15/08/2026
IMPORTANT NOTICE about and mailicious email.
I got a call to help an organization with their email being hijacked.
They got an email from a patient and clicked on the link.
They were not locked out, but - the bad folks create an admin account, the demoted this account. So in effect the access is lost. They change all the MFA stuff. So you can get in but you change any thing or look at things because you can authenticate.
And they started to send out email to folks with the same information.
I am going to share the body of the email. I removed the link so it where it would be doesn't work. But the link takes you to Adobe.com and then utilizes a resource connection to activate whatever they did to harvest credentials. I don't know the full extent of what that does other than takes email credentials.
A few things to pay attention to - the link looks like it is going to a PDF.
The company name is repeated 3 times in the body and once in the subject line. In hind sight, who composes and email like this but this is exactly why applications and accounts need to reviewed for suseptability.
New Submission [company name].pdf
Please see the attached New Submission [company name] file.
Thanks & Regards,
[company name]
The first line is the link and replace company name with anything.
This particular attack seems to bypass basic security and once they are in they just keep going.
So please pay attention to the links and what you clicking on.
BTW - Adobe was completely useless for support, I was trying to explain to them what was going on so they could kill the account and document but they just don't understand and could never get them to escalate this into their security group.
Microsoft is about as helpful as Adobe, again there is a language barrier and this doesn't follow their script so they try to mash it into that.
Be careful out there.