In the future, that Zoom-based video of your boss may not be real. But strategies such as adopting shared secrets and multi-person authorization could thwart scammers.
This week's breach roundup is led by a phishing attack on Orlando Family Physicians earlier this year, which led to the compromise of data tied to nearly 450,000 patients. The incident is among the largest reported in the health care sector this year, serving as a reminder to review all endpoints and access controls.
A phishing-related data compromise impacting more than 200,000 patients tied to ClearBalance lead's this week's health care data breach roundup, which also includes breaches at NYC Health + Hospitals and the University of Maryland, Baltimore, among others.
Many of the spear-phishing emails show the threat actor did their homework, with procurement jargon and references to real executives and ongoing projects.
The scheme is yet another recent example of phishing campaigns leveraging communication mediums outside of email to catch prospective victims off-guard. And it works in part because website operators that use chat features are not always diligently scanning uploaded files for malware.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.