Fake MyChart / patient portal breach lure — "your MyChart account was accessed during a recent security incident, verify identity within 24 hours or access will be suspended" targeting US patients; SSN + insurance ID + DOB + medical-history harvest for medical-identity theft (post-2024 Change Healthcare / Ascension / Kaiser breach era)
fake-mychart-patient-portal-breach-lure
What this tier means
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
How Gorganizer detects this
Fake "your MyChart / patient portal account was accessed during a recent security incident — verify your identity within 24 hours or access will be suspended" email targeting US patients. Harvests SSN + insurance ID + DOB + phone + address + medical history for medical-identity theft downstream (fraudulent prescription runs, Medicare-Advantage plan enrollment fraud, stolen benefits). The 2024 Change Healthcare breach (100M+ records), Ascension ransomware incident, and Kaiser Permanente tracker leak primed patients to expect real "your records may have been affected" notifications, which is why this phish converts. Medical records are the highest-price single identity-theft class on dark markets ($250-1000 each vs. $5-50 for a credit card), so attacker ROI justifies the custom-lure investment. Fires when the body references MyChart / patient portal / Epic / health portal / patient records access AND contains breach / verify-identity / re-authenticate / suspend urgency. Excludes mychart.com, epic.com, kp.org, clevelandclinic.org, hopkinsmedicine.org, mayoclinic.org, partners.org, nyulangone.org, mountsinai.org, cedars-sinai.org, uchicagomedicine.org, mgh.harvard.edu, upmc.com, uclahealth.org, nhs.uk, patient.co.uk, plus .gov / .edu umbrellas. Auto-classified as danger via the `-lure` suffix.
False-positive guard
Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.
About the scoring engine
Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.
Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.
Ready to clean your inbox?
Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.
Get started