A Phishing Link at a Perth Medical Practice Becomes an Account Takeover

A representative walkthrough of how we respond when a staff member at a Perth medical practice is phished and their Microsoft 365 account is taken over — contain, assess breach exposure, and harden patient data. From Computer Mechanics, Perth IT specialists since 1997.

AmirAmir · Cloud System Engineer
14 August 2026
5 min read
Cybersecurity
Microsoft 365
Phishing
Healthcare
Perth Business

This is a representative scenario, not a specific client. It's a composite of the kind of account-takeover response we handle, written to show how we work and why. Real incidents vary, and the details here are deliberately general.

A staff member at a Perth medical practice gets an email that looks like a Microsoft "your mailbox is full" notice, clicks through, and enters their Microsoft 365 password on a login page that looks exactly right. It wasn't Microsoft — it was a phishing page, and the attacker now has a working password. Within minutes a single phished login can become a full account takeover: mailbox rules quietly redirecting mail, messages sent as the staff member, and — most seriously in healthcare — potential exposure of patient information. Here's how we respond, and why practices handling health data need more than a password.

How it starts: one convincing login page

Modern phishing doesn't look like the clumsy scams of a decade ago. The page is pixel-perfect, the email is urgent but plausible, and busy clinical staff are exactly the kind of distracted, trusting target attackers rely on. The click itself isn't the failure — it's what the environment lets happen after the click that decides how bad this gets. (Our guide on how to identify phishing emails is what we walk teams through to cut the click rate in the first place.)

First: lock the attacker out

The moment we're told an account may be compromised, containment comes before investigation:

  • Reset the password and revoke every active session, so an already-open session can't keep working while we clean up.

  • Re-register multi-factor authentication so the attacker's device is kicked out and only the real user can get back in.

  • Hunt for hidden mailbox rules. The classic account-takeover move is a rule that auto-deletes or hides the attacker's own activity and forwards a copy of incoming mail outside the practice. We remove any we find and check every other account for the same.

Assess: what did they actually touch?

Containment stops the bleeding; now we work out the scope, because in healthcare that determines your legal obligations:

  • What was in that mailbox and OneDrive? Referrals, results, patient correspondence, scanned documents — we establish what the account could reach.

  • Did they send anything, or set up forwarding? Outbound messages and forwarding rules tell us whether the attack was spreading or exfiltrating.

  • Did they reach anything beyond email — SharePoint, the practice-management system, other linked services?

Is this a notifiable data breach?

This is the question a medical practice can't skip. If patient information was accessed or exposed, the incident may trigger reporting under the Privacy Act and the Notifiable Data Breaches scheme, and there may be obligations around My Health Record. We help the practice assess this honestly and quickly — the goal is to make the right call on notification with clear evidence, not to guess. (We cover the shape of this in our FAQ on what happens after a breach.)

Hardening so it can't happen again

A phished password should be a non-event, not a crisis. What we put in place so it is:

  • MFA on every account, phishing-resistant for clinical and admin staff. A stolen password alone then opens nothing.

  • Conditional access so only known, compliant devices can reach patient data — a login from an unexpected location or unmanaged device is blocked or challenged.

  • Email filtering and impersonation protection to stop the phishing email landing at all.

  • Audit logging and alerting so a suspicious sign-in raises a flag early, instead of being discovered weeks later.

  • Staff training aimed at the reality of a busy practice, not a generic template.

How we help Perth healthcare

Medical, dental and allied-health practices carry some of the strictest data obligations of any small business, which is why we take a dedicated approach to IT for Perth healthcare: the layered security above, sized to a clinical setting and aligned to the RACGP and AHPRA expectations around protecting patient data. The support model is simple — we own the IT around your clinical software and keep the doors locked, so a moment's distraction at reception doesn't become a data breach.

If a login at your practice has just done something it shouldn't, treat it as urgent: call us on (08) 9325 1196 or get in touch. We've kept Perth businesses' data secure since 1997.

Amir
Written by
Amir
Cloud System Engineer · 10+ years in IT

Amir is a Cloud System Engineer with over a decade of experience across server management, networking, cloud solutions and virtualisation. He designs and secures the Microsoft 365, Azure and network environments that Perth businesses rely on, turning complex infrastructure into scalable, efficient solutions.

Meet the IT Support Perth team →
Amir
14 August 2026
5 min read
Cybersecurity
Microsoft 365
Phishing
Healthcare
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

A Fake Invoice Nearly Gets Paid at a Perth Accounting Firm: How We Respond

A representative walkthrough of how we respond when a Perth accounting firm spots a business email compromise (fake-invoice) scam — stop the payment, trace the intrusion, and close the hole for good. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

A Perth Business's Server Dies — and the Backup Hadn't Run in Weeks

A representative walkthrough of how we recover a Perth business after a server failure — and what we do when the backup everyone trusted had silently stopped running. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Hackers Are Scanning Every Business Website for a Way In: ACSC Alert Explained

The ACSC has warned that hackers are scanning websites worldwide, including many Perth small businesses, for outdated CMS software and plugins to plant hidden backdoors. Here's what to check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do
Cybersecurity
Patch Management

Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do

Microsoft's August 2026 security update patched a Windows flaw that was already being exploited to seize full control of machines, plus a critical SharePoint hole. Here's what Perth businesses need to check this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/12/2026
Call us