DENTAL PHISH WATCH Sector security advisory — Australian dentistry DPW-2026-001

Phishing campaign distributing remote-access malware via compromised dental practice mailboxes

StatusACTIVE
First observedMid-2026; most recent wave 22–23 July 2026
Sector affectedDental practices, Australia-wide (compromised senders identified to date in Victoria and New South Wales)
Threat typeBusiness email compromise → credential-themed file-share lure → remote-access trojan (Windows)
Last updated23 July 2026
Issued byA Victorian dental practice affected by this campaign, in coordination with reports from peer clinics. Contact via the reporting form (section 7).
Source codeAll tooling and this site are open source for independent review: github.com/DentaSuite/dental-phish-guard
START HERE — TWO QUICK QUESTIONS

Answer below and you'll get a plain-English checklist for your exact situation — whether you own a practice or work across several, and whether anything has been clicked. Nothing you answer is recorded. (Prefer a full page? Open it separately.)

1Summary

An ongoing phishing campaign is propagating between Australian dental practices through compromised email accounts. After gaining access to a clinic's mailbox, the operator sends "shared a file with you" emails to the clinic's correspondents. Because these messages originate from a genuine, previously trusted account, they pass SPF, DKIM and DMARC authentication and are rarely intercepted by spam filtering.

The linked pages deliver a remote-access trojan for Windows. During installation the malware displays a fake Windows Update screen; an infected machine observed by the issuing practice showed live hands-on-keyboard control by a remote operator. Follow-on activity has included repeat access attempts weeks after initial compromise.

Each recipient practice that is compromised becomes a new distribution point to its own contact network. Compromised senders have been identified in both Victoria (a south-east Melbourne cluster consistent with propagation through local referral relationships) and New South Wales, indicating national reach: any practice that has ever corresponded with an affected clinic may be targeted regardless of state.

Link-scanning services return benign results for this infrastructure: the kit serves a decoy page to automated scanners. A "clean" URL scan is not evidence of safety for this campaign.

2Indicators and example

Sample campaign email: imitation Microsoft file-share notification titled 'Dental Clinic Name shared a file with you' with an Open Document button

Fig. 1 — Campaign email received 23 July 2026 (sending clinic anonymised). Waves are near-identical: imitation Microsoft share card, "Open Document" button, instruction to open on a desktop computer.

Message characteristics

  • Subject of the form "[Practice name] shared a file with you"; sender is a real practice known to the recipient
  • Body styled as a Microsoft OneDrive/SharePoint share notification; single link, no attachment
  • Instruction to open the link on a desktop or Windows laptop (the payload targets Windows only)
  • Recipients concealed via BCC ("undisclosed recipients"); no personal salutation
  • Frequently sent outside business hours; timestamps of 3–6 am AEST observed, consistent with an overseas operator

Network indicators

DOMAIN (do not visit)OBSERVED
avernix​.vu​/accessearly wave
uvanv​.vuearly wave
xornavo​.vu​/file12 Jul 2026
lornica​.vu​/dental16 Jul 2026
clientesetupdoc​.vu​/access22 Jul 2026
docsecdental​.vu​/mesh22 Jul 2026

A newly registered domain is used for each wave. Detection should rely on the message pattern, not on any specific domain.

Verification guidance: before opening any unexpected file-share link — including from trusted colleagues — telephone the apparent sender on a known number and confirm they sent it. Do not verify by email reply: if the account is compromised, the operator controls the replies.

3Current statistics

Figures are compiled from sighting reports and automated detections submitted by participating practices, and update as reports are received. Affected practices are treated as victims: they are notified privately by telephone and are not named. Map positions are rounded to approximately 10 km.

practices with compromised accounts identified
of which notified and in recovery
detection reports received
most recent detection
Fig. 2 — Approximate locations of identified compromised practices, shown where each sending practice is located. Local clusters follow referral networks, but identified senders now span multiple states.

4How to tell if your practice is affected

There are two distinct questions: whether a practice computer is infected, and whether the practice mailbox is compromised and being used to attack others. Either can be true without the other, and a compromised mailbox usually produces no symptoms visible to its owner — most affected practices learn of it only when a colleague telephones to ask about a strange email.

Signs a computer is infected

Signs the practice mailbox is compromised

Practice-wide mailbox sweep

Have one person search the practice mailbox — including archived mail, not just the inbox — with:

"shared a file with you" OR "shared a folder with you" OR "shared a file for you"

The same phrase search works in Gmail and Outlook. Suspect matches carry the indicators in section 2: real clinic as sender, single link with no attachment, unusual domain, an instruction to open on a desktop computer, odd send times. Then ask every staff member, openly and without blame, whether anyone opened such a link and whether any machine has shown the symptoms above. The flowchart below walks a practice through the outcomes; a printable copy is in section 6.

Flowchart: search the mailbox for share-lure phrases; if matches are found, question staff; branch to contain-and-report, precautionary lockdown, or full incident response depending on answers
Fig. 3 — Staff sweep procedure. Click to open the printable A4 version.

Ten-minute self-check

  1. Gmail accounts: run the Security Checkup at myaccount.google.com/security (devices, recent activity, third-party access); in Gmail settings review Forwarding and POP/IMAP and Filters and blocked addresses; click Details at the bottom-right of the inbox for recent session activity.
  2. Microsoft 365 / Outlook: review sign-in activity at account.microsoft.com (or Entra sign-in logs, if administered); in Outlook settings review Mail → Rules and Forwarding; administrators can run a message trace for unexpected outbound volume.
  3. Search Sent and Deleted Items for "shared a file".
  4. Review installed programs on each Windows machine for the remote-access tools listed above.
  5. Ask staff directly whether anyone has opened a file-share link recently. A no-blame framing gets truthful answers; minutes matter more than fault.

If any indicator above is present, proceed to section 8 (incident response) and report via section 7. If in doubt, treat the mailbox as compromised — a password change with multi-factor enrolment costs minutes; a missed compromise costs weeks.

5Recommended actions

All staff

Practice owners and IT providers

6Resources

How to install the Phish Guard extension (about two minutes)

Download the extension zip above, right-click it and choose Extract All (remember where the folder goes — usually Downloads), then:

Four steps: open chrome://extensions, switch on Developer mode, click Load unpacked and choose the extracted folder, extension appears in the list
Fig. 4 — Installing in Chrome. In Microsoft Edge the address is edge://extensions; every other step is identical. Repeat on each computer that checks email.

What it does once installed

Nothing, most of the time — it sits quietly. But when an email matching this attack is opened in Gmail or Outlook web, a red warning appears above the message before anyone can click, spelling out exactly why it's dangerous:

A phishing email in webmail with the extension's red DANGER banner above it listing the reasons it was flagged
Fig. 5 — A live capture of the extension flagging a demonstration email. It also keeps a private list of which clinics sent flagged emails (click its toolbar icon) so they can be phoned and warned, and — unless you switch it off in that popup — sends the sender address and attack domains (never the email itself) to this advisory's statistics.

Using the printed materials

Print the poster and the sweep flowchart on A4 and put them where email is actually read — the front desk and the staff room, not the filing cabinet. Open the booklet in Word, type your practice name on the cover, print a copy per staff member, and walk through it at a team meeting — it takes about 15 minutes and reception staff are the most important audience. The IT guide isn't for you: forward it to whoever looks after your computers with the message "please do these and confirm in writing".

Everything above, including this site itself, is published in full at github.com/DentaSuite/dental-phish-guard so you or your IT provider can verify exactly what it does before installing. Detection reports are write-only; submitted data is readable only by the advisory coordinator.

7Reporting a sighting

Reports serve two purposes: the practice whose account was compromised is notified privately by telephone, and new infrastructure is added to the indicator list, the browser extension, and takedown requests. Reports are reviewed individually; nothing is published automatically and reporting practices are not named.

The most useful evidence is the original message file. In Gmail: message menu (⋮) → "Download message". Attach it to the pre-filled email this form produces. Do not include patient information.

Submitting opens a pre-filled message in your own mail application for review before sending.

8Incident response after a click

  1. Disconnect the affected computer from the network immediately and cease using it.
  2. Reimage the machine (wipe and reinstall Windows). Antivirus remediation alone is insufficient where interactive remote access has occurred.
  3. From a separate, known-clean device: change the mailbox password, enable multi-factor authentication, and terminate all active sessions.
  4. Audit mailbox configuration for forwarding rules, filters and auto-replies not created by the practice; confirm recovery contact details are unchanged; review authorised third-party applications.
  5. Treat all credentials stored in browsers on the affected machine as compromised. Change them, beginning with banking, then Medicare/PRODA, HICAPS, practice management and supplier accounts. Notify the bank if payment details were stored.
  6. Advise correspondents that mail from the practice's address may be malicious.
  7. If patient information may have been accessed, contact your indemnity provider regarding obligations under the Notifiable Data Breaches scheme (OAIC).
  8. Report the incident to the ACSC at cyber.gov.au/report, and review practice bank accounts and recent invoices for unauthorised changes.