For about half a year, corporate email accounts belonging to more than 100 employees of the National Health System (NHS) in the United Kingdomwere used to send phishing emails, which aimed, among other things, at stealing Microsoft credentials.
It appears that cybercriminals managed to hack into the email of NHS employees and began using them for phishing attacks. This began last October and continued until at least April 2022.
See also: Phishing emails target Twitter users with “verified” accounts

According to researchers at email security firm INKY , the attackers sent more than a thousand phishing emails from NHS employee email accounts. The compromised accounts belonged to employees in England and Scotland.
The researchers tracked phishing emails originating from two NHS IP addresses and delivered from the email of 139 NHS employees. INKY detected 1,157 phishing emails from the two addresses. However, the true scope of the attack is unknown, as the analysts only traced the emails to their own customers.
“The NHS confirmed that the two addresses were relays within the [NHSMail] mail system used for a large number of accounts,” the INKY researchers said in report .
In most cases, the phishing emails sent fake notifications for delivery of new documents that linked to phishing pages, which asked victims to enter Microsoft credentials.
See also: F5: Critical BIG-IP RCE bug allows device takeover
The attackers tried to make the emails very convincing, including adding the NHS confidentiality disclaimer at the bottom of the message.
INKY researchers also found other phishing emails that impersonated brands like Adobe and Microsoft by adding the companies' logos.
In other cases, attackers would tell victims about a supposed donation, but the victim would have to provide personal information (e.g., full name and address, mobile phone number) to receive the funds. The reply to the message returned a response from someone using the name Shyann Huels and stating that he was “Mr. Jeff Bezos’ special secretary for international affairs.”

The same name and message have appeared in scams since early April.
INKY researchers have alerted the NHS to phishing emails being sent from compromised accounts . The British agency took immediate action and addressed the threat after mid-April, although some people are still receiving malicious messages.
See also: Cisco: Fixes NFVIS bugs that gave root access
Roger Kay, INKY's Vice President of Security Strategy, stresses that these phishing campaigns are not the result of a breach of the NHS email server "but of accounts that have likely been compromised individually."
This phishing campaign shows once again how important it is to be careful with the emails we receive, especially when they contain a link or attached file.
Source: www.bleepingcomputer.com
