Security advisory

Phishing attack targeting Victorian dental and medical practices

We have seen this first-hand on systems we monitor. This page explains what it looks like, how to check whether your practice has been affected, and what to do if someone has already clicked.

SteevePublished Updated 4 August 2026

A phishing attack is moving through dental and medical practices across Victoria. We have seen it first-hand on systems we monitor, and it is not slowing down.

There is nothing to buy on this page. Share it with any practice you know.

Why we are publishing this

Phishing is not new. An attack of this kind used to reach the practices we support about once a year.

We have seen several in the last few weeks alone.

That change is the reason this page exists. This is not a general reminder to be careful online. Something specific has shifted, and practices deserve to know what it is.

What is happening

You receive an email from a practice you know. A real practice, a real address, someone your team has corresponded with before. The subject looks like a file share — something like “Smith Dental shared a file with you” — styled to look like a Microsoft OneDrive notice, with an Open Document button.

The practice it came from is real. Their account has been taken over. In almost every case they have no idea it is happening.

That is what makes this one spread. Every practice that clicks becomes the next sender.

It began in dental practices. It is now reaching medical and allied health practices, and other industries beyond healthcare. Anyone in your address book is a target, and you are in theirs.

How the phishing attack spreads between practicesA four-step cycle. One practice is compromised when a staff member opens a shared-file link. The attacker takes their address book. The same email then arrives at another practice from a genuine address. If someone there clicks, that practice becomes the next sender and the cycle repeats.1A practice iscompromisedSomeone opens a sharedfile link. Attackers nowcontrol that computer.2The address bookis takenEvery practice they haveever emailed becomesa target.3You receivethe emailFrom a real address, at apractice you know. Theyhave no idea.4If someoneclicksYour practice becomesthe next sender, and itstarts again.Every practice that clicks becomes a launchpad for the next roundHOW IT SPREADS
Why it keeps spreading: every practice that clicks becomes the sender for the next round.

Two things give it away

It asks you to open the link on a “Desktop or Windows Laptop”

No genuine file share cares what device you use. It asks because the software only runs on Windows.

The timing is often wrong

Several arrived at three or four in the morning. No practice sends referral documents at 3am. The senders are overseas.

What the phishing email looks likeAn illustration of the fake file-share email. Three warning signs are marked: the sender is a genuine practice whose account has been taken over, the message was sent at 3.14 in the morning, and it asks the reader to open the link on a Desktop or Windows Laptop.WHAT IT LOOKS LIKEFromSmith Dentalreception@smithdental.com.au3.14 amSmith Dental shared a file with youA document has been shared with you.Please open on your Desktop or Windows Laptop.Open DocumentThis link expires in 24 hours.Illustration — not a real messageThe sender is realTheir account has beentaken over. They donot know.Sent at 3.14 amNo practice sharesreferrals overnight."Desktop or Windows"The software only runson Windows. Nothingelse asks this.
An illustration of the email, with the three tells marked. This is a mock-up, not a screenshot of a real message.

The links go to newly registered addresses, often ending in .vu. A new address is registered for each round, so do not rely on recognising a list. Recognise the pattern.

What happens if someone clicks

Remote-control software installs behind a screen that looks like a Windows update. A person overseas then has control of that computer.

Three things follow. They read the mailbox. They take every password saved in the browser. They send the same email to everyone in the address book.

Two points matter more than anything else on this page.

Antivirus does not stop this

What installs is legitimate remote-access software — the same category of tool an IT provider uses to connect to your computers. To the machine, it looks like ordinary software being installed in the ordinary way. There is no virus for antivirus to find.

A clean scan means nothing

Run one of these links through a link checker and it comes back safe. The site shows scanners a harmless decoy page and shows your staff the real one.

If your only checks are antivirus and a link scanner, this attack passes both.

The first line of defence: remove admin access

Everything this attack does depends on being able to install software on the computer.

If the account your team signs into each day is a standard account rather than an administrator account, that install is blocked. The screen asks for a password nobody at the front desk has, and the attack stops there — before anyone has to notice anything is wrong.

Most practices run with administrator rights for a good reason. It gives the team flexibility — installing a driver for a new scanner, updating imaging software, getting on with the day without waiting for someone else to unlock it.

So this is a balancing act rather than a simple fix. The question is not whether that flexibility is worth having. It is how much of it you need on the machines that hold patient records, against what it costs you if one of them is taken over.

Worth asking your IT provider: which accounts actually need administrator rights, and what would it take to move the rest to standard accounts without slowing your team down.

Day-to-day accounts should not be able to install software.

A separate administrator account, used when something genuinely needs installing, keeps most of the flexibility and removes most of the risk. It costs nothing.

It is not a complete answer on its own. An attacker who gets into a mailbox can still read it and still email your contacts. But it stops the most damaging part of this attack, and it works even when someone clicks.

The one rule that beats it

Removing admin rights is the technical defence. This is the one that works at the front desk, in the moment.

Before opening any unexpected shared-file link, even from someone you trust, phone them and ask if they sent it.

Thirty seconds. That is the whole defence.

Do not ask by replying to the email. If their account has been taken over, the person who answers is the attacker.

If someone has already clicked

Speak up straight away. No blame — these emails are convincing, and blaming the person who clicked only means the next one stays quiet.

  1. Unplug that computer from the network and stop using it.
  2. Have that machine assessed properly. An antivirus scan on its own is not enough. What it needs depends on what is found — that ranges from targeted clean-up and password resets through to rebuilding the machine.
  3. From a different computer, change the email password, turn on two-step verification, and sign out all sessions.
  4. Check the mailbox for forwarding rules or filters nobody created. Hidden rules let an attacker keep reading your mail after a password change.
  5. Treat every password saved on that machine as taken. Change them, banking first.
  6. Warn your contacts. They are receiving the same email from your address.
  7. Report it at cyber.gov.au/report.
  8. Watch the practice bank account and any invoices.

You can report an incident to the Australian Signals Directorate at cyber.gov.au/report.

What to ask your IT provider

If your provider connects remotely, looks around and reports that they did not find anything, that is not sufficient for this attack. There is nothing for a scan to find.

Ask these six questions directly, and expect a clear answer to each. The first five are about this incident. The last one is about stopping the next.

  1. Has the affected machine been properly assessed, not just scanned?
  2. Have mailbox forwarding rules and filters been checked?
  3. Is two-step verification turned on across all accounts?
  4. Do everyday accounts still have administrator rights?
  5. Have the sign-in logs been reviewed?
  6. Have all machines been checked for unauthorised remote-access software?

A clear answer to all five is what a proper response looks like.

If you work at more than one practice

This affects you wherever you work, whether or not the practice is yours.

If your email stays signed in on a practice computer, or the browser saves your passwords, then anything you have logged into on that machine is exposed when reception clicks one of these. It does not matter that it is not your practice and not your computer.

Turn on two-step verification for your personal email — the code that goes to your phone when you sign in. Log out properly at the end of the day. Do not let practice computers save your passwords. If a practice you have worked at is affected, change your passwords even if nothing looks wrong.

A request to referrers and labs

Attach documents to emails rather than sending download links.

If attachments are how we all normally send things, these links stand out immediately.

What we have seen

We monitor systems across Victorian dental and medical practices. This attack has been attempted against practices we look after on several occasions in recent months. Each time it was detected and stopped before anyone reached patient data.

That is not luck. It is what continuous threat monitoring is for. Antivirus alone would not have caught any of them, because there was no virus to catch.

We are not naming any practice, and we will not. Affected practices are victims, and the right response is a quiet phone call, not publicity.

Credit where it is due

A Melbourne practice owner at Park Rd Dental was hit by this attack and documented it publicly at phishwatch.parkrddental.com.au. Their free, open-source project includes a triage tool, staff training material, a printable poster and a browser extension that flags these emails. Worth a look.

If you have received one of these emails, you can report it through their site. The practice it came from almost certainly does not know, and a quiet phone call is how they find out before it spreads further.

Next steps

This attack travels through address books. It reaches your practice because somebody you correspond with was caught first, and it reaches the next practice because somebody was caught at yours.

That works both ways. Every practice that knows what to look for is one fewer launchpad for the next round. Awareness spreads faster than the attack does, but only if people pass it on.

Send this page to every practice you deal with

Referrers, labs, specialists, the practice down the road. It takes a minute and it protects all of us.

itnode.com.au/advisory

Three things worth doing today:

  1. Forward this page to the practices you refer to and receive from.
  2. Print the front-desk poster below and put it where your team opens email.
  3. Raise it at your next study club or practice meeting. Thirty seconds of explanation stops it spreading further.

If you would like us to check

A free phishing and remote-access check

We check whether your everyday accounts have administrator rights, look for remote-access software nobody installed, review mailbox rules, confirm two-step verification is on, check your sign-in logs, and test that your patient-data backup actually restores.

Twenty minutes. No obligation. No disruption to clinic hours.

We support dental, medical and business clients across Victoria.

Common questions

How do I know if my practice has been affected?
Check for remote-access software nobody installed, mailbox forwarding rules nobody created, and unfamiliar sign-ins. If a staff member opened a shared-file link recently and something felt wrong, treat that machine as suspect.
Will antivirus stop this attack?
No. What installs is legitimate remote-access software, so antivirus treats it as normal. Detecting it requires monitoring what is running and what it connects to.
We ran the link through a scanner and it came back clean. Are we safe?
No. These sites show scanners a harmless page and show your staff the real one. A clean scan proves nothing here.
A machine was affected. Is a virus scan enough?
A scan on its own is not enough. What the machine needs depends on what is found, so it has to be assessed case by case — the response can range from a targeted clean-up and password resets through to rebuilding the machine. Whichever it is, treat every password saved on that machine as taken.
What is the single most effective thing we can do?
Look at whether the accounts your team signs into each day need administrator rights. This attack has to install software to work, and a standard account cannot. Admin rights exist for good reason — flexibility — so it is a balancing act, but a separate administrator account used only when something genuinely needs installing keeps most of that flexibility and removes most of the risk.
Does this affect Dental4Windows or EXACT directly?
The attack targets people rather than practice management software. The risk to your system is what an attacker can do once inside your network using a staff member’s access.
Is this only affecting dental practices?
No. It began in dental practices and has spread to medical and allied health practices, and to other industries. It travels through address books, so any practice that corresponds with an affected one is a target.
What are our obligations if patient data is exposed?
Patient data is health information under the Privacy Act 1988. Where an eligible data breach occurs, the practice has notification obligations to the OAIC and to affected patients. Speak to your own adviser about your position.

Further reading: Report an incident (cyber.gov.au) · Notifiable Data Breaches (OAIC)