Health Care Social Engineering Campaign
ID: ce23411c-f1ea-56cb-a6b7-dee0a076c510
STIX ID: report--ce23411c-f1ea-56cb-a6b7-dee0a076c510
Feed Name: ReliaQuest Blog
ReliaQuest investigated a targeted early-April 2024 campaign against healthcare Revenue Cycle Management staff in which attackers used prior-breached credentials and location-spoofed infrastructure to access VPNs, then social-engineered help-desk personnel to reset MFA and take over accounts; compromised mailboxes and SharePoint were searched for banking information and likely used to alter routing details. The report provides observed IOCs, discusses attacker infrastructure and techniques, and offers defensive recommendations (stricter help-desk verification, device-based auth, conditional access).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
