Security News > 2020 > March > Health workers are top of phishers' target lists thanks to data value

Health workers are top of phishers' target lists thanks to data value
2020-03-16 15:30

Nurses are among the groups most heavily targeted by email scammers because of the value of the data they can access, according to email security biz Proofpoint's Adenike Cosgrove.

Cosgrove, an infosec strategist for Proofpoint, told The Register that not only are nurses and other frontline healthcare professionals at the top of phishing target lists, but that a healthcare worker asked her for advice on security best practice - rather than her own organisation's security team.

With today seeing the UK's GCHQ unit NCSC issue fresh warnings over phishers using the current coronavirus situation as fresh bait to lure targets into opening malware-laden email attachments, Cosgrove's description of this incident ought to have corporate infosec teams paying more attention to how approachable they are to their own colleagues.

Cosgrove described one such incident: "One interesting threat that we've seen is criminals pretending to be a hospital in Nashville, Tennessee. There's an Excel document within the email, which says 'Here are your HIV results; open the Excel document to view the results'."

It's not just healthcare people either, Cosgrove told us: "Criminals are targeting HR professionals too. Their job is to open those emails, open those Word documents. Their job is to enable the macros so they can read the CVs!". Linking this with the earlier example of the healthcare organisation whose staffers didn't feel they could talk to their own IT security team, she says: "We blanket-train people into saying don't enable macros, don't open Word documents, yet HR professionals get emails they're not expecting every single day. Their job is to open them! So now you're telling me that I shouldn't do my job? This is why security loses credibility with the business."


News URL

https://go.theregister.co.uk/feed/www.theregister.co.uk/2020/03/16/proofpoint_interview/