An Indianapolis safety-net health system says a phishing chain that started with a compromised business contact reached one of its employee accounts and exposed patient information.
It started outside the health system. Someone had taken over the email account of a business contact that Eskenazi trusts, then used it to push thousands of messages to that contact’s whole address book. A link in one of those messages reached an Eskenazi worker, and by July 27, 2026 staff had confirmed an intruder was inside a cloud-based work account. The review later showed the access stretched back to June 1.
The message looked genuine, and the worker followed a link dressed up as a secure document notice and completed an authentication step. That handed the attacker the employee’s cloud-based work account.
Eskenazi Health runs the public hospital arm of the Health and Hospital Corporation of Marion County, and it is handling the review for the county corporation and its divisions. Law enforcement was notified, and notices with credit monitoring are going out to people whose electronic health information was involved.
Health systems increasingly live in cloud productivity suites, where one authenticated session can unlock years of correspondence and records. Security leaders should pair phishing-resistant login for staff with monitoring that flags mail spreading through a contact’s address book the way this one did.