Holiday Shopping Season Phishing: What Care Staff Should Watch For

The weekend after Thanksgiving is a busy time for online shopping, and for criminals who send fake emails and texts. Staff are more likely to check personal accounts on work devices, tap on delivery notices, and click on offers, often on a phone between tasks. For a care facility, one clicked link on a shared workstation can become a problem for resident records.

This post covers the lures you are most likely to see this season, what staff should look for, and what leadership can do so that one mistake does not become a breach.

Common holiday lures

Attackers reuse familiar themes because they work. Expect variations on these.

Package delivery problems. A text or email says a parcel could not be delivered and asks you to confirm an address or pay a small fee.

Gift card requests. A message that appears to come from the administrator or a department head asks someone to buy gift cards "for the staff party" and send the codes.

Fake order confirmations. A receipt for an expensive item you never ordered, with a link or phone number to "cancel" it.

Shipping and payroll notices. Messages about direct deposit changes, bonus payments or holiday schedules that ask staff to log in on a lookalike page.

Charity appeals. Giving-season requests from organizations that do not exist.

Account alerts from retailers and banks. "Your account has been locked" notices that lead to fake login pages.

Red flags to teach

Short, memorable rules work better than long policies.

Urgency or pressure. Real organizations rarely demand immediate action under threat.

Unexpected requests for money, codes or passwords. Especially gift cards.

Sender mismatch. The display name looks right, but the address behind it is a random or slightly misspelled domain.

Links that do not match. On a computer, hover over the link before clicking. On a phone, press and hold to preview the address.

Anything asking you to log in from a message. Go to the website directly by typing the address or using a saved bookmark.

Requests that skip normal process. Payroll, vendor payments and access changes should follow the usual approval path.

What to do if someone clicks

Make it easy and safe to report. The faster IT hears about a click, the less damage it does.

Disconnect the device from the network if you can, or tell IT immediately.

Do not try to clean it up or delete evidence.

If a password was typed in, change it from a different device and tell IT so other sessions can be ended.

Note the time, the message, and what was done. These details help the investigation.

Make clear that nobody will be punished for reporting quickly. People who fear blame wait, and waiting is what makes incidents bigger.

Controls that reduce risk

Staff awareness is one layer. Leadership can add others.

Email filtering

Make sure your email platform filters spoofed messages and scans links and attachments. Review settings rather than assuming defaults are strong.

Multi-factor authentication

A stolen password is much less useful when a second factor is required. Prioritize email, remote access and any system holding resident information.

Separate personal browsing

Where practical, discourage personal shopping on shared nurses' station computers, and limit what those devices can access. A shared workstation signed in to the clinical record is a poor place to open a holiday coupon.

Payment verification rules

Require a phone call to a known number before changing banking details or sending any unusual payment, even when the request appears to come from the boss.

Reminders at the right time

A brief note in the staff huddle or on the pay stub this week will do more than an annual training session. Keep it short and concrete.

A simple message for your next huddle

Here is wording you can use as is: "This is the season for fake delivery texts, gift card requests and fake order receipts. If a message rushes you, asks for money or a password, or does not look right, do not click. Forward it to IT or tell your supervisor. Reporting is always okay, even if it turns out to be nothing."

Where we fit

UnityCare IT helps healthcare organizations configure email protection, roll out multi-factor authentication and provide short staff reminders like this one. If you would like a quick review of your email filtering before the holidays, we are glad to take a look.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172