A phishing attack is moving through dental and medical practices across Victoria. We have seen it first-hand on systems we monitor, and it is not slowing down.
There is nothing to buy on this page. Share it with any practice you know.
Why we are publishing this
Phishing is not new. An attack of this kind used to reach the practices we support about once a year.
We have seen several in the last few weeks alone.
That change is the reason this page exists. This is not a general reminder to be careful online. Something specific has shifted, and practices deserve to know what it is.
What is happening
You receive an email from a practice you know. A real practice, a real address, someone your team has corresponded with before. The subject looks like a file share — something like “Smith Dental shared a file with you” — styled to look like a Microsoft OneDrive notice, with an Open Document button.
The practice it came from is real. Their account has been taken over. In almost every case they have no idea it is happening.
That is what makes this one spread. Every practice that clicks becomes the next sender.
It began in dental practices. It is now reaching medical and allied health practices, and other industries beyond healthcare. Anyone in your address book is a target, and you are in theirs.
Two things give it away
It asks you to open the link on a “Desktop or Windows Laptop”
No genuine file share cares what device you use. It asks because the software only runs on Windows.
The timing is often wrong
Several arrived at three or four in the morning. No practice sends referral documents at 3am. The senders are overseas.
The links go to newly registered addresses, often ending in .vu. A new address is registered for each round, so do not rely on recognising a list. Recognise the pattern.
What happens if someone clicks
Remote-control software installs behind a screen that looks like a Windows update. A person overseas then has control of that computer.
Three things follow. They read the mailbox. They take every password saved in the browser. They send the same email to everyone in the address book.
Two points matter more than anything else on this page.
Antivirus does not stop this
What installs is legitimate remote-access software — the same category of tool an IT provider uses to connect to your computers. To the machine, it looks like ordinary software being installed in the ordinary way. There is no virus for antivirus to find.
A clean scan means nothing
Run one of these links through a link checker and it comes back safe. The site shows scanners a harmless decoy page and shows your staff the real one.
If your only checks are antivirus and a link scanner, this attack passes both.
The first line of defence: remove admin access
Everything this attack does depends on being able to install software on the computer.
If the account your team signs into each day is a standard account rather than an administrator account, that install is blocked. The screen asks for a password nobody at the front desk has, and the attack stops there — before anyone has to notice anything is wrong.
Most practices run with administrator rights for a good reason. It gives the team flexibility — installing a driver for a new scanner, updating imaging software, getting on with the day without waiting for someone else to unlock it.
So this is a balancing act rather than a simple fix. The question is not whether that flexibility is worth having. It is how much of it you need on the machines that hold patient records, against what it costs you if one of them is taken over.
Worth asking your IT provider: which accounts actually need administrator rights, and what would it take to move the rest to standard accounts without slowing your team down.
Day-to-day accounts should not be able to install software.
A separate administrator account, used when something genuinely needs installing, keeps most of the flexibility and removes most of the risk. It costs nothing.
It is not a complete answer on its own. An attacker who gets into a mailbox can still read it and still email your contacts. But it stops the most damaging part of this attack, and it works even when someone clicks.
The one rule that beats it
Removing admin rights is the technical defence. This is the one that works at the front desk, in the moment.
Before opening any unexpected shared-file link, even from someone you trust, phone them and ask if they sent it.
Thirty seconds. That is the whole defence.
Do not ask by replying to the email. If their account has been taken over, the person who answers is the attacker.
If someone has already clicked
Speak up straight away. No blame — these emails are convincing, and blaming the person who clicked only means the next one stays quiet.
- Unplug that computer from the network and stop using it.
- Have that machine assessed properly. An antivirus scan on its own is not enough. What it needs depends on what is found — that ranges from targeted clean-up and password resets through to rebuilding the machine.
- From a different computer, change the email password, turn on two-step verification, and sign out all sessions.
- Check the mailbox for forwarding rules or filters nobody created. Hidden rules let an attacker keep reading your mail after a password change.
- Treat every password saved on that machine as taken. Change them, banking first.
- Warn your contacts. They are receiving the same email from your address.
- Report it at cyber.gov.au/report.
- Watch the practice bank account and any invoices.
You can report an incident to the Australian Signals Directorate at cyber.gov.au/report.
What to ask your IT provider
If your provider connects remotely, looks around and reports that they did not find anything, that is not sufficient for this attack. There is nothing for a scan to find.
Ask these six questions directly, and expect a clear answer to each. The first five are about this incident. The last one is about stopping the next.
- Has the affected machine been properly assessed, not just scanned?
- Have mailbox forwarding rules and filters been checked?
- Is two-step verification turned on across all accounts?
- Do everyday accounts still have administrator rights?
- Have the sign-in logs been reviewed?
- Have all machines been checked for unauthorised remote-access software?
A clear answer to all five is what a proper response looks like.
If you work at more than one practice
This affects you wherever you work, whether or not the practice is yours.
If your email stays signed in on a practice computer, or the browser saves your passwords, then anything you have logged into on that machine is exposed when reception clicks one of these. It does not matter that it is not your practice and not your computer.
Turn on two-step verification for your personal email — the code that goes to your phone when you sign in. Log out properly at the end of the day. Do not let practice computers save your passwords. If a practice you have worked at is affected, change your passwords even if nothing looks wrong.
A request to referrers and labs
Attach documents to emails rather than sending download links.
If attachments are how we all normally send things, these links stand out immediately.
What we have seen
We monitor systems across Victorian dental and medical practices. This attack has been attempted against practices we look after on several occasions in recent months. Each time it was detected and stopped before anyone reached patient data.
That is not luck. It is what continuous threat monitoring is for. Antivirus alone would not have caught any of them, because there was no virus to catch.
We are not naming any practice, and we will not. Affected practices are victims, and the right response is a quiet phone call, not publicity.
Credit where it is due
A Melbourne practice owner at Park Rd Dental was hit by this attack and documented it publicly at phishwatch.parkrddental.com.au. Their free, open-source project includes a triage tool, staff training material, a printable poster and a browser extension that flags these emails. Worth a look.
If you have received one of these emails, you can report it through their site. The practice it came from almost certainly does not know, and a quiet phone call is how they find out before it spreads further.
Next steps
This attack travels through address books. It reaches your practice because somebody you correspond with was caught first, and it reaches the next practice because somebody was caught at yours.
That works both ways. Every practice that knows what to look for is one fewer launchpad for the next round. Awareness spreads faster than the attack does, but only if people pass it on.
Send this page to every practice you deal with
Referrers, labs, specialists, the practice down the road. It takes a minute and it protects all of us.
itnode.com.au/advisory
Three things worth doing today:
- Forward this page to the practices you refer to and receive from.
- Print the front-desk poster below and put it where your team opens email.
- Raise it at your next study club or practice meeting. Thirty seconds of explanation stops it spreading further.
Free resources
Free resources
Print these for your practice
No form, no email address required.
- Front-desk poster (PDF)For dental and medical practices. Print it and put it where your team opens email.
- Front-desk poster — medical (PDF)The same notice, worded for medical and allied health practices.
- If you clicked — staff card (PDF)The first five minutes matter most. For the staff room.
- Six questions to ask your IT provider (PDF)A one-page checklist for the practice owner.
If you would like us to check
A free phishing and remote-access check
We check whether your everyday accounts have administrator rights, look for remote-access software nobody installed, review mailbox rules, confirm two-step verification is on, check your sign-in logs, and test that your patient-data backup actually restores.
Twenty minutes. No obligation. No disruption to clinic hours.
We support dental, medical and business clients across Victoria.
Common questions
- How do I know if my practice has been affected?
- Check for remote-access software nobody installed, mailbox forwarding rules nobody created, and unfamiliar sign-ins. If a staff member opened a shared-file link recently and something felt wrong, treat that machine as suspect.
- Will antivirus stop this attack?
- No. What installs is legitimate remote-access software, so antivirus treats it as normal. Detecting it requires monitoring what is running and what it connects to.
- We ran the link through a scanner and it came back clean. Are we safe?
- No. These sites show scanners a harmless page and show your staff the real one. A clean scan proves nothing here.
- A machine was affected. Is a virus scan enough?
- A scan on its own is not enough. What the machine needs depends on what is found, so it has to be assessed case by case — the response can range from a targeted clean-up and password resets through to rebuilding the machine. Whichever it is, treat every password saved on that machine as taken.
- What is the single most effective thing we can do?
- Look at whether the accounts your team signs into each day need administrator rights. This attack has to install software to work, and a standard account cannot. Admin rights exist for good reason — flexibility — so it is a balancing act, but a separate administrator account used only when something genuinely needs installing keeps most of that flexibility and removes most of the risk.
- Does this affect Dental4Windows or EXACT directly?
- The attack targets people rather than practice management software. The risk to your system is what an attacker can do once inside your network using a staff member’s access.
- Is this only affecting dental practices?
- No. It began in dental practices and has spread to medical and allied health practices, and to other industries. It travels through address books, so any practice that corresponds with an affected one is a target.
- What are our obligations if patient data is exposed?
- Patient data is health information under the Privacy Act 1988. Where an eligible data breach occurs, the practice has notification obligations to the OAIC and to affected patients. Speak to your own adviser about your position.
Further reading: Report an incident (cyber.gov.au) · Notifiable Data Breaches (OAIC)
