ADA NSW is reminding members to remain vigilant following reports that the phishing campaign we first alerted members to in March is continuing to affect dental practices across Australia.
These phishing emails are particularly convincing because they are sent from genuine dental practice email accounts that have already been compromised. They often appear to come from someone you know and may ask you to review a shared document or click a link.
If a link is clicked, attackers may gain unauthorised access to your computer or email account, allowing them to send further phishing emails from your practice and potentially access sensitive information.
Before you click – verify first
If you receive an unexpected file-sharing email, even from a trusted colleague or another dental practice, verify it by telephone before opening the link.
Do not rely on replying to the email, as a compromised account may still be under the attacker’s control.
Protect your practice
Please ensure you and your team continue to follow these cybersecurity best practices:
- Do not click unexpected links or download attachments from unsolicited emails.
- Verify unexpected document-sharing requests by calling the sender.
- Never enter passwords after following a link received by email.
- Enable multi-factor authentication (MFA) on email and other critical business systems.
- Keep operating systems, browsers and endpoint protection software up-to-date.
- Use strong, unique passwords for all accounts.
- Review remote access software and ensure only approved tools are installed and secured.
If you think you’ve been compromised
If you believe someone in your practice has clicked a suspicious link or your email account may have been compromised:
- Disconnect the affected computer from the network if possible.
- Contact your IT provider immediately.
- Change your email password from a different, trusted device.
- Enable MFA if it is not already in place.
- Check your email account for any unauthorised forwarding rules or unusual activity.
- Notify colleagues if suspicious emails may have been sent from your account.
- Report the incident through the Australian Cyber Security Centre (ACSC).
Cyber threats continue to evolve, and attacks increasingly rely on convincing people to trust legitimate-looking emails rather than exploiting technical vulnerabilities. A quick phone call to confirm an unexpected document request can prevent a significant security incident.
ADA NSW will continue to monitor this issue and provide members with updates if new information becomes available.