[REVISION HISTORY]
MyChart patient portal phishing campaign
Updated 1 time since CLSTR started tracking revisions of this situation.
What changed
2026-09-01 10:35 UTC → 2026-09-01 15:52 UTC ·
added
removed
A widespread phishing campaign has emerged targeting users of the MyChart patient portal, owned by Epic Systems. The campaign utilizes deceptive emails, text messages, and phone calls that mimic legitimate MyChart branding to trick individuals into clicking malicious links or disclosing sensitive personal and financial information. Scammers often use tactics such as promising free health packages, Medicare-related benefits, medical test results, or loyalty rewards to create a sense of urgency. The primary objective of these attacks is to install malware on victims' devices or facilitate identity theft. Both St. Luke’s University Health Network and Pennsylvania officials issued warnings regarding the scam, noting that the MyChart platform itself has not been compromised. Instead, cybercriminals are exploiting the brand's high recognition. The scale of the campaign is significant, with reports indicating approximately 190 million MyChart users worldwide could be targeted. In the United States, various hospitals, including those in Florida, have issued alerts to their patients. Epic Systems has warned that the fraudulent communications are often disguised as medical test results or health rewards to exploit the high level of brand trust associated with the platform, which is used by 44 percent of the healthcare market.
Versions
- 2026-09-01 15:52 UTC MyChart patient portal phishing campaign
- 2026-09-01 10:35 UTC MyChart patient portal phishing campaign
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.