CRBC News
Security

Healthcare Sector Faces Surge in Vishing and Phishing Attacks, Researchers Warn

Healthcare Sector Faces Surge in Vishing and Phishing Attacks, Researchers Warn
Two Scientists analyzing chemical data to researchers medicine for healthcare industry at laboratory , Scientists analyzing DNA for researchers drug

The healthcare and pharmaceutical sectors are seeing a rise in social-engineering attacks—particularly vishing and credential-stealing phishing. Health-ISAC says ShinyHunters is using medical-themed impersonation domains and aggressive phone tactics, while Unit 42 linked [my-passkeys[.]com] to The Com. ReliaQuest confirmed sustained phishing/vishing infrastructure with registrations into late September 2026. Recent breaches affecting Clover Health, AdaptHealth (4.1M+ patients) and Hims & Hers highlight the threat.

Cybersecurity researchers and threat intelligence teams warn that the healthcare and pharmaceutical industries are being targeted by an escalating wave of social-engineering attacks—especially voice-phishing (vishing) and credential-stealing phishing campaigns.

Health-ISAC recently reported that the actor known as ShinyHunters is using medical-themed impersonation domains and aggressive phone-based tactics to trick healthcare employees into revealing login credentials or performing password and MFA resets. Errol Weiss, chief security officer at Health-ISAC, told Cybersecurity Dive that more than a dozen member organizations have been targeted in recent months.

"They're pretty belligerent when it comes to getting somebody on the phone and convincing them they need to click on a password reset or an MFA reset," Weiss said.

Unit 42, the threat research arm of Palo Alto Networks, identified a domain—[my-passkeys[.]com]—that appears linked to an underground cybercrime network known as The Com. Unit 42 researchers say the domain matches known attacker fingerprints and was first observed in mid-September; at least two organizations in healthcare and pharmaceuticals may be at risk from associated vishing or phishing activity.

ReliaQuest corroborated this trend, reporting a sustained cluster of phishing and vishing infrastructure targeting healthcare and pharmaceutical organizations, with domain registrations continuing into late September 2026.

Recent Notable Incidents

The alert follows several high-profile social-engineering incidents affecting the sector this year:

  • Clover Health — In a mid-July SEC filing, the company said attackers used social engineering to access three non-managerial employee accounts.
  • AdaptHealth — In July, the provider of CPAP machines and medical devices disclosed a social-engineering breach that exposed data for more than 4.1 million patients after threat actors accessed cloud-based business applications.
  • Hims & Hers — In April, the telehealth company reported a social-engineering compromise of a third-party customer service platform that exposed customer names and email addresses.

What Organizations Should Watch For

Researchers emphasize the attackers' use of authentic-looking medical-themed domains and high-pressure phone tactics designed to prompt immediate action (password or MFA resets). Healthcare organizations should prioritize staff training on vishing and phishing indicators, enforce robust multi-factor authentication procedures that resist resets over unsolicited calls, monitor domain registrations for lookalike domains, and maintain incident response readiness.

Help us improve.

Related Articles

Trending