care Social Engineering Campaign
In early April 2024, ReliaQuest identified a coordinated campaign targeting health care organizations' Revenue Cycle Management departments. Attackers used social engineering to manipulate help desk staff into resetting MFA credentials after bypassing location-based access controls with stolen credentials, then accessed banking systems likely to alter routing information. The campaign involved extensive reconnaissance, multi-stage authentication attacks, and infrastructure pivoting across multiple hosting providers.
Why it matters: Health care organizations and their finance teams face immediate risk from targeted social engineering attacks against help desk staff; practitioners should implement stricter MFA reset verification procedures, device-based conditional access, and escalation controls for finance-related identity requests to prevent banking fraud.
- Source published
- First seen by Cybersecurity Tracker