A primary reception email account configured with rolling archival settings serves as the central focal point of a newly confirmed security incident at GO2 Health. The multidisciplinary medical practice, which operates out of Brisbane, Australia, and specializes in veteran healthcare services, suffered a localized data breach resulting from a phishing-led Business Email Compromise (BEC) attack. An unauthorized third party successfully compromised and accessed a single internal reception mailbox, exposing sensitive patient information that accumulated over a 12-month period. Although the core patient clinical database remained completely isolated and secure, the compromised inbox contained administrative exchanges, personal identifiers, and Department of Veterans' Affairs (DVA) ID numbers. The compromise of an administrative email account illustrates the persistent threat that phishing poses to the healthcare sector, particularly organizations dealing with specialized community data. In this specific incident, the exposed mailbox acted as an unintended repository for inbound and outbound communication, meaning that any message or attachment sent to the reception address was visible to the threat actor. This configuration expanded the risk from simple account access to a broader exposure of protected health information. According to forensic investigations and subsequent public reports, the unauthorized access was first detected on April 24, 2026. GO2 Health immediately engaged external cybersecurity specialists to contain the breach, secure the compromised environment, and mandate password resets for all personnel with delegated access to the mailbox. However, because the inbox maintained historical correspondence going back approximately one year, investigators spent nearly three months parsing the mailbox logs and auditing email files to identify the exact individuals whose records were compromised. The clinic formally notified the Office of the Australian Information Commissioner (OAIC) on May 18, 2026, and initiated patient notifications in July 2026. This incident highlights a major vulnerability in modern healthcare administration: the reliance on shared, high-traffic email inboxes as long-term storage mechanisms. Reception mailboxes frequently receive highly sensitive attachments, including medical referrals, identification documents, and intake forms. When these files are left in the inbox folder indefinitely without strict retention controls, they become high-value targets for opportunistic attackers who gain access via basic phishing campaigns.