CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ✉ Email Security Mar 20, 2026

Phishing operation attacking at least 20 health care organizations disrupted by Microsoft - American Hospital Association

American Hospital Association Archived Mar 20, 2026 ✓ Full text saved

Phishing operation attacking at least 20 health care organizations disrupted by Microsoft American Hospital Association

Full text archived locally
✦ AI Summary · Claude Sonnet


    Sep 18, 2025 - 03:34 PM Microsoft Sept. 16 announced it had disrupted a growing phishing service that had targeted at least 20 U.S. health care organizations. The company said it used a court order granted by the U.S. District Court for the Southern District of New York to seize 338 websites associated with RaccoonO365, a cyber threat group known for stealing Microsoft 365 credentials through phishing tactics. RaccoonO365 offers subscription-based phishing kits that allow individuals to steal Microsoft credentials by mimicking official Microsoft communications. The company said the phishing kits use Microsoft branding to create fraudulent emails, attachments and websites. Since July 2024, the kits have stolen at least 5,000 Microsoft credentials from individuals in 94 countries. The group was recently observed offering a new artificial intelligence-powered service in an attempt to scale their operations. “Credentials stolen through RaccoonO365 enabled ransomware attacks against hospitals, posing a direct threat to patient and community safety,” said John Riggi, AHA national advisor for cybersecurity and risk. “This operation also highlights a disturbing trend — cybercriminals’ increased use of ‘initial access brokers’ to steal credentials and AI to accelerate the effectiveness, sophistication and impact of cyberattacks. The need for continued and evolving social engineering training for staff is essential to defend against the latest deception tactics used by hackers.” For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity. Cybersecurity HEADLINE Virtual event to focus on cyber incident response and recovery The Health Sector Coordinating Council Cyber Working Group and Health-ISAC (Information Sharing and Analysis Center) will host a joint cybersecurity event July… HEADLINE Medical technology company Stryker disrupted globally by cyberattack Stryker, a medical technology company that provides services and products for hospitals, was disrupted globally by a cyberattack, the company announced March… HEADLINE White House issues executive order addressing cybercrime by threat groups The White House issued an executive order March 6 to combat cybercrimes by threat groups. The order highlights how such groups can receive willing or… HEADLINE ASPR releases cybersecurity module to conduct risk assessments  The Administration for Strategic Preparedness and Response has released a new cybersecurity module for organizations to conduct risk assessments. The free… PERSPECTIVE Staying Cyber Alert and Cyber Ready As the world has learned in recent years, today’s conflicts are fought with many weapons, and cyber warfare is an integral part of the arsenal.As of this… HEADLINE FBI reminds of potentially malicious activity by Iranian cyber actors The FBI is reminding critical infrastructure organizations to implement mitigations from a June 2025 fact sheet on potential actions by Iranian-affiliated…
    💬 Team Notes
    Article Info
    Source
    American Hospital Association
    Category
    ✉ Email Security
    Published
    Mar 20, 2026
    Archived
    Mar 20, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗