Business Email Compromise: How Fake Invoices Drain Care Operators

Not every cyberattack involves malware. In business email compromise (BEC), criminals use email to trick someone into sending money or changing payment details. There may be no virus at all, just a convincing message. The FBI's Internet Crime Complaint Center has long identified BEC as one of the costliest forms of cybercrime, and care operators with busy accounts payable teams and many vendors are natural targets.

How the Scam Works

Impersonating an executive

A message appears to come from the administrator, owner or CFO and asks a business office employee for an urgent wire transfer, gift cards or a change to payroll direct deposit. It may say the sender is in a meeting and cannot talk.

Impersonating a vendor

A supplier, pharmacy, contractor or software company seems to send an updated invoice with new bank details "because we changed banks." The invoice looks real because the attacker may have copied a genuine one.

Hijacking a real conversation

If an attacker has broken into a real email account, they can reply within an existing thread about an invoice, which is extremely convincing. They may also set up hidden forwarding rules to watch your messages.

Payroll diversion

An email that appears to come from an employee asks HR to change direct deposit to a new account.

Attorney or closing scams

During a sale, refinance or construction project, a message appears to come from a lawyer or title company with wiring instructions.

Why Care Organizations Are Vulnerable

High-value payments to many vendors

Staff who handle accounts payable alongside other duties

Multiple facilities or owners and a distance between decision makers

A culture of helpfulness and quick response

Email accounts without multi-factor authentication

Warning Signs

A request to change bank details or payment method

Urgency, secrecy or a request not to call

A sender address that is almost, but not quite, right

A reply-to address that differs from the sender

Unusual wording from a person who writes differently

Payment to a new account in a different city or institution than usual

An executive asking staff to handle something "quietly"

Controls That Stop Most Losses

1. Verify changes by a second channel

Any request to change bank details must be confirmed by calling a phone number you already have on file, not one in the email. Make this a written policy with no exceptions for executives.

2. Require two approvals

For payments above a set amount, or any new payee, require two people to review and approve.

3. Slow down first-time payments

A waiting period for new vendor payments gives time to verify.

4. Use multi-factor authentication

This helps prevent account takeovers that fuel the most convincing scams.

5. Mark external email

Banners that flag messages from outside your organization help staff notice impersonation.

6. Look for suspicious email rules

Have IT periodically check for forwarding rules and unusual sign-ins in email accounts.

7. Train the right people

Focus on accounts payable, payroll, HR and executive assistants, and use real examples.

8. Talk to your bank

Ask about positive pay, payee verification and what can be done if a fraudulent wire is sent.

If a Fraudulent Payment Goes Out

Time matters enormously.

Contact your bank immediately and ask them to recall or freeze the transfer.

Notify your insurer, since policies often have short reporting windows.

File a report with the FBI's Internet Crime Complaint Center and local law enforcement.

Have IT investigate the email accounts involved and reset credentials.

Preserve the messages for investigators.

Check whether protected health information was exposed, which might trigger HIPAA analysis.

Insurance Notes

Funds transfer fraud and social engineering coverage may be subject to lower limits or specific conditions, such as verification procedures. Ask your broker.

A One-Page Policy to Write This Week

No bank detail changes without call-back verification

Two approvals above a threshold

Executives cannot request exceptions by email

Suspicious requests are reported to a named person

Quarterly reminders for finance staff

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations tighten email security, add MFA and investigate suspicious account activity. If you would like a review of your email protections or help drafting a verification policy, we are glad to help.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172