The Attack That Doesn't Look Like an Attack
When we picture a cyberattack, we picture someone breaking in — defeating a firewall, exploiting a flaw, brute-forcing a password. The uncomfortable reality behind most modern healthcare breaches is far less cinematic: the attacker logged in. With a real username and a real password, through the front door, looking exactly like a legitimate employee. There was nothing to "detect" at the moment of entry because, technically, nothing was broken. A valid credential was used as designed.
This is why credential theft has become the dominant initial-access vector in healthcare breaches. It sidesteps the entire conversation about patching and perimeter hardening. And the supply of stolen credentials feeding it comes increasingly from a specific, industrialized source: infostealer malware.
What an Infostealer Actually Does
An infostealer is a lightweight piece of malware with one job: harvest credentials and run. It does not encrypt your files or announce itself like ransomware. It quietly scrapes everything useful from an infected device — saved browser passwords, session cookies, authentication tokens, VPN and email credentials, anything that can be turned into access — packages it up, sends it to the attacker, and often deletes itself. The whole operation can be over in seconds, leaving little trace.
People get infected the ordinary ways: a malicious email attachment, a fake software download, a cracked application, a booby-trapped browser extension. Crucially, the infected device is frequently personal — a home laptop or phone an employee also uses to check work email or log into the EHR remotely. That device is outside your managed environment, so your controls never see the theft happen. The credential simply appears, later, in the wrong hands.
The Credential Economy
Here is what makes this an ecosystem rather than a one-off crime. The criminals running infostealers are usually not the ones who attack your practice. They are wholesalers. The harvested credentials — millions of them — get bundled into "logs" and sold on dark-web marketplaces and private channels, sorted and searchable. A ransomware operator who wants into a healthcare target does not need to hack anyone. They search the market for credentials tied to medical or healthcare domains, buy a batch for a trivial sum, and start trying them.
This division of labor is exactly why the threat scales so brutally against small practices. You do not have to be specifically targeted to be victimized. You just have to have a credential sitting in a database somewhere, waiting for someone to filter for "healthcare" and "remote access." We walk through the cleanup side of this in the credential leak response playbook.
Breaking the Pipeline
The good news is that a credential-driven attack has several distinct links, and breaking any one of them disrupts the whole chain:
- Make a stolen password insufficient on its own. This is what multi-factor authentication does, and it is why MFA is the single highest-value control against this entire category. If a purchased credential gets the attacker to a second-factor prompt they cannot satisfy, the credential is worthless. Prioritize MFA on email, remote access, and the EHR above all else.
- Shrink what one stolen credential can reach. An account with access to everything is a catastrophe when stolen; an account scoped to only what that role needs is a contained incident. Least-privilege access turns a stolen login into a limited problem instead of a full breach.
- Find out before the attacker uses it. Stolen credentials usually circulate for a while before they are exploited. Dark-web credential monitoring watches for your domain's credentials appearing in breach dumps and infostealer logs, so you can force a password reset while the stolen one is still just sitting in a database — before it becomes an intrusion.
- Reduce the harvest at the source. Much of this starts with a person clicking something. Ongoing, behavior-focused phishing and security training lowers the infection rate, and clear policies about using personal devices for work access reduce the unmanaged exposure that infostealers feed on.
Why This Belongs in Your Risk Analysis
Credential theft is not a fringe scenario to mention in passing — given the breach data, it belongs as a named, assessed risk in your formal risk analysis, with the controls above documented as your response. OCR's enforcement pattern rewards exactly this: identifying a real, prevalent threat and showing what you did about it. "We recognize credential theft as our leading breach risk, we enforce MFA on all critical systems, we monitor for leaked credentials, and we train against phishing" is a defensible posture. Silence on the threat that causes most breaches is not.
The attacker buying your password is betting that you are relying on that password alone. The entire defense comes down to making that bet wrong.
Related Reading
- Dark-web credential monitoring
- The credential leak response playbook
- Phishing training that changes behavior
- HIPAA breaches in 2026: what happened
Call to Action
Are any of your practice's credentials for sale right now without your knowledge? Schedule a walkthrough to see how HIPAA Security Suite monitors for leaked credentials and enforces the controls that make them useless, or take the 3-minute readiness quiz.