U.K. National Health Service Targeted with Over 40,000 Email Scams Aimed at Stealing Patient Data

Stu Sjouwerman | Aug 18, 2020

uk national health service scam emailThe last few months have been very busy for cyber attackers targeting the NHS, as the number of phishing emails reported within the NHS shows a continual barrage of attacks.

The U.K.’s National Health Service (NHS) safeguards patient data for all U.K. residents – a treasure trove for cybercriminals. According to data obtained via a Freedom of Information request by UK think tank, Parliament Street, the NHS’ malicious email reporting system received a total of 43,108 reports of suspicious emails received by NHS doctors, nurses and other staff between March and mid-July.

Email-based attacks included scams targeting HR employees using emails impersonating employees asking for payroll banking details to be changed, as well as attacks targeting employees using malicious links that supposedly would allow employees to validate their information to receive their paycheck.

Regardless of the specific scam, 43K phishing emails that made it all the way to the Inbox is eye-opening. It should send the message that organizations can’t assume security solutions will keep malicious emails from reaching the user.

According to NHS Digital’s CIO, Neil Bennet, phishing attacks are the greatest concern. “As phishing emails continue to be the most prominent vehicle to infiltrate or disrupt systems, I would urge staff to verify every email they receive."

Organizations need to go beyond simply advising employees to “watch out” and implement Security Awareness Training that will educate employees on why they need to care, what they need to be on the lookout for, and how to spot malicious or suspicious emails.

Discover Your Organization’s Exposed Email Attack Surface

Cybercriminals constantly scan the deep web and thousands of breach databases to find exposed employee identities, credentials, and passwords to launch targeted social engineering attacks. Run our free Email Exposure Check Pro (EEC) to safely uncover your at-risk users and see what your organizational structure looks like to an attacker before they exploit it.

Get Your Free Email Exposure Report

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.