Security Advisory

Protect Yourself from Phone-Based Credential Scams (Vishing)

UConn Health Information Technology wordmark
Jan 01, 1901
Chief Information Officer
Rick McCarthy
All News

Dear Colleagues,

We are sharing this advisory out of an abundance of caution due to recent reports of cybercriminals targeting healthcare organizations through phone-based social engineering attacks, commonly known as vishing (voice phishing).

In these attacks, the phone call is the primary attack method, not the website. Attackers attempt to gain trust by impersonating IT support personnel, security staff, vendors, or other trusted organizations and then direct users to websites that appear legitimate.

How the Scam Typically Works

An attacker may call and claim to be from:

  • UConn Health IT
  • Microsoft Support
  • Epic
  • McKesson
  • Medtronic
  • Boston Scientific
  • A help desk, security team, or other third-party support organization

They may already know your:

  • Name
  • Department
  • Manager
  • Work location

The caller then creates urgency with statements such as:

  • "Your account is under attack."
  • "We are responding to a security incident."
  • "Your VPN access is about to be disabled."
  • "We need to verify your account immediately."

The attacker may direct you to a website that contains a familiar company name and appears healthcare-related. The goal is to convince you to enter your username and password or approve a multifactor authentication (MFA) request.

Be Especially Alert for Unexpected MFA Requests

A common tactic is for the attacker to obtain your credentials and then attempt to log in to a legitimate system. You may then receive a Microsoft Authenticator, Duo, or other MFA prompt.

The attacker may tell you:  "That's the verification request I just sent. Please approve it."

Do not approve any MFA request that you did not personally initiate.

Our Most Important Security Guidance

Work with known contacts only.

If you receive an unexpected call from someone claiming to represent UConn Health IT, Microsoft, Epic, McKesson, Medtronic, Boston Scientific, or any other vendor:

  1. Do not provide your username, password, verification code, or MFA approval.
  2. Do not visit websites provided during the call.
  3. End the call.
  4. Contact the organization using a phone number or contact method you already know and trust.
  5. Report suspicious calls immediately to the Information Security team.

Remember

UConn Health Information Technology and Information Security personnel will never ask you to:

  • Provide your password.
  • Read a one-time passcode over the phone.
  • Approve an MFA request you did not initiate.
  • Bypass security controls.
  • Enter credentials into a website sent to you during an unsolicited call.

When in doubt, stop the conversation and independently verify the request through trusted channels.

Report suspicious activity: Report any suspicious calls, emails, text messages, or authentication prompts to the Information Security team immediately by calling the IT Service Desk, x4400.
 
Thank you for helping protect UConn Health, our patients, and our organization from social engineering attacks. 

Rick McCarthy
Chief Information Officer
UConn Health