It happens in a split second. A staff member is searching for something on a workstation and the screen fills with a loud warning: "Your computer is infected. Call Microsoft support immediately." There may be a siren, a countdown or a message claiming that resident data is at risk. These are scams, and they work by creating panic. The best defense is a simple script that staff have already practiced.
They are web pages, not messages from your computer's security software. The page is designed to look like a system alert and to make the visitor believe that calling the number is the only option. People who call are connected to a scammer who may ask them to install remote access software, pay for useless services or reveal passwords. In a healthcare setting, a remote connection to a workstation could expose resident information.
Real operating system and security warnings do not display a phone number and do not demand that you call immediately.
Post it where people work and review it at huddles.
Stop. Do not call the number. Do not click anything in the pop-up, including the "close" buttons, which can be part of the trick.
Do not type or share anything. No passwords, no personal details.
Close the browser the safe way. Try to close the window normally. If it will not close, use the keyboard method your IT team has taught you, such as using the task manager to end the browser. If the screen is stuck in full-screen mode, press the escape key or hold the power button as a last resort.
Tell someone. Report it to your supervisor and the IT help desk right away, even if you think you closed it safely.
Do not restore the old tabs. When you reopen the browser, choose to start fresh, not to restore the last session.
If you called, or let someone in, say so immediately. Disconnect the workstation from the network, and tell IT. Nobody will be punished; speed is what matters.
Run a security scan on the computer and check for unfamiliar programs or browser extensions.
Look for remote access tools that were not installed by your IT team.
Clear the browser's notification permissions and reset settings if needed.
Change passwords for accounts used on that device if there is any chance information was entered.
Review whether any resident data was accessible and involve the privacy officer if there was a remote session or data entry.
Look at web filtering logs to find out how the user reached the site.
DNS or web filtering blocks many known malicious sites before they load.
Block pop-ups and notification requests by default, and keep browsers updated.
Staff accounts that cannot install software make it much harder for a scammer to gain a foothold.
Tell staff plainly that IT will never ask them to install remote software unless they have requested help through the normal channel.
Short, real-looking examples work best. A few minutes at a huddle, with a screenshot of a typical pop-up, prepares people better than a long lecture.
How a supervisor responds shapes whether staff report next time. If someone reports a pop-up and gets thanked, others will report too. If they are scolded, the next employee may say nothing, and a real problem will have a head start.
Consider printing a card with three lines: stop, do not call, tell IT, and the help desk phone number and email. Put it near workstations and in break rooms.
UnityCare IT can set up web filtering and browser protections, help you write a one-page response card and provide short training for your staff so that a scary pop-up is a minor interruption.
A helpdesk your staff can call or text when something stops working.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172