Patients across the United States are being targeted by a new phishing scheme that mimics the widely used MyChart portal from Epic. The fake emails look like routine notifications about lab results or doctor messages, but they lead to counterfeit login pages that capture usernames and passwords and can even install malware on Windows computers.
How the scam works
Scammers copy the look and code of the real MyChart site, then send messages that say, “Your recent results are ready.” The email includes a button that redirects to a bogus sign‑in page. When a user enters their credentials, the attackers obtain the login information.
In one variant, after a victim signs in, the fake site displays a fabricated medical record and a pop‑up claiming an “AI‑powered review” found critical patterns in blood work. The page then urges the user to complete a “human verification” step. The instructions tell Windows users to press the Windows key + R, paste content from the clipboard, and press Enter – a command that opens the Windows Run box and executes malicious code, installing malware on the computer.
Another version offers a bogus “2026 Medicare Health Kit” or “Senior Health Package.” After clicking the link, users are taken through unrelated advertising sites to a fake MyChart‑branded survey with a countdown clock. The site claims the kit is free but asks for a shipping fee, then collects personal information and credit‑card details. No kit is ever shipped.
Protecting yourself
Because legitimate MyChart messages often arrive the same day as these scams, it’s crucial to verify any unexpected alerts. Open the MyChart app directly, use a saved bookmark, or navigate to the provider’s official website rather than clicking buttons in emails. Check the full sender address – a display name of “MyChart” can be spoofed.
MyChart will never ask you to run keyboard shortcuts or download executable files to view results. If you see such instructions, close the page immediately.
Enable two‑step verification (2FA) on your MyChart account. The extra check, whether via a code or an authenticator app, can block unauthorized access even if a password is compromised. Consider using passkeys, which reduce reliance on reusable passwords.
Use a reputable password manager to generate unique, strong passwords for each account. Reusing passwords across sites can turn a single breach into a larger problem.
Maintain up‑to‑date antivirus software and keep Windows and browsers patched. Modern security tools can flag malicious downloads and suspicious websites before they cause harm.
For further guidance on spotting phishing attempts, see the CyberGuy LIVE replay and checklist at CyberGuyLive.com.
Original reporting: Fox News (HLL/CB) — read the source article.