The healthcare and pharmaceutical sectors are facing a heightened risk of social-engineering attacks, according to cybersecurity researchers and threat intelligence experts.
The Health Information Sharing and Analysis Center recently warned that the group ShinyHunters was using voice-phishing attacks to target the healthcare sector. The hackers used medical-themed impersonation domains to trick healthcare employees into exposing their credentials.
More than a dozen member organizations have been hit by social-engineering attacks over the past couple of months, Errol Weiss, chief security officer at Health-ISAC, told Cybersecurity Dive. The actors involved are using aggressive tactics to try to compromise targeted companies.
“They’re pretty belligerent when it comes to getting somebody on the phone and convincing them they need to click on a password reset or an MFA reset,” Weiss said.
Researchers have separately identified a domain linked to The Com, an underground cybercrime network, which is likely being used in phishing attacks against healthcare organizations, according to researchers at Unit 42, the threat research and incident response arm of Palo Alto Networks.
The domain, [my-passkeys[.]com, is likely associated with Com-affiliated hackers based on known fingerprints, according to Unit 42 researchers. The domain was first identified in mid-September. At least two organizations in the healthcare and pharmaceutical sectors are potentially at risk of vishing, according to Unit 42 researchers.
Researchers at ReliaQuest confirmed a similar pattern of activity outlined in the Health-ISAC advisory.
“Our domain analysis identified a sustained cluster of phishing and vishing infrastructure targeting the healthcare and pharmaceutical sector across the same period, with registrations continuing into late September 2026,” a spokesperson for ReliaQuest told Cybersecurity Dive.
Initial access
The healthcare industry has faced a series of social-engineering attacks in recent months.
Clover Health, a provider of healthcare plans for seniors, reported an attack in a mid-July regulatory filing with the Securities and Exchange Commission. The hackers gained access to three non-managerial employee accounts using social engineering.
AdaptHealth, a provider of CPAP machines and other medical devices, in July reported a social-engineering attack that exposed the data of more than 4.1 million patients. The hacker gained access to certain cloud-based business applications, according to a regulatory filing by the company.
Hims & Hers, a telehealth provider, in April disclosed a social-engineering attack that compromised a third-party customer service platform. Hackers gained access to customer names and email addresses, but more sensitive information was not lost.