Dear Colleagues,
We are sharing this advisory out of an abundance of caution due to recent reports of cybercriminals targeting healthcare organizations through phone-based social engineering attacks, commonly known as vishing (voice phishing).
In these attacks, the phone call is the primary attack method, not the website. Attackers attempt to gain trust by impersonating IT support personnel, security staff, vendors, or other trusted organizations and then direct users to websites that appear legitimate.
How the Scam Typically Works
An attacker may call and claim to be from:
- UConn Health IT
- Microsoft Support
- Epic
- McKesson
- Medtronic
- Boston Scientific
- A help desk, security team, or other third-party support organization
They may already know your:
- Name
- Department
- Manager
- Work location
The caller then creates urgency with statements such as:
- "Your account is under attack."
- "We are responding to a security incident."
- "Your VPN access is about to be disabled."
- "We need to verify your account immediately."
The attacker may direct you to a website that contains a familiar company name and appears healthcare-related. The goal is to convince you to enter your username and password or approve a multifactor authentication (MFA) request.
Be Especially Alert for Unexpected MFA Requests
A common tactic is for the attacker to obtain your credentials and then attempt to log in to a legitimate system. You may then receive a Microsoft Authenticator, Duo, or other MFA prompt.
The attacker may tell you: "That's the verification request I just sent. Please approve it."
Do not approve any MFA request that you did not personally initiate.
Our Most Important Security Guidance
Work with known contacts only.
If you receive an unexpected call from someone claiming to represent UConn Health IT, Microsoft, Epic, McKesson, Medtronic, Boston Scientific, or any other vendor:
- Do not provide your username, password, verification code, or MFA approval.
- Do not visit websites provided during the call.
- End the call.
- Contact the organization using a phone number or contact method you already know and trust.
- Report suspicious calls immediately to the Information Security team.
Remember
UConn Health Information Technology and Information Security personnel will never ask you to:
- Provide your password.
- Read a one-time passcode over the phone.
- Approve an MFA request you did not initiate.
- Bypass security controls.
- Enter credentials into a website sent to you during an unsolicited call.
When in doubt, stop the conversation and independently verify the request through trusted channels.
Report suspicious activity: Report any suspicious calls, emails, text messages, or authentication prompts to the Information Security team immediately by calling the IT Service Desk, x4400.
Thank you for helping protect UConn Health, our patients, and our organization from social engineering attacks.
Rick McCarthy
Chief Information Officer
UConn Health





