Business Email Compromise: How Fake Invoices Drain Care Budgets

Not every cyberattack involves encrypted files or ransom notes. One of the quiet, costly threats to healthcare organizations is business email compromise, often shortened to BEC. The attacker's goal is simple: convince someone with access to money to send it to the wrong place.

For care operators, the targets include accounts payable, payroll and the administrator's office. This post explains how these scams work and the controls that stop them.

How the scam works

The impersonated vendor

An email arrives that appears to come from a regular supplier, contractor or staffing agency. It says the bank account has changed and asks that future payments go to a new account. The message may use real invoice numbers and a familiar tone, because the attacker has been reading the vendor's mail or has copied past messages.

The impersonated executive

A message appears to come from the owner or administrator, asking the business office for an urgent wire or a set of gift cards, and saying they are in a meeting and cannot talk.

The payroll diversion

An email, supposedly from an employee, asks HR to change direct deposit details before the next pay run. Sometimes the attacker has actually taken over the employee's mailbox.

The compromised mailbox

In the most damaging versions, the attacker has real access to a mailbox through a stolen password. They set up hidden forwarding rules, watch for payment conversations and step in at the right moment.

Warning signs

A first-time request to change banking details

Pressure to act quickly or keep the request quiet

A reply-to address that differs slightly from the real one, such as one letter swapped

Writing style that is a little off, or a signature block that does not match previous messages

An executive asking for something outside normal process

A request to move the conversation to text or a personal email address

Controls that actually work

1. Call-back verification

Any request to change payment details must be confirmed by calling a phone number you already have on file, never one in the email. Make this a written rule, with no exceptions for urgency or seniority.

2. Dual approval

Require two people to approve new vendors, banking changes and payments above a threshold you set. The second approver should see the verification evidence.

3. Payroll change process

Handle direct deposit changes through a secure portal or in person, with identity confirmation, and send a notification to the employee's previous contact information.

4. Multi-factor authentication on email

MFA greatly reduces the chance of a stolen password turning into a taken-over mailbox. Disable legacy email protocols that bypass it.

5. Email protections

Turn on external sender banners, impersonation protection for executive names, and alerts for new forwarding rules. Configure SPF, DKIM and DMARC for your own domain so that others cannot easily spoof you.

6. Training for the right people

The business office, HR and administrative assistants are the primary targets. Give them focused sessions with examples of real-looking requests.

If money has already been sent

Speed is everything. Take these steps immediately:

Call your bank and request a recall or hold on the transfer.

Contact your bank's fraud department and ask them to reach the receiving bank.

File a report with the FBI Internet Crime Complaint Center at ic3.gov.

Notify your cyber or crime insurer.

Have IT investigate the mailbox for rules, sign-in history and forwarding.

Reset passwords and revoke sessions for affected accounts.

Because a BEC incident may involve a compromised mailbox containing protected health information, also consult your privacy officer about whether a HIPAA breach assessment is needed.

Make verification a habit

The goal is to make the safe step the normal step. Write a one-page procedure, post it in the business office, and thank employees who pause to verify, even when the request turns out to be genuine. UnityCare IT can help secure your email environment, set up the alerts and authentication that block spoofing, and train your accounting and administrative staff. Contact us if you would like an email security review.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172