Cloud-based allied health practice management software provider Power Diary suffered an authorized session token bypass. Threat actors used the compromised developer panel to blast malicious medical phishing and spam emails directly to patients.