What happened
West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.
How the deception worked
Employees were sent phishing messages that imitated routine internal or Microsoft 365 notifications and were induced to enter their work credentials on a lookalike sign-in page. Hospital email is a high-yield target because clinical and billing staff exchange large volumes of patient-identifying correspondence with outside parties, so an unexpected message about a shared document or account issue does not stand out. With the harvested credentials the attacker signed in as the employee and had access to the full mailbox history. The activity resembled normal user logins, which is why detection depended on account anomaly review rather than malware alerts.
The control that would have caught it· our reading, not a claim from the sources
Enforcing phishing-resistant MFA and automatically expiring or archiving mailbox contents containing PHI would have both blocked the login and limited what a single compromised account exposed.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.