Emergency Guide: How to Contain a Phishing Campaign That Harvested Your Clinic’s VPN Credentials Overnight
Immediate Actions
Stabilize and activate your response
Treat this as a VPN Credential Compromise affecting patient care operations. Activate your Incident Response Plan, appoint an incident lead, and use an out-of-band channel (phone/secure chat) for coordination. Set clear objectives: stop attacker access, protect clinical systems, and preserve evidence.
First 15 minutes
- Block the phishing domain, sender, and URLs at email, DNS, and web filters; immediately quarantine matching messages.
- Disable or pause new VPN logins; force-logoff all active VPN sessions from the concentrator, then re-enable access only for essential staff if care would be disrupted.
- Place a temporary change freeze on non-IR work and start an incident log to record actions and timestamps.
- Notify executive leadership, clinical operations, privacy/compliance, and your SOC/MSSP.
First hour
- Require Multi-Factor Authentication for any VPN or remote access not already enforcing it; prohibit SMS codes and enable number-matching or FIDO2 where possible.
- Reset passwords for all users who received or interacted with the phish; immediately rotate privileged and VPN appliance admin credentials.
- Revoke refresh tokens and remember-device states from your identity provider; invalidate VPN session caches and RADIUS/LDAP tokens.
- Isolate endpoints of known clickers via EDR; capture volatile data and preserve logs.
Preserve evidence
Enable full logging on VPN, identity, and email systems. Export and preserve authentication logs, message traces, and firewall telemetry. Do not wipe machines unless necessary for safety; collect images or triage data first.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Incident Assessment
Establish the timeline and entry points
- Identify when the phishing campaign began, which lures or brands were abused, and delivery paths (external, vendor spoof, or compromised account).
- List recipients, open/click times, and any credential posts to the phishing site.
Identify compromised VPN credentials
- Correlate VPN concentrator and IdP logs for post-phish authentications, especially after-hours or from unfamiliar ASN/countries.
- Flag “impossible travel,” logins from unmanaged devices, failed-then-success patterns, and sudden MFA device enrollments.
- Cross-check AD/role changes, new mailbox rules, and privilege escalations following VPN sign-ins.
Scope potential impact
- Map what VPN-accessible resources the accounts could reach (EHR, file shares, PACS, billing, AD, RDP, SSH).
- Run targeted Network Traffic Analysis for lateral movement, data staging, or unusual egress from VPN IP pools.
- Assign a risk rating to drive containment depth and clinical continuity decisions.
Containment Measures
Identity and access controls
- Mandate Multi-Factor Authentication for all remote access; prefer phish-resistant methods (FIDO2/WebAuthn) and disable legacy protocols.
- Apply emergency Access Control Policies: geo-block countries not used by staff, restrict to compliant/managed devices, and require reauthentication for privileged actions.
- Remove affected users from VPN groups until cleared; apply just-in-time elevation for admins only when necessary.
VPN-level controls
- Terminate all sessions; rotate any shared secrets, local VPN accounts, and API keys associated with the concentrator.
- Temporarily limit VPN access to critical subnets; disable split tunneling and enforce least-route access.
- Ensure logging at maximum verbosity on the concentrator and upstream firewalls.
Endpoint and email controls
- EDR-isolate clicker endpoints; remove malicious browser extensions, remote tools, or persistence if present.
- Search and purge phishing messages tenant-wide; disable autoforwarding and suspicious inbox rules.
- Block command-and-control destinations discovered during analysis.
Data protection safeguards
- Throttle or temporarily block external file shares, SFTP, or cloud sync from VPN IP space if exfiltration is suspected.
- Increase DLP sensitivity on EHR exports and billing reports during the incident window.
Communication Procedures
Internal notifications
- Brief executives, clinical operations, and the privacy officer with clear status, risks, and expected impacts to scheduling or telehealth.
- Coordinate with facilities/biomed if any networked medical devices could be reachable via VPN.
Staff guidance
- Send an out-of-band alert with explicit actions: password reset by a set deadline, MFA re-enrollment steps, how to report suspicious messages, and what not to do.
- Provide a staffed help channel for clinicians to minimize disruption to patient care.
External coordination
- Engage your SOC/MSSP, email and VPN vendors, EHR provider, and critical third parties whose access may be affected.
- Work with privacy/compliance on regulatory duties; initiate a HIPAA risk assessment if ePHI exposure is plausible.
Documentation
- Maintain an incident diary with decisions, commands executed, indicators blocked, and communications issued.
- Preserve evidence chains for any forensic artifacts collected.
Recovery Steps
Restore trust in identity
- Reset passwords for all users in scope and re-enroll MFA with stronger methods; revoke all refresh tokens and device trusts.
- Audit and clean privileged groups; implement just-enough-admin and approval workflows for elevation.
Harden VPN and supporting systems
- Apply vendor fixes and firmware updates as part of Security Patch Management; remove deprecated cipher suites and protocols.
- Rotate certificates/PSKs where applicable; enforce device compliance checks and per-app tunneling for high-risk apps.
Endpoint remediation and validation
- Run full EDR scans, remediate findings, and reimage any host with high-confidence compromise.
- Validate that no persistence, new local admins, or rogue services remain.
Threat hunting and assurance
- Hunt for attacker techniques: VPN-to-AD changes, mailbox rule creation, RDP usage, and data staging paths.
- Keep heightened monitoring for at least two credential-rotation cycles.
Lessons learned
- Update your playbooks, tuning rules, and Access Control Policies; schedule a tabletop to rehearse the revised steps.
- Capture metrics: time to revoke sessions, time to reset credentials, and mean time to containment.
Prevention Strategies
Programmatic Phishing Detection
- Combine user training with modern email controls (attachment/link rewriting, anomaly detection, and brand spoofing protection).
- Run routine simulations and provide targeted coaching for roles at higher risk (front desk, billing, leadership).
Stronger Multi-Factor Authentication
- Adopt phish-resistant factors (FIDO2 security keys) for admins and remote users; enable number matching and geo/IP context checks.
- Block legacy authentication and enforce device-bound credentials where feasible.
Tighten Access Control Policies
- Apply least-privilege roles, conditional access by device posture and location, and time-bound access for contractors and vendors.
- Segment VPN access by role and application, minimizing lateral movement risk.
Security Patch Management
- Establish monthly patch cadences with an emergency window for critical updates to VPN appliances, identity systems, and EDR.
- Continuously verify firmware and OS levels on remote endpoints that connect to the clinic’s network.
Monitoring and rehearsals
- Centralize logs, enable actionable alerts, and perform continuous Network Traffic Analysis for early detection.
- Test your Incident Response Plan through quarterly tabletops and annual red/blue exercises.
Swift containment, disciplined communication, and rigorous recovery will protect patient care and data. Use this emergency guide to drive decisive action now, then institutionalize the improvements so the next attempt is detected and stopped early.
FAQs.
What are the first steps to contain a phishing attack?
Block the phishing domain and quarantine matching emails, terminate all VPN sessions, enforce Multi-Factor Authentication, reset passwords for exposed users, revoke tokens, and isolate endpoints that interacted with the lure. Activate your Incident Response Plan, coordinate via an out-of-band channel, and start preserving VPN, identity, and email logs immediately.
How can we identify compromised VPN credentials?
Correlate VPN and identity logs for post-phish logins from new locations or unmanaged devices, “impossible travel,” sudden MFA enrollments, and mailbox rule creation. Look for successful authentications without expected MFA challenges, spikes in failed-then-success sequences, and access to sensitive resources shortly after the phishing event. Augment with Network Traffic Analysis to spot lateral movement or data staging.
What communication should be sent to staff after a phishing incident?
Send an out-of-band notice summarizing what happened (without sensitive details), the immediate actions required (password reset, MFA re-enrollment, reporting instructions), the deadline, and where to get help. Include clear do’s and don’ts, remind staff not to click or forward suspicious messages, and confirm that clinical operations should follow established downtime or continuity procedures if directed.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.