Watch Out for the Scams That Follow After a Cyberattack
When a major company gets hit by a cyberattack, the story usually focuses on the attack itself. What systems went down, the customer information that was stolen, the systems impacted and how long will recovery take.
There is another risk that happens after an attack that doesn't get nearly as much attention. That risk is (secondary) scammers showing up after the original attack. These secondary scammers don't need access to a company's private network. All they need is the information already released to the public.
These scammers knows a cyber incident has happened. Additionally, they know customers and employees are confused about how the cyber attack may affect them personally. That creates a great opportunity to scam individuals.
What Happened After the Kettering Health Cyberattack
We saw an example of these typeo of scammers in Ohio after the 2025 cyberattack against Kettering Health.
Kettering Health reported unauthorized access to its network on May 20, 2025. The attack disrupted technology operations for the healthcare provider, affecting services including phones, scheduling and leading to the cancellation of elective procedures.
While Kettering Health was working to restore its systems, another issue emerged. Residents of the community began receiving scam calls from people claiming to represent Kettering Health. Kettering residents were asked to provide credit card information to make their payments over the phone.
In this situation, the scammers only needed to know basics of the initial cyberattack and found a way to take advantage of the situation.
Why a Cyberattack Makes Other Scams More Believable
Imagine a company you regularly do business with announces that it has experienced a cyberattack. The next morning, you get an email that reads, "Because of yesterday's security incident, all customers are required to reset their passwords."
Or, what if you received a phone call and someone said, "Our payment system was affected by the outage. We need to verify the credit card you have on file."
The request might make sense with what you know. And that's why the scam works because the requests seem serious and realistic- that's why these type of scams work. If a hospital, manufacturer, or local business announces an attack, scammers can quickly build upon that information to further pursue their own financial goals.
Scams Should You Expect After a Cyber Incident
There isn't one specific follow-up scam to watch out for, but below are some common examples. Of course, criminals will adapt their approach depending on what information is released to the public.
Example #1, "You Need to Reset Your Password"
This is one of the easiest messages to make believable after an attack.
An employee or customer receives an email saying passwords must be reset because of the security incident. The link may even lead to a page that looks almost identical to a Microsoft 365 or company login screen. The individual enters a username and password and now a criminal has a new set of credentials.
This is specific example is especially concerning because stealing an email account can cause more damage then one stolen credit card. As we explain in our article on Business Email Compromise, criminals may monitor legitimate conversations, learn how a company operates, impersonate employees and eventually attempt financial fraud. So, monitoring an email account could lead to devasting financial results.
Exampe #2, "We Need to Verify Your Payment Information"
This is similar to what Kettering Health warned the public about following its incident.
A criminal calls and claims that a payment failed during the outage. For example, they may say an invoice needs to be processed again or your account needs to be "verified."
Any unexpected change to banking or payment instructions should be confirmed using a phone number or contact method you already trust, not the contact information included in the email or a return call on your phone's caller ID.
Example #3, "Your Information Was Exposed"
Someone contacts you claiming your personal information was part of the breach. They offer to help you check whether your Social Security number, banking information or password was exposed. All you have to do is "verify" your information first. Now the person supposedly helping protect you has the information they want to steal.
If an organization experiences a breach, go directly to its official website for information. Don't rely on a link from an unexpected email, text message, social media post or phone call.
The Attack Can Spread Beyond the Original Company
There is another part of this that businesses who experience a cyber attack need to consider. You hold information and/or contact information to your customers, vendors, accountants, attorneys, suppliers, insurance carriers, etc. If one company experiences a cyber incident, scammers can potentially use that company's information to target other organizations that work with that business.
A vendor might receive, "Our systems were affected by the recent cyberattack, so we've temporarily changed banks. Please send all outstanding payments to this new account."
Or an employee might receive, "We're reviewing third-party access following the breach. Please sign in to verify your vendor account."
Businesses Need a Response Plan
When companies think about incident response, they focus on containing the attacker and getting the business running again. But communication is an essential part of the response plan as well.
If your company experiences a cyber incident, customers and employees should know where official updates will come from. Be specific with staff and clients so that individuals can verify requests are valid.
Examples of what you might include in the plan:
- "We will never ask you for your password."
- "We are not requesting payments by phone."
- "Official updates will only appear on our website."
- "Employees should contact the help desk before responding to unexpected security requests."
Our guide to building an incident response plan covers why organizations should establish these responsibilities and communication procedures before an emergency happens.
What Should You Do If You Get a Suspicious Message After a Cyberattack?
If someone calls asking for payment information, hang up and call the organization using the number on its official website (not sponsored).
If you receive a password reset email, don't automatically click the link. Ensure you have a vaild phone number and call the service instead.
If your phone suddenly starts receiving MFA approval requests you didn't initiate, don't approve them just to make the notifications stop.
Final Thoughts
The initial cyberattack may get the headline, but the scams that follow may not. That means individuals have a responsibly to be cautious. Additionally, an incident response plan (for all businesses) should account for those risks.
Recovering a company’s servers is only a part of recovering from a cyberattack. There is a responsibility to also protect people and other businesses.
If you believe your business is actively being hacked, visit our 24/7 cybersecurity emergency response page.
Christina is a seasoned professional with over seventeen years of experience across multiple disciplines. She holds dual bachelor's degrees in English Education and Theatre, equipping her with a strong foundation in communication, storytelling, and audience engagement. Throughout her career, she has developed a diverse skill set that includes marketing strategy, program management, public speaking, leadership development, education, operations, project management, and cross-functional collaboration.
As the Marketing Manager at 4BIS Cyber Security and IT Services, Christina leads strategic marketing initiatives that drive brand awareness, community engagement, and business growth. Her journey with the company spans several roles, including helpdesk technician, dispatcher, administrative support, digital creator, and content developer. This unique progression gives her a deep understanding of both the technical and operational sides of the business, allowing her to translate complex cybersecurity concepts into clear, compelling messaging that resonates with decision-makers and the broader community.
Christina is known for blending creativity with strategy and for building marketing programs rooted in education, trust, and meaningful connection.
