MedRisk
  • Home
  • News
    NewsShow More
    Interlock claims it took dialysis data from a South Jersey kidney practice
    Interlock claims it took dialysis data from a South Jersey kidney practice

    A ransomware group with a taste for medical records says it broke…

    September 30, 2026
    A ransomware crew posts a Charlotte allergy clinic to its leak page
    A ransomware crew posts a Charlotte allergy clinic to its leak page

    A ransomware group that keeps circling U.S. healthcare has posted a Charlotte…

    September 30, 2026
    Indianapolis safety-net system traces a breach to a hijacked inbox
    Indianapolis safety-net system traces a breach to a hijacked inbox

    An Indianapolis safety-net health system says a phishing chain that began with…

    September 30, 2026
    A Kansas pathology lab and hospital settle a 2024 breach suit
    A Kansas pathology lab and hospital settle a 2024 breach suit

    A Salina, Kansas pathology laboratory and the hospital it serves have agreed…

    September 30, 2026
    A suspected ShinyHunters ringleader faces a Rotterdam court
    A suspected ShinyHunters ringleader faces a Rotterdam court

    Dutch police have arrested an Amsterdam man accused of working with the…

    September 30, 2026
  • Articles
    ArticlesShow More
    The HIPAA risk analysis is mandatory since 2005 yet still missing
    The HIPAA risk analysis is mandatory since 2005 yet still missing

    A compliance attorney's takeaways from the OCR-NIST HIPAA security conference point to…

    September 24, 2026
    Security analyst arranging plain folders on a table in a bright hospital IT office
    CISA pitches cheap decoys as a tripwire for hospital intruders

    New CISA guidance urges resource-stretched critical infrastructure teams, hospitals included, to plant…

    September 18, 2026
    Hand-drawn illustration of a physician in a white coat looking at a phone in a bright hospital corridor
    Hospitals wrestle with AI tools doctors adopt on their own

    Clinicians are reaching for free AI assistants before IT has approved anything,…

    September 17, 2026
    Hand-drawn illustration of a Latin American hospital campus with palm trees
    Report finds care providers absorb most Colombian intrusions

    A Biofile analysis drawn from IBM's X-Force data finds hospitals and clinics…

    September 14, 2026
    German textile firm insolvency after cyberattack highlights healthcare supply chain risk

    ZEGO-TVZ collapse after cyberattack reveals healthcare supply chain vulnerability in specialized medical…

    July 18, 2026
  • Features
    FeaturesShow More
    Israel's largest HMO pairs its AI rollout with a security vendor
    Israel’s largest HMO pairs its AI rollout with a security vendor

    Israel's largest health maintenance organization is pairing a cybersecurity vendor with its…

    September 30, 2026
    HIPAA security rule overhaul pushed to July 2027 as healthcare sector pushes back

    HHS has delayed the first major HIPAA Security Rule overhaul in over…

    July 12, 2026
    Healthcare Cyberattacks Persist as SonicWall Report Flags Millions of Exploitation Attempts and Rising Ransomware Pressure

    SonicWall’s latest Healthcare Protect Brief warns that healthcare remains the most persistently…

    June 23, 2026
    FTC Warns Tech Giants Against Weakening Encryption or Enabling Censorship

    The agency cautions leading U.S. tech companies that complying with foreign demands…

    May 17, 2026
    McLaren Health Care Confirms Ransomware Attack Affecting 740,000 Patients in Michigan

    The provider has disclosed a ransomware attack that compromised the personal and…

    May 17, 2026
  • Spotlight
    SpotlightShow More
    Ryuk operator pleads guilty Blackcat AlphV conspirator sentenced to 6 years

    Two ransomware actors face prison time in separate cases involving Ryuk and…

    July 13, 2026
    Legacy Sitecore Flaw Exploited in Healthcare Environments to Deploy WeepSteel Malware

    Mandiant warns that outdated Sitecore configurations in healthcare systems could expose sensitive…

    May 17, 2026
    Three Healthcare Organizations Disclose Major Data Breaches Impacting Over 175,000 Patients

    Recent breaches at CPAP Medical Supplies, a Miracle Ear franchisee, and a…

    May 17, 2026
    Stealthy Prompt Injection in Images Lets Attackers Hijack AI Systems

    Researchers have discovered a method for hiding malicious instructions in images that…

    May 17, 2026
    Transparent Tribe Targets Indian Government With Malicious Desktop Shortcut Files

    The Pakistani-linked APT36 group has expanded its tactics by weaponizing Linux BOSS…

    May 17, 2026
  • About
    • Mission
    • Services
    • Contact
  • Alerts
  • AI Risk
  • Compliance & Legal
  • Cryptography
  • CVEs
  • Data Breaches
  • Malware
  • OT/ICS
  • Phishing
  • Privacy
  • Ransomware
  • Social Engineering
  • Startups
  • Threats
MedRiskMedRisk
Font ResizerAa
  • Home
  • News
  • Articles
  • Features
  • Spotlight
  • Events
Search
  • Quick Links
    • Home
    • News
    • Articles
    • Features
    • Spotlight
  • About MedRisk
    • Mission
    • Services
    • Contact
Have an existing account? Sign In
Follow US
© 2026 MedRisk. All Rights Reserved.
News

Indianapolis safety-net system traces a breach to a hijacked inbox

An Indianapolis safety-net health system says a phishing chain that began with a compromised business contact reached an employee account and exposed patient information.

MedRisk Staff
Last updated: September 30, 2026 3:27 am
By
mradmin
Share
2 Min Read
Indianapolis safety-net system traces a breach to a hijacked inbox
SHARE

An Indianapolis safety-net health system says a phishing chain that started with a compromised business contact reached one of its employee accounts and exposed patient information.

It started outside the health system. Someone had taken over the email account of a business contact that Eskenazi trusts, then used it to push thousands of messages to that contact’s whole address book. A link in one of those messages reached an Eskenazi worker, and by July 27, 2026 staff had confirmed an intruder was inside a cloud-based work account. The review later showed the access stretched back to June 1.

The message looked genuine, and the worker followed a link dressed up as a secure document notice and completed an authentication step. That handed the attacker the employee’s cloud-based work account.

Eskenazi Health runs the public hospital arm of the Health and Hospital Corporation of Marion County, and it is handling the review for the county corporation and its divisions. Law enforcement was notified, and notices with credit monitoring are going out to people whose electronic health information was involved.

Health systems increasingly live in cloud productivity suites, where one authenticated session can unlock years of correspondence and records. Security leaders should pair phishing-resistant login for staff with monitoring that flags mail spreading through a contact’s address book the way this one did.

TAGGED:cloud account takeoveremail compromiseEskenazi HealthHIPAAIndianapolisPatient DataPhishing
SOURCES:Eskenazi HealthClaim DepotBeinsure
Share This Article
Email Copy Link Print
Previous Article A Kansas pathology lab and hospital settle a 2024 breach suit A Kansas pathology lab and hospital settle a 2024 breach suit
Next Article A ransomware crew posts a Charlotte allergy clinic to its leak page A ransomware crew posts a Charlotte allergy clinic to its leak page

You May also Like

AlertsArticles

Healthcare Systems on Alert as Cisco ASA Scans Surge, Hinting at New Vulnerabilities

May 17, 2026
News

CISA Reschedules CIRCIA Town Halls After DHS Shutdown, Posing Urgent Questions for Healthcare Incident Reporting

June 12, 2026
Illustration of a calm modern clinic building surrounded by trees in Poland
News

Poland probes a second medical data attack on a software supplier

September 27, 2026
News

Medical Hosting Under Siege cPanelSniper Exploit Targets 44k Servers Threatening Patient Data

May 17, 2026
Show More
MedRisk

The latest in healthcare & medical technology risk
From breaking news to expert analysis, our coverage helps professionals stay informed, secure, and ahead of the threat curve.

X-twitter Youtube Linkedin

© 2026 MedRisk. All rights reserved. Privacy | Legal

Quick Links

  • News
  • Articles
  • Features
  • Spotlight
  • Events
  • Mission
  • Services
  • Contact
Welcome to Foxiz
Username or Email Address
Password

Lost your password?