The US Department of Health and Human Services (HHS) warns that hackers are using social engineering tactics to target IT help desks in hospitals and the Health and Public Health (HPH) sector in general.

According to experts, these tactics have allowed attackers to gain access to targeted organizations' systems by enrolling their own MFA.
In these attacks, attackers use a local code to trick organizations into calling them and pretending to be employees from the finance department. They then provide verification details for supposedly stolen identities, including corporate ID and social security numbers. Using this sensitive information and claiming that their smartphone is broken, they convince the hospital or organization’s IT help desks to enroll a new device (under the attacker’s control) in MFA.
See also: Hospitals: Cyberattacks and ways to protect yourself
By connecting the device, hackers gain access to corporate resources and can redirect banking transactions as part of compromise (BEC) attacks.
“The hackers specifically targeted login information associated with payer websites, where they then submitted a form to make changes to ACH for payer accounts,” HC3 says [PDF].
Experts warn that once hackers gain access to employee email accounts, they send instructions to payment processors to divert legitimate payments to bank accounts controlled by the attackers .
In the attacks that were detected, the funds were later transferred to accounts abroad.
During the malicious campaign, the hackers also registered a domain with a single-letter variation of the target organization and created an account impersonating the target organization's Chief Financial Officer (CFO).
See also: Lurie Hospital Recovers from Ransomware Attack
Such attacks affect the healthcare industry in other ways as well. In addition to stealing money, social engineering can cause significant data breaches, as hackers can gain access to sensitive patient information.
Furthermore, these attacks can paralyze the IT systems of medical institutions, thus interrupting the provision of medical care and the smooth operation of health services.
Finally, these attacks can undermine public trust in the healthcare sector, as patients may be concerned about the security of their personal data.

Are Scattered Spider hackers behind the attacks?
The tactics described in the Department of Health's alert are similar to those used by the Scattered Spider (also known as UNC3944 and 0ktapus).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This group often impersonates employees to fool the targets' customer service staff.
Hackers have targeted many large organizations, including Microsoft, Binance, CoinBase, T-Mobile, Verizon Wireless, AT&T, Slack, Twitter, Epic Games, Riot Games, and Best Buy.
See also: Romania: 18 hospitals affected by ransomware attack
However, the attacks on hospital IT help desks have not been officially attributed to specific hackers.
To prevent such attacks in the healthcare sector, service desk employees must take some protective measures:
- Training IT help desk staff to recognize fraud.
- Verify employees requesting password resets and new MFA devices.
- Monitoring for suspicious ACH changes.
- Re-validation of users with access to payer websites.
- Review of personal requests for sensitive matters.
- Requirement for supervisors to verify requests.
Source: www.bleepingcomputer.com
