Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Healthcare workers emailed about a day off — but it was a cybersecurity test

Newfoundland and Labrador's health authority sent a phishing email to employees offering a paid day off for completing a survey, as part of a cybersecurity test. The email was meant to assess workers' compliance with security protocols, but some staff criticized the approach as deceptive.

Background

- Newfoundland and Labrador's health authority (NLHS) sent a fake phishing email to its own staff, disguised as a "wellness day" offer, as a cybersecurity exercise. - Phishing is a type of cyberattack where fraudulent messages trick recipients into clicking malicious links or sharing sensitive information. Healthcare systems have become prime targets for such attacks (e.g., the 2023 Fredericton hospital ransomware incident, the 2024 BORN Ontario breach). - The test highlights the tension between employee trust and security vigilance: many workers were frustrated by the deception, arguing it erodes morale at a time when healthcare staff are already stretched thin. - The article matters because it shows a real-world example of how institutions try to train employees against social-engineering threats — and the backlash that can result when the "training" feels like a trick.