
Canadian Health Workers Furious After Fake 'Day Off' Email Turns Out to Be a Cybersecurity Trap
Exhausted healthcare workers in Newfoundland were briefly overjoyed by a promised paid holiday — only to discover it was an internal phishing test.
Healthcare Workers Deceived by Fake Paid Holiday Email in Newfoundland
For healthcare workers in the Canadian province of Newfoundland and Labrador, the daily grind has become increasingly difficult to bear. Chronic understaffing, relentless burnout, and shrinking resources have driven many employees in the sector to the edge of their limits. So when a cheerful email landed in thousands of their inboxes recently, it briefly felt like long-overdue relief had finally arrived.
The Email That Sparked Outrage
The message, carrying the subject line "June Holiday," appeared to come as a genuine gesture of gratitude from health service leadership. It acknowledged the enormous effort staff had put in — including hundreds of hours of mandatory overtime — during the challenging rollout of a new digital health platform known as CorCare. The email praised employees for their dedication and professionalism, stating that the organization recognized the weight of what workers had carried through such a demanding period of change.
As a token of appreciation, the message promised a paid day off. Staff were simply asked to click a link to claim their well-earned break.
There was, however, one telling red flag: the email had been sent from an external domain — remailmail.com — rather than an official organizational address.
The Cruel Twist
The joy was short-lived. The very next day, workers discovered the shocking truth: the entire thing had been staged. The "June Holiday" email was, in reality, an internal cybersecurity awareness drill designed to identify employees who would click on suspicious links — a classic phishing simulation.
For staff who had already been denied actual vacation days during the CorCare implementation, the revelation hit hard. Anger and disbelief spread rapidly through the workforce.
Jerry Earle, president of the Newfoundland and Labrador Association of Public and Private Employees, did not mince words in his response.
"Our members deserve better than to be taunted with the promise of a day off after the incredible amount of work and sacrifice they made to get CorCare up and running," he said in a public statement, describing the incident as a "cruel hoax" that left him and his colleagues feeling "disgusted."
Earle further revealed that the email had pushed at least one employee over the edge, calling it the "straw that broke the back" for an already burned-out workforce.
Nurses and Union Leaders Speak Out
Yvette Coffey, president of the Registered Nurses' Union Newfoundland and Labrador, shared similar frustrations. Speaking to CBC News, she explained that the stress of mandatory overtime combined with repeated denials of vacation requests had already driven some workers to resign during the CorCare rollout. She described the phishing test as "very insensitive and very disrespectful" to union members, and called for someone to be held accountable.
Sherry Hillier, president of CUPE Newfoundland and Labrador, also weighed in sharply.
"While I understand that cybersecurity awareness is important, especially in a healthcare setting, targeting a benefit like paid time off is disgusting," she said. "These workers are tired, burned out, and desperate for time off. As the employer, NL Health knows that and chose to exploit that feeling anyway."
Why Cybersecurity Matters — But This Still Crossed a Line
The context behind the test is worth noting. Healthcare institutions across Canada have become prime targets for cybercriminals seeking to freeze hospital systems and demand ransoms. Newfoundland itself has painful experience with this threat: a significant cyberattack in 2021 knocked critical healthcare computer systems offline for several months. Phishing emails — malicious messages disguised as legitimate communications — are a common method used by hackers to gain access to secure systems.
The need for staff education on cybersecurity threats is real. But the manner in which this particular test was executed struck a deeply sensitive nerve.
Management Apologizes, But Critics Say It Is Not Enough
Health service leadership moved quickly to issue an apology once the backlash erupted. Ron Johnson, the health board's interim CEO, acknowledged that the exercise had failed to reflect the organization's values.
"We are taking a step back to review how these exercises are developed and communicated to ensure they reflect the respectful and supportive culture we strive to foster," Johnson wrote in a statement. He later told reporters directly that the test "really missed a mark" and was "not reflective of how we value our employees."
An internal investigation was also announced to examine how the email was conceived and approved.
Despite the apology, union leaders remained largely unsatisfied, arguing that the acknowledgment failed to capture the depth of disappointment and hurt felt by frontline workers who had given so much and received so little in return.
A Workforce Already at Its Breaking Point
This incident shines a harsh light on the fragile state of healthcare staffing in Newfoundland and Labrador — and arguably across Canada as a whole. When workers are so depleted that the mere promise of a single day off can generate genuine excitement, it speaks volumes about the conditions they are enduring. Exploiting that vulnerability, even unintentionally, risks further eroding trust between healthcare employees and the institutions that depend on them.
For many workers, this was not just a poorly timed cybersecurity drill. It was a painful reminder of how little they feel seen and valued by the systems they sacrifice so much to support.

