Scammers impersonate MyChart to steal credentials and spread Windows malware
Criminals are sending fake MyChart emails that mimic real patient-portal alerts, capturing login details and installing malware on Windows PCs.
A wave of phishing attacks is targeting users of Epic's MyChart patient portal by sending emails that appear to be official notifications of test results. The messages contain branding identical to the real portal and link to a counterfeit login page that captures credentials. After signing in, victims see fake medical data, often framed as critical, to pressure them into further action.
Certain variants then direct Windows users to open the Run dialog and execute a copied command or download a file named Full_Analysis_Report.exe, which can install malware. Health organizations including Penn Medicine and the office of Pennsylvania Attorney General Dave Sunday have issued alerts, noting that the MyChart platform itself has not been breached. Experts advise patients to access MyChart directly via trusted URLs, verify sender addresses, avoid running any commands, and enable two-factor authentication.
Why it matters
The scam exploits trusted health communications to steal credentials and infect computers, putting personal data and security at risk.
In this story
