A phishing email can give an attacker control of a computer in your practice without delivering any malware. The email tricks someone into installing a real remote-support program, the kind your IT provider uses to fix a computer from somewhere else, and antivirus software usually has nothing to flag.
In a May 26, 2026 alert, the FBI warned that a criminal group called the Silent Ransom Group uses phone calls and phishing emails to pose as IT support, then gets into victims' computers "usually through legitimate remote access tools." The FBI says the group has hit healthcare companies, along with insurance and finance firms, and that "traditional antivirus products are also unlikely to flag the intrusion."
What remote-support software is and why attackers want it
The industry name for these programs is remote monitoring and management (RMM) software. IT help desks and outside IT companies use them every day to see a computer's screen, install updates, and troubleshoot problems without driving to your office.
According to a joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency, and the Multi-State Information Sharing and Analysis Center, Protecting Against Malicious Use of Remote Monitoring and Management Software, attackers can misuse any legitimate RMM product, including well-known tools like ScreenConnect and AnyDesk. The same advisory notes that "RMM software allows cyber threat actors to avoid using custom malware."
The Department of Health and Human Services (HHS) has warned healthcare organizations about the same problem. In an October 2023 alert, its Health Sector Cybersecurity Coordination Center (HC3) said "the same solutions used to operate, maintain, and secure healthcare systems and networks can also be turned against their own infrastructure."
What the approach looks like to your staff
HC3 lists "phishing emails, fake support calls, or even impersonating IT personnel" among the common ways attackers target people in healthcare.
The FBI alert describes two versions. In the older one, a phishing email claimed the recipient owed a small "subscription fee." To cancel it, the victim called the number in the email, and the attacker on the line emailed a link to download remote access software.
As of spring 2026, the FBI says the group poses as the victim's own IT department instead. It calls employees directly, or sends phishing emails urging them to call "IT support," and once someone is on the phone, the attacker directs them to grant access to a remote desktop session.
Among the warning signs, the FBI lists "new, unauthorized downloads of system management or remote access tools," naming Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, and Atera.
Why antivirus stays quiet
The CISA advisory says: "The use of RMM software generally does not trigger antivirus or antimalware defenses."
HC3 explains why: "Since remote access software is used by organizations for legitimate purposes, its use is frequently not flagged as malicious by security tools or processes."
Attackers can also run some of these tools without installing them. CISA says portable versions let attackers "bypass both administrative privilege requirements and software management control policies," and that criminals use legitimate remote-support software "as backdoors for persistence," a way back in after the first visit.
Why this matters for a small practice
Phishing reaches small practices often: in Paubox's survey of healthcare organizations with fewer than 250 employees, 43% reported a phishing or spoofing incident in the past year, and about half had no phishing or spoofing protection beyond their email platform's default settings, according to What small healthcare practices get wrong about HIPAA and email security.
Once inside, the FBI says this group moves fast: its members "quickly pivot to data exfiltration without encryption," then threaten to sell or post the stolen data and call the victim's employees or clients to push for payment. On a front-desk or billing computer, the data within reach is usually the same patient information your staff can open.
Under HIPAA's Breach Notification Rule, an unauthorized use or disclosure of protected health information (PHI) is presumed to be a breach unless you can show, through a risk assessment, a low probability that the information was compromised. If you can't tell what a stranger did during a remote session, that assessment gets hard to complete.
What to check this month
You don't need a security team to act on this. Most of these steps are a conversation with whoever handles your IT.
If no outside company handles your IT, the owner or office manager can start with the first check. On each computer, open the list of installed programs and look for remote-support names such as AnyDesk, ScreenConnect, Splashtop, or Zoho Assist that nobody in the office set up. If you find one you can't explain, bring in an IT security firm to check every computer, since CISA warns attackers use these tools to keep a way back in.
- Ask your IT provider which remote-support tool they use on your computers, and write the name down. CISA tells organizations to audit remote access tools to identify which RMM software is authorized.
- Ask them to check every computer for remote-support programs that aren't on that list, including portable versions that run without being installed.
- Ask about application controls, settings that only let approved programs run. CISA's RMM advisory recommends them, including "allowlisting RMM programs." While you're at it, CISA's guidance for small and mid-sized businesses says the IT provider's own accounts should get admin permissions only as needed.
- Tell staff how real IT support contacts them. The FBI recommends written policies on "when and how IT support will communicate and authenticate themselves to employees." Add one simple rule: opening a shared document should never require installing a program, and an unexpected call from "IT" gets a callback to a number you already have.
- Turn on multifactor authentication (MFA) for email and other accounts. The FBI recommends phishing-resistant multifactor authentication "for as many services as possible."
- Review your IT contract. CISA's small-business guidance recommends contracts that cover monitoring of the provider's activity on your network and notification when the provider has a security incident. An IT provider that can reach PHI also needs a signed business associate agreement (BAA).
Related: The importance of reviewing your BAA
Stopping it at the inbox
The FBI maps this group's first step to phishing emails "using invoice, billing, subscription, or IT-themed lures," and CISA's first listed mitigation is to block phishing emails.
Paubox's AI-powered Inbound Email Security analyzes tone, sender behavior, and message intent to catch phishing before it lands in a staff inbox. It works alongside HIPAA compliant email for the messages your practice sends to patients and referral partners.
The fastest check costs nothing: ask your IT provider which remote-support tool they use, and whether it is the only one on your computers.
Read also: Phishing emails hide the danger until after the click
