Fake IT Support Calls Are Targeting Healthcare: What Your Team Should Verify

Vault Technologies Team • August 11, 2026

Share this article

Fake IT Support Calls Are Targeting Healthcare: What Your Team Should Verify

Healthcare employee verifies a suspicious IT support call while a security analyst monitors identity access activity.

Published August 10, 2026


An unexpected call from “IT” may not seem suspicious. Healthcare employees speak with support vendors, software companies, and internal IT teams every day.


That normal interaction is exactly what makes this attack effective.


Google Threat Intelligence Group, or GTIG, recently reported that attackers are calling employees while pretending to be IT-support personnel. The caller creates an urgent reason to update multifactor authentication, register a passkey, or complete a security migration. The employee is then sent to a convincing but fraudulent login portal.


Healthcare was among the industries targeted by infrastructure connected to this campaign.


Quick Answer: What Should an Employee Do During an Unexpected IT Call?


Do not provide a password, read back an authentication code, approve an unexpected MFA prompt, or register a passkey based only on an incoming call.


End the conversation and contact IT through the telephone number, support portal, or internal contact your organization already has on file. Verify the request before changing anything.


If you already followed the caller’s instructions, report it immediately. The sooner IT knows what happened, the sooner it can revoke sessions, review account activity, and determine what needs to be secured.


What Is Happening?


GTIG tracks the group behind this activity as UNC6671. Its attacks have been connected to several public extortion brands, including BlackFile, Redact, Pink, Helix, and Falcon.


The names may change, but the approach is consistent:


  1. Research an organization and its employees.
  2. Call an employee while pretending to represent the IT help desk.
  3. Create urgency around an MFA, passkey, or security update.
  4. Send the employee to a fake portal using the organization’s name.
  5. Capture credentials and authentication information.
  6. Use the access to enter cloud services such as Microsoft 365 or Okta.
  7. Find valuable information and remove it from the environment.
  8. Use the stolen information for extortion.


In some cases, the attackers called employees on their personal mobile phones. GTIG also observed spoofing of legitimate help-desk numbers, meaning the caller ID could appear familiar.


A familiar number is not proof that the caller is legitimate.


Why This Matters to Healthcare Organizations


Healthcare employees are accustomed to outside support.


A nurse may speak with the EHR vendor. A practice manager may work with the billing company. A dental office may need help with imaging software. A home-health employee may contact IT from the field. Staff in a senior-living community may depend on remote support outside normal business hours.


Attackers take advantage of that trust.


If an attacker gains access to an employee’s Microsoft 365 or another cloud account, the attacker may be able to reach whatever that employee is authorized to use. Depending on the person’s role, that could include email, shared documents, schedules, operational records, billing information, or vendor communications.


This does not mean every targeted healthcare organization was breached or that patient information was stolen. GTIG identified healthcare among the sectors targeted by campaign infrastructure, but it did not publicly identify every organization or report the outcome of every attempt.


The practical lesson is simpler: employees need an easy way to verify IT, and IT needs a reliable way to verify employees.


Why These Calls Work


The Request Sounds Routine

Password resets, MFA changes, software updates, and new-device enrollment are normal IT activities. The attacker disguises the request as something employees already expect.


The Caller Creates Urgency

The employee may be told that an account will be disabled or that a security update must be completed immediately. That pressure makes it less likely that the person will stop and verify the request.


The Caller May Know Real Information

An attacker may know the employee’s job title, supervisor, telephone number, vendor, or email address. Real information makes a false story sound credible.


The Website Looks Professional

The fake portal may include the organization’s name and familiar terms such as “MFA,” “SSO,” “passkey,” or “help desk.” A professional-looking page can still be fraudulent.


MFA Is Not All the Same

MFA remains an important security control. However, attackers may convince an employee to disclose a code, approve a prompt, or complete authentication through a fraudulent website.

Phishing-resistant methods provide stronger protection, but technology alone cannot replace a clear verification process.


Five Rules for Unexpected IT Calls

1. Pause Before Acting

A legitimate support professional should understand why an employee wants to verify a security-sensitive request.

Urgency should never eliminate verification.


2. Never Share Authentication Information

Employees should not disclose their password, MFA code, password-reset code, recovery code, or the contents of an unexpected authentication prompt.

They should never approve an MFA request they did not initiate.


3. Use the Official Support Channel

Do not use a link or callback number supplied by the caller.

End the call and contact IT using the support number, portal, or internal contact already documented by the organization.


4. Verify the Ticket

Ask for a ticket number, then verify it through the normal support system. A ticket number by itself is not proof, but it gives the real IT team something to confirm.


5. Report Suspicious Calls

Even an unsuccessful attempt may show that the organization is being targeted. Record the time, telephone number, domain name, text messages, and other available details.

Do not revisit a suspicious website merely to collect more information.


What If Someone Already Followed the Instructions?

Treat the situation as time-sensitive, but avoid blame.


Employees sometimes hesitate to report a mistake because they are embarrassed or worried about getting in trouble. That delay gives the attacker more time.


The employee should stop communicating with the caller and contact the established IT or security representative immediately. They should explain:


  • What information they entered or disclosed
  • Whether they approved an MFA prompt
  • Whether they registered a passkey or authentication method
  • Which website they visited
  • Which device they used
  • Whether they downloaded anything
  • When the interaction occurred


Depending on what happened, the technical response may include resetting credentials, revoking active sessions, reviewing authentication methods, checking Microsoft 365 and email activity, examining the managed device, and preserving relevant logs.


Changing the password may not be enough if the attacker already obtained an authenticated session or registered another authentication method.


How Healthcare Leaders Can Reduce the Risk


Healthcare administrators do not need to become security analysts. They do need written answers to a few practical questions.


Do Employees Know How to Verify IT?


Publish one official support number and one approved support portal. Explain how technicians identify themselves, what they will never request, and how employees should report suspicious contact.

Keep those instructions somewhere staff can access during an outage.


Is There a Callback Rule?


Employees should be expected to end unsolicited calls involving passwords, MFA, passkeys, remote access, or security settings. They can then reconnect through the official support channel.

Leadership should support this behavior. Employees should never feel that verifying an IT request will get them in trouble.


How Are Password and MFA Resets Approved?

Help-desk personnel should not rely only on information that can be researched or purchased, such as birth dates, job titles, addresses, or supervisor names.

Password resets, MFA resets, new-device enrollment, passkey registration, and recovery-method changes should follow a documented identity-verification process.

Privileged and administrative accounts should receive additional scrutiny.


Are Important Accounts Adequately Protected?

GTIG recommends phishing-resistant authentication such as FIDO2 security keys, passkeys, and Windows Hello for Business.

Healthcare organizations should introduce stronger authentication carefully, starting with administrators and other high-risk accounts. Changes must be planned and tested so they do not interrupt clinical workflows.


Is Anyone Reviewing the Activity?

Organizations should be able to review password resets, MFA changes, unusual sign-ins, new authentication methods, unexpected inbox rules, privileged-account changes, and other suspicious activity.

Collecting logs is not enough. Someone must know when to review them, what requires escalation, and how the organization will document its response.


Protect, Operate, Recover, and Grow

Protect

Use strong authentication, separate administrative accounts from everyday accounts, apply least privilege, and require documented verification for password and MFA resets.


Operate

Maintain current support contacts, escalation paths, account procedures, and instructions for remote or after-hours employees.


Recover

Document how the organization will revoke affected sessions, secure accounts, preserve relevant information, examine managed devices, and continue essential workflows during a disruption.


Grow

Use exercises and real incidents to improve employee education, vendor oversight, technical documentation, and technology planning.


The Bottom Line

Fake IT-support calls work because employees are accustomed to trusting the people who maintain their technology.

The answer is not to make staff distrust every support interaction. The answer is to give them a simple verification process that works during a busy clinic day, an after-hours shift, or a home-health visit.

Every employee should remember three things:

  1. Never disclose a password or authentication code during an unsolicited call.
  2. Verify the request through the organization’s established support channel.
  3. Report a suspected mistake immediately.

A calm, documented process protects the organization without making legitimate support harder to use.


Frequently Asked Questions


What Is an IT Help-Desk Voice-Phishing Attack?

It is a social-engineering attack in which someone calls an employee while pretending to be an authorized IT-support professional. The caller tries to obtain credentials, authentication approval, remote access, or control of an account.


Will a Legitimate IT Technician Ask for My Password or MFA Code?

A properly designed support process should not require an employee to disclose a password or one-time MFA code. Verify unusual requests through the organization’s official support channel.


Can Caller ID Prove the Call Came From Our Help Desk?

No. Telephone numbers can be spoofed. End the call and reconnect through a known support number or approved portal.


Does MFA Stop Fake IT-Support Attacks?

MFA reduces risk, but some methods can be socially engineered or intercepted. Phishing-resistant authentication offers stronger protection against fraudulent websites.


What Should I Do if I Approved an Unexpected MFA Request?

Contact your established IT or security representative immediately. Provide the time, account, device, prompt, website, and any other available details.


Why Would Attackers Target a Small Healthcare Organization?

Small healthcare organizations still rely on valuable email, scheduling, billing, vendor, and clinical-support systems. They may also have informal support procedures that are easier to impersonate.


How Can We Verify a Passkey-Enrollment Request?

Start the process through an approved internal procedure, known support portal, or independently verified technician. Do not register a passkey through a link supplied during an unexpected call or text message.


Strengthen Your Healthcare Technology Readiness

Vault Technologies helps healthcare organizations improve Microsoft 365 and endpoint administration, help-desk processes, technical documentation, backup and recovery planning, and care-continuity readiness.

Our nurse-led perspective keeps the focus where it belongs: technology should support patient care, not interrupt it.

A complimentary Technology Health Assessment can help establish a practical baseline across access controls, endpoint management, vendor dependencies, support procedures, documentation, and recovery readiness.


Know where your organization stands. Request a complimentary Technology Health Assessment and identify the technology risks that deserve attention first.


The assessment is a practical planning tool. It is not a legal opinion, compliance certification, penetration test, forensic investigation, or guarantee against cyber incidents.


Authoritative Sources



Recent Posts

Healthcare administrator reviewing secure cloud access controls following Amgen’s reported patient P
By michael August 3, 2026
Amgen confirmed patient PHI was taken from third-party cloud environments. Learn five practical cloud security checks for healthcare organizations of every size.
By BSFM4465 August 3, 2026
This is a subtitle for your new post
Healthcare IT administrator reviewing N-central cybersecurity alerts and managed endpoint activity o
By michael August 3, 2026
N-central attacks reached managed endpoints. See what healthcare organizations should verify with their MSP after CVE-2026-18577 was actively exploited now.
Maryland medical group ransomware attack exposed patient records, leading to class-action lawsuits
By michael July 6, 2026
A January 2025 ransomware attack on a Maryland medical group exposed 934,000 patient records and triggered class-action lawsuits. See what proactive IT management would have changed.
Dental ransomware attack case study: $350,000 HIPAA settlement — Vault Technologies
By michael June 29, 2026
A 2020 dental ransomware attack led to a $350,000 HIPAA settlement after a 2-year disclosure delay. See what proactive monitoring and incident response would have changed.
By michael April 16, 2026
Vault Technologies Case Study — Synology 4‑Bay NAS Recovery for GoodGardens
By michael March 12, 2026
This is a subtitle for your new post
By michael March 12, 2026
Case Study: Emergency Data Recovery for a Time‑Sensitive Project
By michael February 24, 2026
Why Vault Technologies Is Becoming Oregon's Trusted IT Partner for Senior Care — and Beyond In a crowded field of MSPs, most companies promise the same things: "fast support," "reliable service," "expert technicians." But the organizations we serve aren't looking for another generic IT provider. They're looking for a partner who understands the stakes of what they do — and shows up with the discipline, documentation, and clarity to match. That's exactly why Vault Technologies was built. As a Service-Disabled Veteran-Owned and Woman-Owned business, we built Vault on the values that shaped our careers: precision, integrity, and accountability. We don't believe in vague promises or confusing pricing. We believe in clear expectations, transparent processes, and IT support that feels like a partnership rather than a gamble. That's what makes Vault different — and it's the thread running through everything we've built since. Built on Discipline, Documentation, and Trust Most MSPs operate behind the curtain. Clients rarely know what's happening, what's included, or what they're paying for. Vault Technologies takes the opposite approach. We document everything. We communicate proactively. We set boundaries clearly. We price transparently — flat, per-seat, per-month, with no hourly billing surprises. Our clients know exactly what we do, how we do it, and what to expect at every step. That clarity builds trust — and trust is the foundation of every long-term partnership we have. A Rare Hybrid: IT Expertise and Clinical Understanding One of the biggest gaps in healthcare IT is the divide between people who understand technology and people who understand care delivery. Most MSPs only know the former. Vault closes that gap. Our co-founder Kristina brings 15 years of nursing experience, including hospice and home care, to every conversation we have with assisted living, home health, and hospice clients. We don't just know what EHR downtime looks like on a dashboard — we know what it means for a med-pass window or a shift change when systems fail. That's a hybrid skillset almost no other MSP in Oregon can offer, and it's why we built our service tiers — Foundation, Continuum, and Vigil — specifically around the realities of shift-based care, not a generic 9-to-5 business clock. A Partner Built for Other MSPs, Too Vault isn't just direct-to-client. We're also structured to support other MSPs who need additional capacity without the overhead of hiring. Through our white-label and subcontracting model, we offer: Overflow ticket capacity when an MSP's queue gets ahead of them Standing capacity partnerships for MSPs ready to free up their senior techs Full-scope backend delivery for MSPs that want to focus on sales and relationships while we run help desk, NOC, security, and M365 administration behind the scenes Every tier comes with clear, published pricing and a transparent application process — because the same documentation-first approach we bring to direct clients applies to our MSP partners too. Certified and Ready for Government and Prime Contracting As a certified SDVOSB, VOSB, WOSB, and EDWOSB small business, Vault is also positioned to support federal, state, and local agencies, as well as prime contractors building out their subcontracting base. We're registered in SAM.gov and eligible for set-aside and sole-source opportunities — backed by the same audit-ready documentation and disciplined execution that defines how we operate everywhere else. Veteran Values, Applied Everywhere We Work Being veteran-owned isn't a marketing slogan for us — it's a mindset. It shows up in how we communicate. It shows up in how we document. It shows up in how we treat clients and partners alike. It shows up in how we build systems that scale — whether that's a single assisted living facility or an MSP partner's entire book of business. Why Organizations Choose Vault Technologies Organizations across Oregon and beyond choose Vault because we offer: Clear, transparent, per-seat pricing Professional, jargon-free communication Documented, audit-ready processes Veteran-level discipline Real clinical understanding for senior care and home health A scalable model for MSP partnerships and government contracting A modern, approachable brand built on substance, not slogans We're not trying to be the biggest MSP in Oregon. We're becoming the most trusted — for the care organizations who depend on us, the MSPs who partner with us, and the agencies who need a certified, capable small business they can rely on. The Future of Vault Technologies  Our mission is simple: become the most trusted IT partner for the organizations that value clarity, reliability, and professionalism — whether that's a senior care facility that can't afford technology failure, an MSP looking for a dependable subcontractor, or an agency seeking a certified small business partner. This is the standard we hold ourselves to, and the standard our clients and partners have come to expect.