October 14, 2019 By David Bisson 2 min read

Healthcare companies experienced a 300 percent increase in impostor email attacks between the first quarters of 2018 and 2019, a new report found.

According to Proofpoint, healthcare organizations received an average of 43 impostor emails during the first quarter of 2019. This constituted a 300 percent increase in impostor email attacks over the same quarter in the previous year. Of affected healthcare organizations, 95 percent were hit with email spoofing of their own trusted domains; on average, 65 people received spoofed email messages.

A deeper dive into the attack emails revealed that subject lines containing the words “payment,” “request,” “urgent” and related terms appeared in 55 percent of the fake emails. In addition, 77 percent of attack messages arrived with malicious URLs. Attackers used this tactic and others to target healthcare entities primarily with banking Trojans.

Email and Malware Attacks in the Healthcare Industry

Bad actors are increasingly launching email attacks to prey upon healthcare organizations. Proofpoint disclosed in February 2019 that the average healthcare organization suffered 96 email fraud attacks in Q4 2018, up 473 percent from the beginning of 2017.

Cybercriminals leveraged those attack emails and other techniques to deliver various malware, but as revealed by Verizon in its “2019 Data Breach Investigations Report (DBIR),” ransomware accounted for 70 percent of all malware incidents that affected this vertical during its data collection period.

Unfortunately, these ransomware attacks didn’t slow down over the next few months. Emsisoft found that healthcare providers weathered 491 ransomware attacks between Q1 and Q3 2019, which comprised about 79 percent of ransomware incidents encountered by all industries during that same time period.

How Can Healthcare Companies Defend Against Email Attacks?

Security professionals can help healthcare organizations defend against email attacks by investing in email security tools to eliminate obvious phishing emails and similar attacks before they arrive in employees’ inboxes. Organizations should also implement mandatory security awareness training to educate users about malicious attachments and links commonly found in attack emails.

More from

How to craft a comprehensive data cleanliness policy

3 min read - Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.Understanding the 6 dimensions of…

2024 roundup: Top data breach stories and industry trends

3 min read - With 2025 on the horizon, it’s important to reflect on the developments and various setbacks that happened in cybersecurity this past year. While there have been many improvements in security technologies and growing awareness of emerging cybersecurity threats, 2024 was also a hard reminder that the ongoing fight against cyber criminals is far from over.We've summarized this past year's top five data breach stories and industry trends, with key takeaways from each that organizations should note going into the following…

Black Friday chaos: The return of Gozi malware

4 min read - On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America. The Black Friday connection Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today