Cybersecurity Updates

Following are recent cybersecurity reports from Valley’s Information Security team. For additional cybersecurity advisories, please visit the Information Systems’ Cybersecurity page on the intranet.

Thank you for your commitment to being cyber-aware and for helping Valley maintain and safe and secure IT environment.

Holiday Awareness

Cybercriminals take advantage of the holiday season to increase their attacks on companies, particularly healthcare. All Valley employees and Members of the Medical Staff need to be vigilant during these times and use the STAR (Stop, Think, Act, Review) tool when using any of Valley's computer systems, including email.

If you are asked for any of your personal information, User ID, or password, please do not provide it.  Contact the Information Systems Service Desk before providing any personal information.

Please report any unusual activity to the Information Systems Service Desk if you are concerned or if something is unusual in our email, text, or software tools.

Scattered Spider Cybercriminal Group

The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) has warned us about Scattered Spider, a cybercriminal group that targets IT Help Desks. Scattered Spider threat actors are considered experts in social engineering and use multiple social engineering techniques, especially phishing and MFA spamming to obtain credentials, install remote access tools, and/or bypass multi-factor authentication (MFA).

How does Scattered Spider work?

A threat actor:

  1. Poses as an IT/Help Desk staff using phone calls or SMS messages.
  2. Directs employees to run unapproved remote access tools. BOMGAR is the only Valley approved remote access solution.
  3. Poses as IT or Help Desk staff to convince employees to share their one-time password or MFA code.
  4. Sends repeated MFA notification prompts asking employees to press ‘Accept.’
  5. Uses voice communication to convince IT Help Desk personnel to reset passphrases and/or MFA tokens of legitimate employees.

Ways to Stay Safe

  1. Be suspicious of potential phishing emails or SMS messages with a high sense of urgency, such as ‘Reset Password’ or ‘Account expiring.’
  2. Never provide sensitive information, such as your Valley credentials or MFA code.
  3. Think twice before responding to an email coming from the outside.
  4. Do NOT install or allow others to install unapproved remote access tools.
  5. STOP. Reach out to the Service Desk directly by calling 201-447-8100.
  6. Do not ‘approve’ MFA prompts unless you’re the one requesting access.
  7. Use Valley’s HRO tools – STAR: Stop, Think, Act, Review.
  8. If you think you’ve been victim of these phishing emails, report it immediately using the Phish Alert Button.