{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509"},"incident":{"slug":"2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509","title":"Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients","date":"2025-03-03","date_precision":"day","year":2025,"victim_org":"Arizona Arthritis and Rheumatology Associates","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5509,"threat_actor":null,"summary":"Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.","how_it_worked":"Staff received phishing email designed to look like routine Microsoft 365 account or document notifications and entered their work credentials on an attacker-controlled sign-in page. The trust signals abused were the familiar Microsoft branding and the ordinary rhythm of clinic email, where staff process insurance, referral and scheduling messages all day and open unfamiliar attachments as a matter of course. With valid credentials the attacker signed into the mailboxes and had immediate access to months of patient correspondence. Because the access used legitimate credentials from a normal cloud client, nothing looked malicious until sign-in anomalies were reviewed.","lessons":"Phishing-resistant MFA on clinical email accounts, plus conditional access blocking unfamiliar sign-in locations, would have made the harvested passwords useless.","confidence":"Confirmed","sources":[{"title":"Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents","url":"https://www.hipaajournal.com/arizona-arthritis-rheumatology-associates-mon-health-phishing-attacks/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509"}}