A phishing scam impersonates patient portal notices to trick people into revealing their login credentials and installing malware. The scam uses emails that resemble legitimate alerts, including messages about lab results, and directs victims to fraudulent pages or downloads designed to compromise devices.

Outlets describe the campaign as aimed primarily at Windows users, with instructions or links that can steal usernames and passwords and lead to infection. While the exact infrastructure and methods can vary between reports, the core mechanism is consistent: the emails imitate real portal communications closely enough to appear credible, then move the victim toward credential harvesting and malicious payloads.

Both sources emphasize that the danger includes both account takeover and device compromise. The reports focus on the scam’s use of common social-engineering tactics and its targeting of health-related account systems, where victims may be more likely to click links quickly. Neither source indicates the existence of a single responsible organization, instead describing the scam as a broader phishing operation distributed across multiple regions.