
This is a representative scenario, not a specific client. It's a composite of the kind of account-takeover response we handle, written to show how we work and why. Real incidents vary, and the details here are deliberately general.
A staff member at a Perth medical practice gets an email that looks like a Microsoft "your mailbox is full" notice, clicks through, and enters their Microsoft 365 password on a login page that looks exactly right. It wasn't Microsoft — it was a phishing page, and the attacker now has a working password. Within minutes a single phished login can become a full account takeover: mailbox rules quietly redirecting mail, messages sent as the staff member, and — most seriously in healthcare — potential exposure of patient information. Here's how we respond, and why practices handling health data need more than a password.
How it starts: one convincing login page
Modern phishing doesn't look like the clumsy scams of a decade ago. The page is pixel-perfect, the email is urgent but plausible, and busy clinical staff are exactly the kind of distracted, trusting target attackers rely on. The click itself isn't the failure — it's what the environment lets happen after the click that decides how bad this gets. (Our guide on how to identify phishing emails is what we walk teams through to cut the click rate in the first place.)
First: lock the attacker out
The moment we're told an account may be compromised, containment comes before investigation:
Reset the password and revoke every active session, so an already-open session can't keep working while we clean up.
Re-register multi-factor authentication so the attacker's device is kicked out and only the real user can get back in.
Hunt for hidden mailbox rules. The classic account-takeover move is a rule that auto-deletes or hides the attacker's own activity and forwards a copy of incoming mail outside the practice. We remove any we find and check every other account for the same.
Assess: what did they actually touch?
Containment stops the bleeding; now we work out the scope, because in healthcare that determines your legal obligations:
What was in that mailbox and OneDrive? Referrals, results, patient correspondence, scanned documents — we establish what the account could reach.
Did they send anything, or set up forwarding? Outbound messages and forwarding rules tell us whether the attack was spreading or exfiltrating.
Did they reach anything beyond email — SharePoint, the practice-management system, other linked services?
Is this a notifiable data breach?
This is the question a medical practice can't skip. If patient information was accessed or exposed, the incident may trigger reporting under the Privacy Act and the Notifiable Data Breaches scheme, and there may be obligations around My Health Record. We help the practice assess this honestly and quickly — the goal is to make the right call on notification with clear evidence, not to guess. (We cover the shape of this in our FAQ on what happens after a breach.)
Hardening so it can't happen again
A phished password should be a non-event, not a crisis. What we put in place so it is:
MFA on every account, phishing-resistant for clinical and admin staff. A stolen password alone then opens nothing.
Conditional access so only known, compliant devices can reach patient data — a login from an unexpected location or unmanaged device is blocked or challenged.
Email filtering and impersonation protection to stop the phishing email landing at all.
Audit logging and alerting so a suspicious sign-in raises a flag early, instead of being discovered weeks later.
Staff training aimed at the reality of a busy practice, not a generic template.
How we help Perth healthcare
Medical, dental and allied-health practices carry some of the strictest data obligations of any small business, which is why we take a dedicated approach to IT for Perth healthcare: the layered security above, sized to a clinical setting and aligned to the RACGP and AHPRA expectations around protecting patient data. The support model is simple — we own the IT around your clinical software and keep the doors locked, so a moment's distraction at reception doesn't become a data breach.
If a login at your practice has just done something it shouldn't, treat it as urgent: call us on (08) 9325 1196 or get in touch. We've kept Perth businesses' data secure since 1997.



