Nebraska Medicine is telling employees to hang up on Microsoft Teams callers who claim to be IT support, the latest hospital system to warn about a vishing wave that has circulated for more than a year. The August 21 alert from the Omaha-based system’s information security team describes callers who invent urgent problems, from compromised computers to password resets, to pressure staff into handing over credentials, approving multifactor authentication prompts, or installing remote access software.
The system’s guidance is blunt: real IT staff never ask for passwords or MFA codes, and never request remote access outside established procedures. Employees who doubt a caller should verify identity through a known contact method, decline any MFA prompt they did not trigger, and reach the help desk through a verified number.
Vanderbilt Health issued a similar warning in June 2025 after staffers saw caller ID change mid-call from a supervisor’s name to something else. The FBI also flagged the pattern in May, when it warned about Silent Ransom Group, a crew that posed as IT workers to break into healthcare organizations.
Help desk impersonation works because a single approved prompt or remote-session grant can open a clinical network to attackers. Hospitals are increasingly drilling staff on the standard response: end the call and dial the help desk back on a known line.