Healthcare Phishing Teardowns
Every Attack of the Day teardown where the targeted organization was in healthcare, newest first. Real attacks on healthcare organizations, dissected: the headers, the lure, and why it got past the first line of defense. Targeted organizations are never named.
All teardownsEducationManufacturingFilter in the ExplorerHealthcare email security
2026
- One Target List, Six Weeks of Conference Invites
- Nothing to Block: A 1990s Domain and a Google Form
- The Phishing Email That Read Backwards in Its Own Source
- Perfect Authentication, Borrowed From a Real Mailbox
- The Redirect That Lied About Its Own Destination
- Mexico's Tax Authority, Sent From a Yahoo Account
- One Extra Letter, Full Auth Pass, Nothing to Scan
- Two Brands in One Message, One URL Built at Runtime
- Known Sender, Perfect Auth, Confirmed Malicious Link
- The SharePoint Lure That Never Touched Microsoft
- Every e, o, and p Was Cyrillic. The Adobe Logo Was Real.
- Two Invoices, One Reference ID, and a $4.8 Trillion Typo
- A DMARC Pass With No SPF, and a CTA Full of Hidden Letters
- Even the Unsubscribe Link Installed a Remote-Access Tool
- Interactive Brokers W-8BEN Lure Hid Behind a 0-Day Domain
- Forged Healthcare Sender, Two-Hop SaaS Redirect: How a Fake Invoice Opens a Phishing Chain
- The Government Card Alert That Lost Its Authentication in Transit
- A Medicare Attestation Request Sent Through Salesforce, Authenticated by the Victim's Own Domain
- The Geek Squad Invoice That Forgot Which Brand It Was Pretending to Be
- The PDF That Passed Every Scan Without Being Read
- The $47,320 Invoice That Came With a W-9 and a Personal Bank Account
- The Spreadsheet That Arrived Twice: CR/LF Filename Obfuscation and a Base64 Shadow Payload
- The Bank Statement You Had to Unlock With Your Birthday: PII-Gated PDF Evasion From Authenticated Infrastructure
- The Unsubscribe Button Was the Payload: How a Fake Health Email Weaponized Opt-Out Compliance
- Past Due Invoice, Future Wire Fraud: How a BEC Campaign Passed Every Authentication Check
- The Meeting Invite That Knew Your Email Address
- The Restaurant Booking Platform That Validated Your Inbox Before the Attack Began
- The Lab Result Notification That Every Security Check Approved (Because the Platform Was Real)
- The Law Firm Name That Used Invisible Characters to Pass Authentication
- The Phishing Simulation Platform That Powered a Real Attack
2025
- The Credential Page Was Real. The Domain Was One Extension Off.
- A 16-Day-Old Domain, Zero Links, and One Phone Number: Anatomy of a Pure TOAD Attack
- Nested RFC822 Attachment with No DKIM or DMARC Signals Thread Hijack via Internal Routing
- Compromised .gov SharePoint Tenant Delivers Credential Harvest via Tokenized Links
- Wire Transfer PDF Invoice Passes DLP Gateway with Full Email Authentication
- Self-Addressed and BCC'd: A Compromised Hospital Account Delivered Encrypted PDFs at Scale
- Facebook Share Notification Abuses Legitimate Infrastructure to Target Corporate Inboxes
- The Invoice Attachment Was Empty. The Attack Was Not.
- The SendGrid Email That Came From a Window Company
- The Vendor Address Hiding in Plain Sight: How a Free Email Service Carried a B2B Impersonation Into a Real Thread
- The Phishing Relay Running on Government Cloud Infrastructure
- The Shared File Card That Was Actually a PNG: Image-Based Microsoft 365 Credential Harvesting
- Voicemail Lure Hides Behind Microsoft Dynamics CRM and Three Mismatched Domains
- Google Sent This Email. The Law Firm Spelled with Cyrillic Letters Did Not.
- The Silent Read: VERP Bounce Sender and a Personal Gmail Read-Receipt Channel in a DMV Impersonation
- Colleague-Confirmed Fraud: When the Invoice Already Has an Internal Warning Attached
- SendGrid as the Delivery Rail, sendgrid-verify[.]com as the Trap
- Voicemail Phish Abuses Microsoft Dynamics 365 Marketing Host to Deliver CEO-Targeted CTA
- The "Access Code" That Passed Every Authentication Check
- A Friend's Sick Daughter and a Gift Card: The BEC Attack That Left No Evidence for Scanners
- When Your Vendor's Email Account Sends You Malware
- AV Said This PDF Was Clean. It Was Wired to Fire a Google Script the Second You Opened It.
- The Invoice Hidden in Your Calendar: .ics Payment Fraud
- The Calendar Invite Google Signed for the Attacker
- Fake Xerox Receipt, No File, Two Reply Mailboxes
- McAfee Renewal Scam Sent Under the Victim's Own Name
- A Zix Secure Message Alert That Opened a ClickUp Form
- A Microsoft Renewal Scam With a Phone Number Payload
- A Fake Secure Message From Your Own IT Security Team
- Dropbox Email, DocuSign Form, One Raw S3 Bucket
- A Real Demio Invite Hid a $969 Crypto Payment Scam
- Everything In This Email Was Real Except One Link
- The Fake Login That Sends You to the Real Microsoft
2024
- A Days-Old Domain Sent a Calendar Invite From Yourself
- A Fake Attorney, Your Real SSN, and a $697 Demand
- A Credential Phish With No Attacker Domain to Block
- The Power BI Report That Was Really a Vishing Lure
- A Real File-Transfer Alert With a Throwaway Reply-To
- The Login-Expiry Lure That Spoofed No One
- The Leftover Footer Link That Unmasked an Invoice Scam
- Two Images, Zero Text: A Secure-Document Lure
- When a University's Own Domain Blasts a Job Scam
- The Email Addressed to Its Own Sender
- One JPEG, Two Attachments, Nothing to Scan
- A DKIM Signature That Pointed at No Key
- The Sender Was a Coworker and Nothing Looked Wrong
- The Forged Reply That Explained Why the Invoice Arrived
- An EY Forum Invoice With Someone Else's Bank Details
- The Attachment Card That Printed Its Own Emptiness
- Fabricated Invoice Thread BEC Rides a Compromised Mailbox
- The Phishing Page No Link Scanner Ever Saw
- Nothing to Block: A Phish With Perfect Authentication