Mothers Day weekend was a busy one for me, we had a client that needed overflow done but my boss and I were having problems navigating the client's EMR system, so we had to go through IT department to have them download this properly. Saturday evening, I had work IT people on my computer, so the issue got fixed and I was working in the website, and somebody pinged in. Without thinking when the ping came up I allowed this thinking it was my IT department checking back into see if the 3rd party site was functioning okay or that it was a staff monitor in the clients' EMR system, when in fact it became apparent after about a minute it was not my IT department, nor was it anyone associated with the client. Come to find out, the window or site that our India IT work counterpart used to have remote access to my computer was left open and not shut, which therefore left me wide open for hackers.
Now, I consider myself an intelligent being, and I would never allow anyone access to my computer remotely (except my IT department from work), so I was not concerned at this point, but when he asked me my phone # and after I answered and realized it was not our IT guy, "Kash", rather some guy from India clearly struck a little fear inside the pit of my stomach. He was trying to tell me I won a gift, and in order to get it, I would have to put in my 'personal information' well, he was very bossy and rude, that didn't go over really well, and I ordered him to get out of my computer immediately. He was trying his best to scam me out of money says my IT department, bringing up a Western Union screen, then probably going to run a scan to scare me (which would not have worked either), but after only a few minutes, I got him out of my computer and all systems were cleared after a few phone calls and scans, thank God. I immediately reported this to my IT department (which I feel should not have left me wide open), but the afterthought for me was that I was in a client's EMR which had pt names and personal information and this really scared me thinking that privacy could have been invaded. I also had a name and phone # of this individual, so our IT department was going to track it down; also this information was given to Microsoft and HP for purposes of tracking and identifying the culprit.
Not to mention, attached to my work computer is a router and I have a personal PC, of course my first thought was does this guy have access to my personal information, bank accts, etc.. I had email open and all kinds of stuff, so in order to further thwart off any attacks to any personal information he could have gotten into or downloading some tracking program, I opted to change my bank accounts and online information. This was probably something I didn't have to do, but in the back of your mind you are thinking months later you'll check in and poof! your identity and/or your bank accounts and all have been stolen or depleted...it was a nightmare just to think about it, but both computers have run efficiently without any problems, the only thing was the scare of it, and the timing of it, as I happen to have a portal open. I do hope that our IT team which was based in India at the time of all of this, has decided upon something else to use besides that remote access site. They should have known the dangers. This really was upsetting to me personally, as well as to my boss.
Clearly hacking and scamming have become the #1 professional activity for criminals, as no longer do they have to wear ski masks and carry a gun, or break in-home to steal, such as this latest scary heist,
NY Times.