The Department of Health and Human Services (HHS) encourages the HPH sector to remain vigilant against elevated cyber threat actor risks. HHS and our federal partners are monitoring an uptick in the use of “vishing” to gain access to HPH systems. Vishing scams happen over the phone, voice email, or VoIP (voice over internet protocol) calls. In addition to implementing the HPH Cybersecurity Performance Goals, HHS would like to remind partners to take the below actions to keep your systems secure:
- Verify urgent or unusual requests received through emails, texts, calls via another communication method before responding.
- Remain cautious of unsolicited emails, calls, or texts from individuals posing as representatives of law enforcement, your organization, or other trusted organizations.
- Provide security awareness training for new employees so they understand the danger vishing attackers can present. Make sure employees only allow verified technicians to access to their computer.
- Deploy Data Loss Prevention across outbound channels to detect the exfiltration phase where the attacker attempts to copy data.
- Eliminate phishable methods like SMS, voice fallbacks, and standard push notifications; enforce Phishing-Resistant MFA by transitioning all administrative and privileged accounts to methods which enable secure, phishing-resistant passwordless logins such as with cryptographic credentials (passkeys), biometrics or external hardware security keys.
Threat actors have also manipulated victims to take certain actions, such as:
- Provide an authentication code that allows the actors to sync their device with the victim’s contact list.
- Move the conversation to encrypted mobile applications, such as Signal, Telegram, and WhatsApp.
- Use voice communications to convince personnel to reset passwords and/or MFA tokens.
Among others, threat actor groups particularly known for these tactics include Scattered Spider and ShinyHunters. Given the increased targeting of the HPH sector, we encourage our partners to review the common tactics of both groups — linked in the CISA Cybersecurity Advisory (CSA) and FBI Public Service Announcement (PSA). Additional threat actor tactics recently seen are outlined in the Malicious Messaging Campaign FBI PSA.
Should your organization be facing a cyber attack:
- Report cyber attacks to any of the below:
– FBI’s Internet Crime Complain Center (IC3)
– A local FBI Field Office
– CISA via the agency’s Incident Reporting System or its 24/7 Operations Center (contact@mail.cisa.dhs.gov) or by calling 1-844-Say-CISA (1-844-729-2472) - You can also contact HHScyber@hhs.gov or (202) 619-7800 for support focused on mitigating adverse patient impacts