DENTAL PHISH WATCH Sector security advisory — Australian dentistry Updated 28 Aug 2026 DPW-2026-001

Phishing campaign distributing remote-access malware via compromised dental practice mailboxes

RUN THIS FIRST · TAKES ABOUT A MINUTE

Check a practice computer for the software this attack installs

When someone opens one of these links, what gets installed is ScreenConnect — genuine remote-support software, turned against the practice, which hands a stranger full control of the PC every time it starts. Because it is legitimate signed software, antivirus does not flag it. This checker looks for it specifically, and tells you which server it reports to.

STEP 1Download the file below. Your browser will warn you about anything that can run — choose Keep.
STEP 2Double-click it. Windows asks permission — click Yes. (Decline and it still runs, with less detail.)
STEP 3Read the result. A copy saves to your Desktop to send your IT provider.
Download the checker (Windows)

Read-only — it changes nothing, installs nothing and removes nothing. It is plain text, not a program: right-click and open it in Notepad to read every line first. We deliberately do not offer a .exe, because downloading and running programs from websites is the habit this campaign relies on.

What it does and does not tell you. It checks one computer for this one payload. Run it on every PC in the practice — a clean result on one says nothing about the others. And a clean result does not mean the practice is unaffected: the mailbox can be compromised with no malware on any machine, which is how this campaign spreads. If a colleague has received odd email from your address, or anyone entered credentials anywhere, use the guided checklist instead.
StatusACTIVE
First observedMid-2026. Most recent file-share wave 28 July 2026; PRODA/HPOS credential campaign first seen 7 August 2026. Payload identified 17 August 2026 from a 14 August compromise
Sector affectedDental practices, Australia-wide (compromised senders identified to date in Victoria and New South Wales)
Threat typeTwo campaigns: (a) business email compromise → file-share lure → remote-access trojan (Windows); (b) Services Australia impersonation → PRODA/HPOS credential theft
Last updated28 August 2026 — payload identified, self-check published
Issued byA Victorian dental practice affected by this campaign, in coordination with reports from peer clinics. Contact via the reporting form (section 9).
Source codeAll tooling and this site are open source for independent review: github.com/DentaSuite/dental-phish-guard
START HERE — TWO QUICK QUESTIONS

Answer below and you'll get a plain-English checklist for your exact situation — whether you own a practice or work across several, and whether anything has been clicked. Nothing you answer is recorded. (Prefer a full page? Open it separately.)

1Summary

Two distinct phishing campaigns are currently targeting Australian dental practices. They are described separately throughout this advisory because they behave differently and require different responses. Section 2 sets them side by side so you can identify which one you are holding.

Campaign A propagates between practices through compromised email accounts. After gaining access to a clinic's mailbox, the operator sends "shared a file with you" emails to that clinic's correspondents. Because the messages originate from a genuine, previously trusted account, they pass SPF, DKIM and DMARC authentication and are rarely intercepted by spam filtering.

The linked pages deliver a remote-access trojan for Windows. During installation the malware displays a fake Windows Update screen; an infected machine observed by the issuing practice showed live hands-on-keyboard control by a remote operator. Follow-on activity has included repeat access attempts weeks after initial compromise.

Simulated fake Windows Update screen: black background, white text reading Working on updates 37% complete, Don't turn off your computer
Fig. 1 — Campaign A: a reconstruction of the fake "Windows Update" screen reported during infection. If a practice computer shows something like this unexpectedly — particularly just after a "shared file" link was opened, or with the mouse moving on its own — treat it as a live intrusion, not a real update. Simulated for awareness.

Each recipient practice that is compromised becomes a new distribution point to its own contact network. Compromised senders have been identified in both Victoria (a south-east Melbourne cluster consistent with propagation through local referral relationships) and New South Wales, indicating national reach: any practice that has ever corresponded with an affected clinic may be targeted regardless of state.

Link-scanning services return benign results for campaign A infrastructure: the kit serves a decoy page to automated scanners. A "clean" URL scan is not evidence of safety.

Campaign B, first seen on 7 August 2026, is a different proposition. It impersonates Services Australia, claims the recipient's PRODA account must be re-linked to HPOS, and harvests the credentials entered on a counterfeit sign-in page. It installs nothing, and it does not arrive from a hijacked colleague — it is delivered cold from throwaway attacker domains. A stolen PRODA credential exposes HPOS, and through it Medicare claiming, DVA, the Australian Immunisation Register and patient records.

2Two separate campaigns — which one are you looking at?

These are different attacks with different aims and, importantly, different responses. Getting the wrong one costs you: wiping a computer does nothing about a stolen PRODA login, and changing a password does nothing about a machine with an intruder on it. Work out which one you have before acting.

CAMPAIGN A · SINCE MID-2026

“[Practice] shared a file with you”

Fake file-share notice that installs malware

WHO IT COMES FROM
A real dental practice you know, whose mailbox has been hijacked. Passes every authentication check.
WHAT IT WANTS
You to click a link and open it on a Windows PC.
WHAT IT DOES
Installs remote-control software behind a fake “Windows Update” screen. A person then operates the machine.
WHAT YOU LOSE
The computer, every password saved in its browsers, and your address book — which becomes the next target list.
Tell-tale: it asks you to open the link on your “Desktop or Windows Laptop”, and the link goes to an odd domain, usually .vu.
→ Detail in section 3 · if someone clicked, section 10
CAMPAIGN B · SINCE AUG 2026

“Re-link your PRODA account”

Fake Services Australia notice that steals your login

WHO IT COMES FROM
Throwaway attacker domains, delivered cold. Not a hacked colleague — a stranger impersonating Services Australia.
WHAT IT WANTS
You to sign in on a fake PRODA page.
WHAT IT DOES
Nothing to your computer. It simply captures whatever you type.
WHAT YOU LOSE
Your PRODA login, and with it HPOS: Medicare claiming, DVA, the immunisation register and patient records.
Tell-tale: the sign-in button does not go to a .gov.au address — and neither does the link text that reads “servicesaustralia.gov.au”.
→ Detail in section 4 · if details were entered, section 11
The rule that beats both: never act on the link, button or phone number printed in an unexpected email. For campaign A, telephone the apparent sender on a number you already have. For campaign B, reach PRODA by typing the address yourself or using your own bookmark, and look Services Australia up independently. In both cases the attacker controls what the email tells you.

3CAMPAIGN AFile-share lure delivering remote-access malware

Campaign A sample: imitation Microsoft file-share notification titled Dental Clinic Name shared a file with you, with an Open Document button

Fig. 2 — Campaign A email received 23 July 2026 (sending practice anonymised). Waves are near-identical: imitation Microsoft share card, “Open Document” button, instruction to open on a desktop computer.

Message characteristics

  • Subject of the form “[Practice name] shared a file with you”; sender is a real practice known to the recipient
  • Body styled as a Microsoft OneDrive/SharePoint share notification; single link, no attachment
  • Instruction to open the link on a desktop or Windows laptop (the payload targets Windows only)
  • Recipients concealed via BCC (“undisclosed recipients”); no personal salutation
  • Send times across five held samples run from 03:41 to 10:58 AEST — two outside business hours, three during. An odd-hours timestamp is a useful prompt, but time of day is not a reliable test and a normal timestamp is not reassurance

Network indicators

DOMAIN (do not visit)OBSERVED
avernix​.vu​/access14 Jul 2026
uvanv​.vuearly wave
xornavo​.vu​/file13 Jul 2026
lornica​.vu​/dental16 Jul 2026
clientesetupdoc​.vu​/access23 Jul 2026
docsecdental​.vu​/mesh23 Jul 2026
dytrix​.vu24 Jul 2026
bzlvaka​.vu​/access28 Jul 2026
dprvirz​.vu (also doc.dprvirz​.vu)31 Jul 2026

A newly registered domain is used for each wave. Detection should rely on the message pattern, not on any specific domain.

What it installs (confirmed 17 Aug 2026): ScreenConnect remote-support software, configured for unattended access and installed twice over, pointing at two different servers. It is legitimate signed software, so antivirus does not flag it — and the fake “Windows Update” screen is that product’s own branding, abused. See how to check a PC.
Verification guidance: before opening any unexpected file-share link — including from trusted colleagues — telephone the apparent sender on a known number and confirm they sent it. Do not verify by email reply: if the account is compromised, the operator controls the replies.

4CAMPAIGN BServices Australia impersonation harvesting PRODA credentials

First seen 7 August 2026. The email claims your Provider Digital Access (PRODA) account is no longer linked to Health Professional Online Services (HPOS) and must be reconnected, with a “Reconnect PRODA” button. It is formatted as a routine automated notice from Services Australia.

Message characteristics

Network indicators

INDICATOR (do not visit)ROLEOBSERVED
verifications​.es​/verification/v333/v3credential-harvest page7 Aug 2026
ghaspert​.comsender domain7 Aug 2026
machsselbst​.comsender domain7 Aug 2026
Verification guidance: a genuine Services Australia link always ends in .gov.au. Reach PRODA only by typing the address yourself or using your own bookmark, never through a button in an email. To confirm anything with Services Australia, look their number up on their website rather than using the one printed in the message.

5Current statistics

Figures are compiled from sighting reports and automated detections submitted by participating practices, and update as reports are received. Affected practices are treated as victims: they are notified privately by telephone and are not named. Map positions are rounded to approximately 10 km.

practices with compromised accounts identified
notified so far (notification in progress)
detection reports received
most recent detection
Fig. 3 — Approximate locations of identified compromised practices for which a location is known, shown where each sending practice is based. Local clusters follow referral networks, but identified senders span multiple states. Markers turn green once that practice has been contacted.

6How to tell if your practice is affected

There are two distinct questions: whether a practice computer is infected, and whether the practice mailbox is compromised and being used to attack others. Either can be true without the other, and a compromised mailbox usually produces no symptoms visible to its owner — most affected practices learn of it only when a colleague telephones to ask about a strange email.

Signs a computer is infected

Signs the practice mailbox is compromised

Checking a computer for the remote-access software this attack installs

Updated 17 August 2026. We now know exactly what campaign A installs, from event logs supplied by an IT provider after a practice was compromised on 14 August. It is ScreenConnect (also sold as ConnectWise Control) — a genuine, commercially sold remote-support product, not a virus. That matters for two reasons: antivirus will not flag it, because it is legitimate signed software; and it is installed as a background service that starts with the computer, so the operator regains control every time the machine boots.

In the case we have logs for, two copies were installed 70 seconds apart, connecting to two different servers. Removing one leaves the other. Anyone cleaning up must find and remove every one.

Checking a PC — three steps, about a minute

  1. Download the checker: Check-This-PC.bat
    Your browser will probably warn you about this file, because browsers warn about anything that can run. Choose Keep / Keep anyway. If you would rather see what it does first, right-click it and open with Notepad — it is plain text and every line is readable. We deliberately do not supply a .exe: telling practices to download and run programs from websites is the habit this whole campaign relies on.
  2. Double-click it. Windows will ask for permission to continue — click Yes. (It needs that only to read the event log. If you click No it still runs, just with less detail.)
    If Windows shows a blue “Windows protected your PC” box, click More info then Run anyway.
  3. Read the result in the black window, and press a key to close it. A copy is saved to your Desktop as PhishWatch-Check-<computer>-<date>.txt which you can email to your IT provider.

It tells you one of three things: nothing found; software found — check with your IT provider, listing the exact server address it connects to; or matches a known attack server, with what to do immediately.

It only reads. It changes nothing, installs nothing and removes nothing. Repeat on every computer in the practice — a result on one PC says nothing about the others. IT providers who would rather run the PowerShell directly can use Check-ScreenConnect.ps1, or push the checks from their RMM.

Before you act on a result: finding ScreenConnect does not mean you have been hacked. Most IT providers legitimately use this exact product, installed in exactly this way. A rule of “ScreenConnect present = compromised” is wrong and will have practices accusing their own IT company.

The reliable test is the server it connects to. Telephone your IT provider on the number already in your records — never one from an email — and ask: do you use ScreenConnect, what exact server address and port does it connect to, and did you install anything on this PC on 14 August? Then compare character by character with what the check reported. Anything that does not match is treated as hostile; anything that matches is left alone. Bear in mind a second client can also be an old agent from a previous IT provider, or a practice-management or imaging vendor's support tool.

Do not uninstall everything “to be safe.” You can cut off your provider's legitimate access and destroy the evidence. If you cannot reach them, disconnect the machine from the network instead — that is reversible and uninstalling is not.

If it is found and your provider does not recognise it

Do not delete it yourself, and do not let anyone delete it as the first move. That instinct is understandable but it makes things worse in three ways: it destroys the records your insurer and a data-breach assessment depend on; if the operator is connected at the time they see it happening and can react; and removing the software does not make the computer safe, because whoever had control may have added accounts, stolen saved passwords or left other tools behind. Deleting closes the door while leaving everything they did inside.

  1. Unplug the network cable and turn off Wi-Fi. Leave the machine switched on. Do not use it and do not type any password into it. Isolation is instant, reversible, and stops the operator immediately — deleting is none of those things.
  2. Ring your IT provider and your insurer from a different device. Many cyber policies require the insurer's consent before remediation and will appoint the responder; remediating first can affect cover.
  3. Change your passwords from a clean device — mailbox first, then banking, Medicare/PRODA, HICAPS and practice software. For the mailbox a password change alone is not enough; see section 10.
  4. Removal comes last, and is a job for the provider — who should preserve the evidence first, remove every agent rather than one, and check the machine for other changes. A script that does this in the right order is provided for them below.
  5. Plan to rebuild the machine. A PC that ran an unattended remote-access agent with full system rights should be reinstalled from clean media, not just cleaned up.

Check every other computer in the practice before assuming it was only one.

For IT providers: Remove-ScreenConnect.ps1 reports by default and changes nothing until run with -Execute and a typed confirmation. It exports the event logs, service configuration and any files the operator transferred before removing anything, takes a -KeepRelay exclusion so your own legitimate agent is left alone, checks the LSA persistence entry that can survive an uninstall, and re-verifies afterwards.

Two indicators worth giving your IT provider: the attacker relay in this case was relay.cojeqinvpt​.online on port 8041, and the second implant used a ConnectWise-hosted address. Blocking outbound port 8041 to anything outside screenconnect.com is the single most useful firewall rule. Full detail is on the technical page.

Practice-wide mailbox sweep

Have one person search the practice mailbox — including archived mail, not just the inbox — with:

"shared a file with you" OR "shared a folder with you" OR "invitation to view shared"

Then run a second search for the government-impersonation campaign — the first search will not find it:

"PRODA" OR "HPOS" OR "Provider Digital Access"

Treat a match from the second search as suspect if it carries Services Australia branding and a sign-in button that is not a .gov.au address.

The same phrase searches work in Gmail and Outlook. Suspect matches from the first search carry the indicators in section 2: real clinic as sender, single link with no attachment, unusual domain, an instruction to open on a desktop computer, odd send times. Then ask every staff member, openly and without blame, whether anyone opened such a link and whether any machine has shown the symptoms above. The flowchart below walks a practice through the outcomes; a printable copy is in section 6.

Flowchart: search the mailbox for share-lure phrases; if matches are found, question staff; branch to contain-and-report, precautionary lockdown, or full incident response depending on answers
Fig. 4 — Staff sweep procedure. Click to open the printable A4 version.

Ten-minute self-check

  1. Gmail accounts: run the Security Checkup at myaccount.google.com/security (devices, recent activity, third-party access); in Gmail settings review Forwarding and POP/IMAP and Filters and blocked addresses; click Details at the bottom-right of the inbox for recent session activity.
  2. Microsoft 365 / Outlook: review sign-in activity at account.microsoft.com (or Entra sign-in logs, if administered); in Outlook settings review Mail → Rules and Forwarding; administrators can run a message trace for unexpected outbound volume.
  3. Search Sent and Deleted Items for "shared a file".
  4. Review installed programs on each Windows machine for the remote-access tools listed above.
  5. Ask staff directly whether anyone has opened a file-share link recently. A no-blame framing gets truthful answers; minutes matter more than fault.

If any indicator above is present, proceed to section 8 (incident response) and report via section 7. If in doubt, treat the mailbox as compromised — a password change with multi-factor enrolment costs minutes; a missed compromise costs weeks.

7Recommended actions

All staff

Practice owners and IT providers

8Resources

How to install the Phish Guard extension (about two minutes)

Download the extension zip above, right-click it and choose Extract All (remember where the folder goes — usually Downloads), then:

Four steps: open chrome://extensions, switch on Developer mode, click Load unpacked and choose the extracted folder, extension appears in the list
Fig. 5 — Installing in Chrome. In Microsoft Edge the address is edge://extensions; every other step is identical. Repeat on each computer that checks email.

What it does once installed

Nothing, most of the time — it sits quietly. But when an email matching this attack is opened in Gmail or Outlook web, a red warning appears above the message before anyone can click, spelling out exactly why it's dangerous:

A phishing email in webmail with the extension's red DANGER banner above it listing the reasons it was flagged
Fig. 6 — A live capture of the extension flagging a demonstration email. It also keeps a private list of which clinics sent flagged emails (click its toolbar icon) so they can be phoned and warned, and — unless you switch it off in that popup — sends the sender address and attack domains (never the email itself) to this advisory's statistics.

Using the printed materials

Print the poster and the sweep flowchart on A4 and put them where email is actually read — the front desk and the staff room, not the filing cabinet. Open the booklet in Word, type your practice name on the cover, print a copy per staff member, and walk through it at a team meeting — it takes about 15 minutes and reception staff are the most important audience. The IT guide isn't for you: forward it to whoever looks after your computers with the message "please do these and confirm in writing".

Everything above, including this site itself, is published in full at github.com/DentaSuite/dental-phish-guard so you or your IT provider can verify exactly what it does before installing. Detection reports are write-only; submitted data is readable only by the advisory coordinator.

9Reporting a sighting

Reports serve two purposes: the practice whose account was compromised is notified privately by telephone, and new infrastructure is added to the indicator list, the browser extension, and takedown requests. Reports are reviewed individually; nothing is published automatically and reporting practices are not named.

The most useful evidence is the original message file. In Gmail: message menu (⋮) → "Download message". Attach it to the pre-filled email this form produces. Do not include patient information.

Submitting opens a pre-filled message in your own mail application for review before sending.

10CAMPAIGN AIncident response — malware, after a click

Use this when someone opened a file-share link and something ran. If instead someone typed credentials into a fake PRODA page, this is the wrong list — go to section 11.

  1. Disconnect the affected computer from the network immediately and cease using it. Containment is achieved at this point — the remaining steps are not a race.
  2. Before anything is wiped, notify your indemnity or cyber insurer. Many policies require the insurer's consent before remediation and will appoint the responder; wiping first can prejudice cover and destroys the only evidence for the data-breach assessment. Take a disk image, or remove the drive and set the machine aside intact.
  3. Reimage the machine (wipe and reinstall Windows). Antivirus remediation alone is insufficient where interactive remote access has occurred. Do not wipe until the disk is imaged or your insurer confirms you may proceed.
  4. From a separate, known-clean device, evict the intruder from the mailbox in this order — a password change alone does not remove them:
    1. reset the password;
    2. revoke all active sessions and refresh tokens (sign out everywhere);
    3. delete every app password;
    4. revoke every third-party or OAuth application with mailbox access that you did not authorise — these survive a password reset;
    5. review registered multi-factor methods and delete any phone, email or authenticator you do not recognise before enrolling your own; simply "turning on 2FA" can cement an attacker's device;
    6. delete unrecognised inbox rules, forwarding addresses and auto-replies, and confirm recovery contact details are unchanged.
    Check these at the server level too, not only in the mail app: Exchange admin centre → Recipients → Mailboxes → mail flow settings (forwarding) and Mailbox delegation; or Gmail → Settings → Accounts and Import → "Grant access to your account", plus any admin-console routing rules.
  5. Treat all credentials stored in browsers on the affected machine as compromised. Change them, beginning with banking, then Medicare/PRODA, HICAPS, practice management and supplier accounts. Notify the bank if payment details were stored.
  6. Advise correspondents that mail from the practice's address may be malicious.
  7. If patient information may have been accessed, you are the entity with the notification obligation — not your IT provider and not your software vendor. Under the Notifiable Data Breaches scheme you must complete a reasonable and expeditious assessment within 30 days of becoming aware, and notify the OAIC and affected patients if serious harm is likely. Involve your indemnity provider immediately; note that professional indemnity and cyber cover are different products and you may hold one without the other.
  8. Report the incident to the ACSC at cyber.gov.au/report, and review practice bank accounts and recent invoices for unauthorised changes.

11CAMPAIGN BIncident response — PRODA credentials entered

Use this when someone typed a PRODA username, password or verification code into a page reached from an email. The computer does not need wiping — this campaign installs nothing. The exposure is the account and everything HPOS reaches through it.

  1. Change the PRODA password immediately, from a device that did not open the link. Reach PRODA by typing the address yourself or using your own bookmark — never a link in an email.
  2. Do not use any phone number or link supplied by the suspicious message; the scam prints its own “Services Australia” contact details. Look the real number up on the Services Australia website.
  3. Telephone Services Australia and report the PRODA account as compromised, so they can review it.
  4. Inspect the PRODA account for changes you did not make: linked services, linked organisations, delegates, registration authority details, and the contact email and mobile. Adding a delegate is how an operator keeps access after a password change, so a password reset alone is not sufficient.
  5. Confirm the multi-factor method on the account is yours and was not switched to an attacker’s device.
  6. Review HPOS for unauthorised activity: claims not submitted by the practice, altered bank or payment details, new delegations, and anything recorded against your provider number.
  7. Change the same password anywhere else it is used, particularly if it also protects email, banking or practice software.
  8. Treat it as a patient-data incident, not only a billing one. PRODA and HPOS reach Medicare, DVA and Australian Immunisation Register records. Where My Health Record is used, notification to the ADHA is a separate mandatory duty alongside any Notifiable Data Breaches assessment.
  9. Contact your indemnity or cyber insurer today; professional indemnity and cyber cover are different products and you may hold only one.
  10. Report to the ACSC at cyber.gov.au/report and via section 9, and keep monitoring claims and payments for several months — provider-number fraud may not surface immediately.
A guided version of this checklist, with tick-boxes, is in the triage tool.

12Acknowledgements

This advisory exists because people who had no obligation to help chose to. Nearly everything on this page beyond our own practice’s experience came from someone forwarding an email, sending a log file, or picking up the phone.

How credit works here

Contributions to date

WHATCONTRIBUTED BYWHEN
Identification of the campaign-A payload. Windows service-install logs from a practice compromised on 14 August, which established that the payload is ScreenConnect deployed as a double implant — the finding behind section 6, technical section 3c and the checker script. This had been the single largest gap in the advisory. An Australian IT provider, on behalf of a client practice
credit by name pending their agreement
17 Aug 2026
Campaign B samples. Two copies of the fake Services Australia / PRODA email, forwarded intact with headers — the basis of section 4. A colleague at a targeted practice 7 Aug 2026
Campaign A samples and sightings from practices in Victoria and New South Wales, which established the wave timeline and the domain rotation. Reporting practices (not named — see policy above) Jul – Aug 2026

If you can add to this

The open questions are listed at the end of the technical analysis. The most useful things anyone can send are an original phishing email with its headers intact, firewall or DNS logs showing how long an operator remained connected, or a disk image taken before a compromised machine is rebuilt. Sightings go through section 9; technical material through the contact form.

Compiled and maintained by Dr James Lee, Park Road Dental.