Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      Artemis II Splashdown Signals A Step Closer to Mass Space Travel

      April 12, 2026

      Anthropic Code Leak Raises Questions About AI Security and Industry Oversight

      April 8, 2026

      NASA Astronauts Use iPhones to Capture Historic Artemis II Mission Images

      April 8, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        NASA Astronauts Use iPhones to Capture Historic Artemis II Mission Images

        April 8, 2026

        OpenAI Expands Influence With Strategic TBPN Media Acquisition

        April 8, 2026

        Cybersecurity Veteran Turns Focus To Drone Hacking After Decades Battling Malware

        April 6, 2026

        Anonymous Social App Surges In Saudi Arabia, Testing Limits Of Digital Freedom

        April 6, 2026

        Peter Thiel’s Bold Ag-Tech Gamble Signals High-Tech Disruption of Traditional Ranching

        April 6, 2026
      • AI

        Anthropic Code Leak Raises Questions About AI Security and Industry Oversight

        April 8, 2026

        The Rise Of Agentic AI Signals A Shift From Tools To Autonomous Digital Actors

        April 8, 2026

        AI Chatbots Draw Scrutiny As Teens Engage In Intimate Roleplay And Emotional Dependency

        April 8, 2026

        Ai-Powered Startup Signals Rise Of One-Person Billion-Dollar Companies

        April 8, 2026

        OpenAI Secures Historic $122 Billion Funding Round at $852 Billion Valuation

        April 7, 2026
      • Security

        Anthropic Code Leak Raises Questions About AI Security and Industry Oversight

        April 8, 2026

        DeFi Platform Drift Halts Operations After Multi-Million Dollar Crypto Hack

        April 7, 2026

        Fake WhatsApp App Exposes Users To Government Spyware Operation

        April 7, 2026

        ICE Deploys Controversial Spyware Tool In Drug Trafficking Investigations

        April 7, 2026

        Telehealth Firm Discloses Breach Amid Rising Digital Health Vulnerabilities

        April 6, 2026
      • Health

        European Crackdown Targets Social Media’s Impact on Children

        April 8, 2026

        AI Chatbots Draw Scrutiny As Teens Engage In Intimate Roleplay And Emotional Dependency

        April 8, 2026

        Australia Moves To Curb Social Media Addiction Among Youth With Expanded Under-16 Ban

        April 5, 2026

        Australia’s eSafety Regulator Warns Big Tech As Teens Circumvent Social Media Restrictions

        April 5, 2026

        Meta Finally Held Accountable For Harming Teens, But Real Reform Remains Uncertain

        April 2, 2026
      • Science

        Artemis II Splashdown Signals A Step Closer to Mass Space Travel

        April 12, 2026

        Peter Thiel’s Bold Ag-Tech Gamble Signals High-Tech Disruption of Traditional Ranching

        April 6, 2026

        White House Tech Advisor David Sacks Steps Down To Lead Presidential Science Advisory

        March 31, 2026

        Blue Origin’s Orbital Data Center Push Signals New Frontier in Tech Infrastructure

        March 27, 2026

        Quantum Cryptography Pioneers Awarded Computing’s Highest Honor

        March 25, 2026
      • Tech

        Peter Thiel’s Bold Ag-Tech Gamble Signals High-Tech Disruption of Traditional Ranching

        April 6, 2026

        Zuckerberg Quietly Offers Musk Support As Tech Titans Align Around Government Power

        April 4, 2026

        White House Tech Advisor David Sacks Steps Down To Lead Presidential Science Advisory

        March 31, 2026

        Another Billionaire Signals Exit As California’s Taxes Drives Out High-Profile Entrepreneurs

        March 28, 2026

        Bezos Eyes $100 Billion War Chest To Rewire Legacy Industry With AI

        March 28, 2026
      TallwireTallwire
      Home»Tech»Weak Email Security Settings on Microsoft 365 Drive Surge in Healthcare Data Breaches
      Tech

      Weak Email Security Settings on Microsoft 365 Drive Surge in Healthcare Data Breaches

      Updated:February 21, 20263 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      Weak Email Security Settings on Microsoft 365 Drive Surge in Healthcare Data Breaches
      Weak Email Security Settings on Microsoft 365 Drive Surge in Healthcare Data Breaches
      Share
      Facebook Twitter LinkedIn Pinterest Email

      Healthcare organizations are facing a growing wave of email-related security failures, with Microsoft 365 repeatedly identified as a major weak link. According to a recent IT Pro–Paubox report, 52% of healthcare email breaches in the first half of 2025 involved Microsoft 365, up from 43% in 2024. In that same period, 107 attacks exposed over 1.6 million patient records, with an average of nearly 16,000 records breached per incident. Compounding the issue, 79% of breached organizations were found to have ineffective DMARC protection (up from 65%), many lacked robust phishing‐reporting among staff (only ~5% of phishing attacks are even reported), and too many depend chiefly on human vigilance rather than resilient technical configuration. 

      Sources: IT Pro, PauBox.com

      Key Takeaway Points

      – Microsoft 365 is increasingly implicated in healthcare email breaches—over half of incidents in early-2025—and failure is often due to poor setup/configuration rather than the inherent defects of the platform itself.

      – Email authentication protocols (DMARC, SPF, DKIM) are frequently misconfigured or insufficiently enforced; a large majority of breached domains have weak DMARC settings.

      – Human and operational factors—such as lack of reporting, bypassing secure tools, understaffed security teams, and overreliance on user behavior—remain central vulnerabilities.

      In-Depth

      Healthcare data security remains under siege, and recent reports confirm that the weakest link is often not the size of the breach, but the basic email configurations and practices institutions rely on.

      The 2025 mid-year healthcare email security analysis by Paubox reveals that in just the first half of the year, 107 email-related breaches compromised more than 1.6 million patient records—an average of nearly 16,000 records per breach. Microsoft 365 accounted for 52% of those compromises, up from 43% in the previous year. Far from being a problem unique to smaller providers, this is happening across organizations large and small. 

      The root causes are less about cutting-edge malware or zero-day exploits, and more about misconfigured security settings and gaps in foundational protections. For example, DMARC—an email authentication standard that helps block spoofed or malicious messages—was found ineffective or too loosely set up (monitor-only) in nearly four in five breached organizations. Compounding the vulnerability, staff often bypass secure message systems, and very few phishing attacks are reported, leaving malicious messages undetected until it’s too late. 

      Financial stakes for these failures are huge. Healthcare breaches not only risk patient privacy and safety but carry steep regulatory penalties and reputational harm. The cost per breach can run into the tens of millions. And while premium email security services (like Mimecast, Proofpoint, Barracuda) are involved in some breaches, their presence isn’t sufficient shield—what matters more is ongoing enforcement, correct setup, default protections, and reducing reliance on human vigilance. 

      To prevent further escalation, healthcare organizations must shift mindset: email security cannot be “good enough.” Institutions need to enforce DMARC/SPF/DKIM correctly (not in passive or monitor modes), automate secure defaults (such as automatic encryption), mandate reporting of phishing from staff, and ensure third-party vendors are held to same standards. Technical defenses must be backed by operational discipline: regular audits, employee training, properly staffed security teams, and continuous monitoring. It’s only by combining strong tools with strong practices that healthcare providers can stem the tide of email‐based breaches.

      Microsoft
      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleWaymo Rolls Out ‘Waymo for Business’ to Bring Robotaxis Into the Corporate Realm
      Next Article Weaponized Desktop Shortcuts: APT36 Strikes Indian Government Agencies

      Related Posts

      NASA Astronauts Use iPhones to Capture Historic Artemis II Mission Images

      April 8, 2026

      OpenAI Expands Influence With Strategic TBPN Media Acquisition

      April 8, 2026

      Microsoft Escalates AI Arms Race With Three New Foundational Models

      April 6, 2026

      Cybersecurity Veteran Turns Focus To Drone Hacking After Decades Battling Malware

      April 6, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      NASA Astronauts Use iPhones to Capture Historic Artemis II Mission Images

      April 8, 2026

      OpenAI Expands Influence With Strategic TBPN Media Acquisition

      April 8, 2026

      Cybersecurity Veteran Turns Focus To Drone Hacking After Decades Battling Malware

      April 6, 2026

      Anonymous Social App Surges In Saudi Arabia, Testing Limits Of Digital Freedom

      April 6, 2026
      Popular Topics
      Tim Cook Quantum computing Startup Series B Tesla Cybertruck Software Samsung Series A Sundar Pichai Robotics UAE Tech spotlight Taiwan Tech SpaceX Sam Altman Tesla trending Satya Nadella Ransomware Viral
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.