FBI Raises Alarm About OAuth Consent Phishing Activity
The Federal Bureau of Investigation (FBI) has issued a warning about ongoing phishing activity involving a sophisticated technique known as OAuth consent phishing. Since late 2025, the FBI has observed malicious cyber actors using OAuth consent phishing in targeted attacks on prominent individuals, their family members, and personal acquaintances to gain persistent access to their accounts.
Similar to other forms of targeted phishing, the campaign involves impersonation of a trusted entity and tricks the victim into granting access to their account; however, this approach does not require the victim to disclose their username and password. The technique relies on OAuth, a commonly used authorization framework that allows websites and web applications to request access to a user’s account on another application, without exposing their login credentials.
With OAuth consent phishing, an attacker creates a malicious application and registers it with a legitimate OAuth provider. The application is configured with high-level privileges, such as the ability to access contacts, read and write emails, send emails on the user’s behalf, and more. The attacker then contacts the targeted individual via email or text and attempts to trick them into initiating the consent process.
In this campaign, the attackers typically impersonate publicly known personalities, government officials, journalists, and other high-profile individuals via a commercial messaging application (CMA). For instance, the individual is invited to take part in an event and must first verify their identity using the malicious but seemingly legitimate application.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
If the victim responds, they are presented with a legitimate permission request screen, such as for Microsoft 365, Google, or another legitimate cloud service. If the victim approves the request by clicking Allow, they provide their consent to the legitimate cloud service, which authorizes the malicious application to have the stated permissions through the provider’s authorization mechanism. The attacker is able to perform a range of malicious activities and access sensitive data without having to obtain the user’s password, and the technique bypasses multifactor authentication controls.
In practice, many users will not be aware that they have been successfully phished and will take no action. Should the victim smell a rat and change their password after granting access, the OAuth authentication token remains valid after the password change and will continue to provide the attacker with the previously granted permissions. The permissions must be revoked by removing the malicious app via the victim’s security settings.
The FBI advises users to be wary of this form of phishing and of any communications from unfamiliar phone numbers, accounts, or senders not in their contact list. Before taking any action in response to an unsolicited communication, users should first verify the identity of the sender and should only grant authorization to trusted applications. Even when the application is trusted, the requested permissions should be carefully assessed.
The post FBI Raises Alarm About OAuth Consent Phishing Activity appeared first on The HIPAA Journal.
Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider – The HIPAA Journal
Wellstar Health System & Cone Health Settle Pixel Lawsuits
Settlements have been agreed to resolve class action lawsuits against Wellstar Health System and Moses H. Cone Memorial Hospital Operating Corporation (Cone Health). The lawsuits stem from the defendants’ use of pixels and other website tracking tools, which are alleged to have resulted in impermissible disclosures of patient data to third parties such as Meta and Google.
Wellstar Health System Pixel Settlement
Wellstar Health System, a Marietta, Georgia-based health system with more than 400 care locations in the state, was sued over its use of tracking tools on its website that are alleged to have resulted in the disclosure of personally identifiable information and protected health information to third parties such as Alphabet Inc. (Google) and Meta Platforms (Facebook), without website users’ knowledge or consent.
The first lawsuit was filed on April 23, 2024, and an amended complaint was filed on August 2, 2024, adding three additional plaintiffs. The lawsuit – Doe v. Wellstar Health System, Inc. – is pending in the United States District Court for the Northern District of Georgia. The lawsuit asserted claims for invasion of privacy – intrusion upon seclusion, breach of fiduciary duty, negligence, negligence per se, breach of implied contract, breach of express contract, unjust enrichment, and violations of the Electronic Communications Privacy Act. The defendant denies all claims and contentions in the lawsuit and maintains that there was no wrongdoing. A settlement was agreed to by all parties to avoid the time, expense, and uncertainty of a trial and related appeals.
Wellstar Health System has agreed to establish a $4,500,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remainder of the settlement fund will be divided equally among all class members who submit a valid claim. The class consists of individuals whose personally identifiable information and/or protected health information was disclosed to third parties via the tracking tools between February 19, 2020, and July 22, 2026. Any remaining settlement funds, such as from uncashed checks, will be distributed to the Good Samaritan Health Center of Cobb.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The deadline for objection and opting out is October 26, 2026. Claims must be submitted by November 10, 2026, and the final fairness hearing has been scheduled for December 1, 2026.
Moses H. Cone Memorial Hospital Operating Corporation (Cone Health) Pixel Settlement
Greensboro, North Carolina-based defendants The Moses H. Cone Memorial Hospital Operating Corporation, d/b/a Cone Health, and The Moses H. Cone Memorial Hospital, d/b/a Cone Health, were sued over the use of tracking tools such as pixels, which had been added to their public website without the knowledge or consent of website users. The lawsuit alleged that the use of the tracking code resulted in disclosures of users’ confidential health information and protected health information to third parties such as Alphabet Inc (Google) and Meta Platforms (Facebook).
The lawsuit, Singh v. The Moses H. Cone Memorial Hospital Operating Corp., et al., is pending in the United States District Court for the Middle District of North Carolina. The lawsuit asserted claims for violation of the Electronic Communications Privacy Act, breach of express contract, breach of implied duty of good faith and fair dealing, breach of implied contract, negligence, breach of fiduciary duty, and unjust enrichment. The defendants maintain that there was no wrongdoing; however, a settlement was agreed by all parties to avoid the costs, delays, and uncertainties of continued litigation.
Cone Health has agreed to establish a $1,765,000 settlement fund, which will be used to pay reasonable attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. After those costs have been deducted, the net settlement fund will be distributed equally among the class members. The value of each cash payment will depend on the number of valid claims received.
The settlement class consists of all individuals who accessed the MyChart patient portal on the defendants’ website between September 1, 2016, and November 3, 2022, as well as any individual who completed a submission form on the defendants’ website between the same dates. The settlement has received preliminary approval from the court. The deadline for opting out and objecting to the settlement is October 5, 2025. Claims must be submitted by October 5, 2026, and the final fairness hearing has been scheduled for November 5, 2026.
The post Wellstar Health System & Cone Health Settle Pixel Lawsuits appeared first on The HIPAA Journal.
Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider
Two ransomware groups have claimed attacks on the home health care provider Interim Healthcare. Data breaches have been announced by Crystal Coast Pain Management, Golden State Orthopedics & Spine, Gardiner Family Chiropractic, and BestCare Treatment Services.
Interim HealthCare of Oklahoma City
Interim HealthCare, a home healthcare provider operating in 40 U.S. states, has been added to the data leak sites of two ransomware groups. The first listing was added to the Genesis ransomware group’s data leak site on August 10, 2026. Genesis claimed to have exfiltrated data in the incident and threatened to publish it if the ransom was not paid. Genesis claims the stolen data relates to Interim Healthcare of Oklahoma and Tulsa, and that 1TB of data was exfiltrated, including medical records, healthcare data, personal data, patient lists, clinical data, and company data. While a list of the compromised files was added to the data leak site, the data allegedly stolen has yet to be published.
Then on August 21, 2026, a second ransomware group listed Interim HealthCare as one of its victims. Anubis claims to have exfiltrated 530 GB of data in the attack, including “financial information about franchisees, details of internal and external audits, discussions of operational issues, as well as memoranda covering all kinds of day-to-day business matters.” Samples of the stolen data were added to the listing, and the stolen data has been published, indicating the ransom was not paid.
While Interim HealthCare has yet to confirm the validity of either claim, Interim HealthCare of Oklahoma City, Inc. reported a network server hacking incident to the HHS’ Office for Civil Rights on July 31, 2026, using a placeholder estimate of 500 affected individuals.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Crystal Coast Pain Management
Crystal Coast Pain Management in North Carolina, a division of East Carolina Anesthesia Associates ECAA), has started notifying patients that some of their personal and protected health information was obtained by an unauthorized third party in a cybersecurity incident earlier this year.
Suspicious network activity was identified on or around January 11, 2026, and third-party digital forensics and cybersecurity experts were engaged to investigate the activity. On April 20, 2026, it was determined that files containing patient information had been copied by the attackers. The file review was completed on June 24, 2026, when it was confirmed that the stolen data included first and last names, dates of birth, medical information, and Social Security numbers.
The cybersecurity experts confirmed the security of its network; however, as a precaution, all affected systems were wiped and rebuilt, and additional security measures have been implemented. No evidence has been found to indicate any misuse of the affected data, but as a precaution, the affected individuals have been offered single-bureau credit monitoring, credit report, and credit score services. A ransomware group called Devman 2.0 claimed it was behind the attack.
Golden State Orthopedics & Spine
Golden State Orthopedics & Spine (GSOS), an orthopedics practice with 13 locations in the San Francisco Bay Area in California, has announced a recent cybersecurity incident. Suspicious network activity was identified on July 2, 2026, and a third-party team of forensics experts was engaged to assist with the investigation and determine the nature and scope of the activity.
GSOS confirmed that its network had been accessed by an unauthorized third party, who may have viewed or obtained files containing patient information. The data review confirmed that the exposed data included first and last names, addresses, dates of birth, Social Security numbers, health insurance information, and medical diagnosis information.
The review of the affected data is ongoing, and the number of affected individuals has yet to be disclosed. GSOS is reviewing its data security policies, procedures, and practices and is taking steps to prevent similar incidents in the future. This appears to have been a ransomware or data theft and extortion incident. A ransomware group called Brain Cipher claimed responsibility for the attack, in which it alleged that 150 GB of data was stolen.
Gardiner Family Chiropractic
Gardiner Family Chiropractic, a chiropractic clinic in Gardiner, Maine, has notified the HHS’ Office for Civil Rights about a network server hacking incident that has affected up to 5,000 patients. Suspicious activity was identified within its computer network on July 17, 2026. An investigation was launched, which confirmed unauthorized network access and the exposure of patient data. Data potentially compromised in the incident includes names, contact information, birth dates, health information, and health insurance/Medicaid information.
According to the substitute breach notice, this was a ransomware attack involving file encryption and data theft. A ransom demand was received; however, the attack was blocked, and the ransom was not paid. The Interlock ransomware group claimed responsibility for the attack. Gardiner Family Chiropractic has taken several steps in response to the attack to strengthen security. In addition to wiping the affected devices and purchasing new computers for its employees, security policies, procedures, and practices have been reviewed, additional security measures have been implemented, and special training has been provided to its workforce on ransomware.
BestCare Treatment Services
BestCare Treatment Services, Inc., an Oregon-based behavioral healthcare provider, has experienced a data security incident involving unauthorized access to parts of its network containing patient information. Unauthorized network activity was identified on June 15, 2026, and a third-party cybersecurity firm was engaged to assist with the investigation and confirm the security of its network.
The investigation confirmed that files had been exposed containing names, dates of birth, contact information, demographic information, medical information, and other patient identifying information. Notification letters were mailed to the affected individuals on August 10, 2026. The data breach was recently reported to the HHS Office for Civil Rights as affecting 4,216 individuals.
The post Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider appeared first on The HIPAA Journal.
