Health-ISAC published a white paper on August 17, 2026, warning that healthcare staff and IT help desks are being targeted through conversational social engineering rather than only malicious software or exploited vulnerabilities.

 

What happened

The report says attackers research employees and organizational structures using public sources, then contact staff by phone, text, or collaboration platforms while posing as clinicians, executives, or other trusted personnel. Attackers may create urgency around patient care or account access to persuade help-desk workers to reset passwords, register new multifactor authentication devices, or bypass identity-verification procedures.

The paper notes Scattered Spider, a financially motivated cybercriminal group that federal agencies say has used voice calls and SMS messages to convince help-desk personnel to reset credentials and MFA tokens. Similar conduct has been documented in healthcare an HHS alert described attackers calling health-sector help desks, supplying stolen personal and corporate information, claiming a phone was broken, and persuading personnel to enroll a new device for MFA. The Health-ISAC paper also warns that generative AI can make impersonation more convincing through voice mimicry, although HHS previously said AI use in the healthcare help-desk incidents it reviewed was unknown.

 

In the know

Scattered Spider emerged in 2022 as a financially motivated, English-speaking cybercriminal collective also tracked as UNC3944, Octo Tempest, Muddled Libra, and Scatter Swine. Early campaigns focused on telecommunications and business-process outsourcing companies, using SMS phishing, SIM swapping, and stolen credentials to defeat multifactor authentication.

The group expanded into data theft, extortion, and ransomware, impersonating employees when calling IT help desks. Notable attributed attacks came in September 2023, when Caesars Entertainment disclosed a social-engineering breach involving an outsourced IT support vendor, and MGM Resorts suffered operational disruption; MGM later estimated the incident reduced its September results by approximately $100 million. Paubox has also covered Clorox’s allegation that Scattered Spider entered its network in August 2023 after service-desk personnel supplied credentials to callers posing as employees, an attack that disrupted manufacturing and distribution.

 

What was said

According to the Health-ISAC report, “Conversational Social Engineering in Care Settings Modern cybercriminals don’t rely exclusively on software vulnerabilities or complex malware to breach hospital networks. Instead, they exploit the human interface through conversational, multi-channel campaigns.”

 

Going deeper

Beyond the attack methods, the Health-ISAC white paper identifies operational conditions that make healthcare particularly exposed. High workforce transience among shift workers, traveling nurses, locum tenens physicians, and outsourced patient-access representatives can cause workers to miss or receive outdated annual training. The paper also argues that a patient-first culture can be manipulated. A caller who claims a surgeon is locked out before a procedure can make identity verification feel like an obstacle to care.

The concern aligns with an ACI study of 453 public healthcare professionals in Kuwait, which explains, “Cybersecurity training competes against clinical training, which is naturally perceived as having more immediate benefits.” The study also found that physicians had lower cybersecurity scores than nurses and administrators, which the authors said may reflect physicians’ higher cognitive load.

The white paper further identifies blind spots across pagers, VoIP calls, SMS, mobile applications, and collaboration platforms that email-only security testing cannot assess. It therefore recommends cross-channel simulations for help desks, patient-access teams, and contact centers; immediate microlearning after failed exercises; and dynamic risk scores combining employee behavior, access privileges, and current threat intelligence.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

Does an MFA bypass mean the technology was hacked?

Usually, attackers do not break MFA’s encryption or security code. They instead deceive users or help-desk personnel, intercept verification codes, add an unauthorized device, or steal an authenticated session.

 

Why do attackers target IT help desks?

Help-desk workers may be authorized to reset passwords, remove authentication factors, and register replacement devices. CISA has documented attackers impersonating employees to persuade help desks to reset credentials and MFA tokens.

 

Why are healthcare help desks particularly attractive targets?

Healthcare help desks must restore access quickly for clinicians, traveling staff, contractors, and other workers involved in patient care. Attackers can exploit this urgency by claiming that an account problem is delaying treatment or another time-sensitive task.

 

How have attackers manipulated MFA in healthcare?

The HHS healthcare-sector alert described callers using stolen personal and corporate information to impersonate employees whose phones were supposedly broken. The attackers then persuaded help-desk personnel to register replacement devices under the attackers’ control.