What Ransomware Awareness Training Misses About Vishing

Office workers using computers in a modern workspace

Most ransomware awareness training programs teach employees to recognise malicious attachments, suspicious links, and spoofed sender addresses. That coverage is necessary but no longer sufficient. The ShinyHunters campaign targeting healthcare organisations, reported by HealthSystemCIO on September 10, 2026, reveals the gap: ransomware actors now routinely begin their attack with a phone call, not an email, and most training programs have no scenario that covers what that call looks or sounds like.

A caller poses as IT helpdesk staff, asks the employee to verify their multi-factor authentication settings, and directs them to a page that mirrors the organisation's real sign-in portal in real time. The attacker relays the stolen credentials to the legitimate portal simultaneously and asks the victim to read back the one-time code while still on the line. According to Mandiant, this reverse-proxy technique enabled ShinyHunters to breach more than 400 organisations in early 2026, affecting Panera Bread, SoundCloud, Match Group, and Crunchbase before the group turned its focus to healthcare.

The vishing technique most training programs do not cover

Post-access, ShinyHunters exfiltrated data from SharePoint, OneDrive, Salesforce, and Slack: that foothold is precisely the position ransomware operators need to move laterally and deploy encryption payloads. The Verizon 2026 Data Breach Investigations Report, which analysed more than 22,000 confirmed breaches, found that ransomware was a component of 48 per cent of confirmed incidents. A program that does not include vishing scenarios alongside email-based phishing simulations is preparing employees for last year's threat, not this one.

Why healthcare and public sector employees are prime targets

Healthcare workers operate under authority structures where responding quickly to an IT request is the professional norm. That same compliance reflex that makes a hospital run efficiently is exactly what a caller impersonating IT support is engineered to trigger. A nurse, a ward coordinator, or an administrative assistant does not have a mental model for what a vishing call looks like because nobody has built that model with them. The Gartner 2026 CISO survey found that 41 per cent of organisations had already experienced a deepfake combined with social engineering on an audio call, a figure that reflects how broadly this technique has been adopted across threat actors, not just ShinyHunters.

In our work with Crown corporations and Canadian public sector organizations, we consistently see human risk treated as a compliance checkbox rather than an operational discipline. Stories like this one underscore why annual click-through training is not enough when the threat landscape evolves weekly.

What to add to your ransomware awareness training program this quarter

The single most effective modification is a verification protocol that employees can apply under pressure: ‘I will hang up and call the helpdesk number from our intranet.’ That sentence, practised through simulation rather than simply read in a module, is the intervention that breaks this attack. Wiring it into a human risk management program that includes regular voice-based testing gives security teams the data to know whether employees actually use it when it matters.

If your current ransomware awareness training program does not include a realistic vishing scenario, your employees have never faced the technique in a safe environment. If you are unsure where the gaps in your program sit, starting with a cybersecurity posture assessment maps training coverage against the current attack surface and tells you which employee populations need the most urgent attention.

Sources