Fake IT Support Calls Are Targeting Healthcare: What Your Team Should Verify
Fake IT Support Calls Are Targeting Healthcare: What Your Team Should Verify

Published August 10, 2026
An unexpected call from “IT” may not seem suspicious. Healthcare employees speak with support vendors, software companies, and internal IT teams every day.
That normal interaction is exactly what makes this attack effective.
Google Threat Intelligence Group, or GTIG, recently reported that attackers are calling employees while pretending to be IT-support personnel. The caller creates an urgent reason to update multifactor authentication, register a passkey, or complete a security migration. The employee is then sent to a convincing but fraudulent login portal.
Healthcare was among the industries targeted by infrastructure connected to this campaign.
Quick Answer: What Should an Employee Do During an Unexpected IT Call?
Do not provide a password, read back an authentication code, approve an unexpected MFA prompt, or register a passkey based only on an incoming call.
End the conversation and contact IT through the telephone number, support portal, or internal contact your organization already has on file. Verify the request before changing anything.
If you already followed the caller’s instructions, report it immediately. The sooner IT knows what happened, the sooner it can revoke sessions, review account activity, and determine what needs to be secured.
What Is Happening?
GTIG tracks the group behind this activity as UNC6671. Its attacks have been connected to several public extortion brands, including BlackFile, Redact, Pink, Helix, and Falcon.
The names may change, but the approach is consistent:
- Research an organization and its employees.
- Call an employee while pretending to represent the IT help desk.
- Create urgency around an MFA, passkey, or security update.
- Send the employee to a fake portal using the organization’s name.
- Capture credentials and authentication information.
- Use the access to enter cloud services such as Microsoft 365 or Okta.
- Find valuable information and remove it from the environment.
- Use the stolen information for extortion.
In some cases, the attackers called employees on their personal mobile phones. GTIG also observed spoofing of legitimate help-desk numbers, meaning the caller ID could appear familiar.
A familiar number is not proof that the caller is legitimate.
Why This Matters to Healthcare Organizations
Healthcare employees are accustomed to outside support.
A nurse may speak with the EHR vendor. A practice manager may work with the billing company. A dental office may need help with imaging software. A home-health employee may contact IT from the field. Staff in a senior-living community may depend on remote support outside normal business hours.
Attackers take advantage of that trust.
If an attacker gains access to an employee’s Microsoft 365 or another cloud account, the attacker may be able to reach whatever that employee is authorized to use. Depending on the person’s role, that could include email, shared documents, schedules, operational records, billing information, or vendor communications.
This does not mean every targeted healthcare organization was breached or that patient information was stolen. GTIG identified healthcare among the sectors targeted by campaign infrastructure, but it did not publicly identify every organization or report the outcome of every attempt.
The practical lesson is simpler: employees need an easy way to verify IT, and IT needs a reliable way to verify employees.
Why These Calls Work
The Request Sounds Routine
Password resets, MFA changes, software updates, and new-device enrollment are normal IT activities. The attacker disguises the request as something employees already expect.
The Caller Creates Urgency
The employee may be told that an account will be disabled or that a security update must be completed immediately. That pressure makes it less likely that the person will stop and verify the request.
The Caller May Know Real Information
An attacker may know the employee’s job title, supervisor, telephone number, vendor, or email address. Real information makes a false story sound credible.
The Website Looks Professional
The fake portal may include the organization’s name and familiar terms such as “MFA,” “SSO,” “passkey,” or “help desk.” A professional-looking page can still be fraudulent.
MFA Is Not All the Same
MFA remains an important security control. However, attackers may convince an employee to disclose a code, approve a prompt, or complete authentication through a fraudulent website.
Phishing-resistant methods provide stronger protection, but technology alone cannot replace a clear verification process.
Five Rules for Unexpected IT Calls
1. Pause Before Acting
A legitimate support professional should understand why an employee wants to verify a security-sensitive request.
Urgency should never eliminate verification.
2. Never Share Authentication Information
Employees should not disclose their password, MFA code, password-reset code, recovery code, or the contents of an unexpected authentication prompt.
They should never approve an MFA request they did not initiate.
3. Use the Official Support Channel
Do not use a link or callback number supplied by the caller.
End the call and contact IT using the support number, portal, or internal contact already documented by the organization.
4. Verify the Ticket
Ask for a ticket number, then verify it through the normal support system. A ticket number by itself is not proof, but it gives the real IT team something to confirm.
5. Report Suspicious Calls
Even an unsuccessful attempt may show that the organization is being targeted. Record the time, telephone number, domain name, text messages, and other available details.
Do not revisit a suspicious website merely to collect more information.
What If Someone Already Followed the Instructions?
Treat the situation as time-sensitive, but avoid blame.
Employees sometimes hesitate to report a mistake because they are embarrassed or worried about getting in trouble. That delay gives the attacker more time.
The employee should stop communicating with the caller and contact the established IT or security representative immediately. They should explain:
- What information they entered or disclosed
- Whether they approved an MFA prompt
- Whether they registered a passkey or authentication method
- Which website they visited
- Which device they used
- Whether they downloaded anything
- When the interaction occurred
Depending on what happened, the technical response may include resetting credentials, revoking active sessions, reviewing authentication methods, checking Microsoft 365 and email activity, examining the managed device, and preserving relevant logs.
Changing the password may not be enough if the attacker already obtained an authenticated session or registered another authentication method.
How Healthcare Leaders Can Reduce the Risk
Healthcare administrators do not need to become security analysts. They do need written answers to a few practical questions.
Do Employees Know How to Verify IT?
Publish one official support number and one approved support portal. Explain how technicians identify themselves, what they will never request, and how employees should report suspicious contact.
Keep those instructions somewhere staff can access during an outage.
Is There a Callback Rule?
Employees should be expected to end unsolicited calls involving passwords, MFA, passkeys, remote access, or security settings. They can then reconnect through the official support channel.
Leadership should support this behavior. Employees should never feel that verifying an IT request will get them in trouble.
How Are Password and MFA Resets Approved?
Help-desk personnel should not rely only on information that can be researched or purchased, such as birth dates, job titles, addresses, or supervisor names.
Password resets, MFA resets, new-device enrollment, passkey registration, and recovery-method changes should follow a documented identity-verification process.
Privileged and administrative accounts should receive additional scrutiny.
Are Important Accounts Adequately Protected?
GTIG recommends phishing-resistant authentication such as FIDO2 security keys, passkeys, and Windows Hello for Business.
Healthcare organizations should introduce stronger authentication carefully, starting with administrators and other high-risk accounts. Changes must be planned and tested so they do not interrupt clinical workflows.
Is Anyone Reviewing the Activity?
Organizations should be able to review password resets, MFA changes, unusual sign-ins, new authentication methods, unexpected inbox rules, privileged-account changes, and other suspicious activity.
Collecting logs is not enough. Someone must know when to review them, what requires escalation, and how the organization will document its response.
Protect, Operate, Recover, and Grow
Protect
Use strong authentication, separate administrative accounts from everyday accounts, apply least privilege, and require documented verification for password and MFA resets.
Operate
Maintain current support contacts, escalation paths, account procedures, and instructions for remote or after-hours employees.
Recover
Document how the organization will revoke affected sessions, secure accounts, preserve relevant information, examine managed devices, and continue essential workflows during a disruption.
Grow
Use exercises and real incidents to improve employee education, vendor oversight, technical documentation, and technology planning.
The Bottom Line
Fake IT-support calls work because employees are accustomed to trusting the people who maintain their technology.
The answer is not to make staff distrust every support interaction. The answer is to give them a simple verification process that works during a busy clinic day, an after-hours shift, or a home-health visit.
Every employee should remember three things:
- Never disclose a password or authentication code during an unsolicited call.
- Verify the request through the organization’s established support channel.
- Report a suspected mistake immediately.
A calm, documented process protects the organization without making legitimate support harder to use.
Frequently Asked Questions
What Is an IT Help-Desk Voice-Phishing Attack?
It is a social-engineering attack in which someone calls an employee while pretending to be an authorized IT-support professional. The caller tries to obtain credentials, authentication approval, remote access, or control of an account.
Will a Legitimate IT Technician Ask for My Password or MFA Code?
A properly designed support process should not require an employee to disclose a password or one-time MFA code. Verify unusual requests through the organization’s official support channel.
Can Caller ID Prove the Call Came From Our Help Desk?
No. Telephone numbers can be spoofed. End the call and reconnect through a known support number or approved portal.
Does MFA Stop Fake IT-Support Attacks?
MFA reduces risk, but some methods can be socially engineered or intercepted. Phishing-resistant authentication offers stronger protection against fraudulent websites.
What Should I Do if I Approved an Unexpected MFA Request?
Contact your established IT or security representative immediately. Provide the time, account, device, prompt, website, and any other available details.
Why Would Attackers Target a Small Healthcare Organization?
Small healthcare organizations still rely on valuable email, scheduling, billing, vendor, and clinical-support systems. They may also have informal support procedures that are easier to impersonate.
How Can We Verify a Passkey-Enrollment Request?
Start the process through an approved internal procedure, known support portal, or independently verified technician. Do not register a passkey through a link supplied during an unexpected call or text message.
Strengthen Your Healthcare Technology Readiness
Vault Technologies helps healthcare organizations improve Microsoft 365 and endpoint administration, help-desk processes, technical documentation, backup and recovery planning, and care-continuity readiness.
Our nurse-led perspective keeps the focus where it belongs: technology should support patient care, not interrupt it.
A complimentary Technology Health Assessment can help establish a practical baseline across access controls, endpoint management, vendor dependencies, support procedures, documentation, and recovery readiness.
Know where your organization stands. Request a complimentary Technology Health Assessment and identify the technology risks that deserve attention first.
The assessment is a practical planning tool. It is not a legal opinion, compliance certification, penetration test, forensic investigation, or guarantee against cyber incidents.
Authoritative Sources
- Google Threat Intelligence Group and Mandiant — “UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments,” published August 6, 2026
- Reuters — “Hackers Targeted U.S. Private Equity and Other Firms, Including Blackstone and CME,” published August 6, 2026
- Microsoft — “Require Phishing-Resistant Multifactor Authentication for Microsoft Entra Administrator Roles,” updated March 24, 2026
- Mandiant — “UNC3944 Targets SaaS Applications,” published June 13, 2024










