Not every cyberattack involves ransomware or stolen medical records. Some of the most costly incidents involve a simple email that convinces someone to send money to the wrong place. This is business email compromise, or BEC, and care providers are attractive targets because they handle large payments, rely on many vendors and often run lean business offices.
BEC works because it targets people and processes, not software. Understanding how it unfolds helps you build checks that stop it.
An attacker sends an email that appears to come from the administrator, owner or CFO and asks the business office to make an urgent payment or buy gift cards. The display name is right, but the address may be from a lookalike domain or a free email account. Sometimes the attacker has actually compromised the executive's mailbox, which makes the message far more convincing.
A message arrives, apparently from a real supplier, saying their bank details have changed and asking you to pay the next invoice into a new account. Attackers often hijack a real email thread, insert themselves into the conversation and wait until an invoice is due.
Someone posing as an employee writes to HR or payroll asking to update direct deposit information. The next paycheck goes to the attacker.
A realistic invoice for services you might plausibly use, such as software, supplies or equipment maintenance, arrives from an unfamiliar company in the hope that no one will check.
When an attacker steals a password, perhaps through phishing, they may read email for days or weeks, learn how your organization handles payments and then send convincing messages from a legitimate account. They may also create hidden inbox rules that forward or delete messages to cover their tracks.
Requests for urgency and secrecy, such as "keep this confidential until the deal is done"
Changes in payment details or a new bank account for an existing vendor
An executive who is traveling or unavailable to confirm by phone
Slight changes in email addresses or writing style
Requests to use gift cards, cryptocurrency or wire transfers outside normal channels
Pressure to skip the usual approval process
Any request to change payment instructions should be confirmed by calling the vendor at a number from your own records, not from the email. Make this an unbreakable rule, even for small changes and even when the request seems to come from a trusted contact.
Payments over a set threshold, and all changes to vendor banking details, should need approval from two people. One person alone should not be able to create a vendor, change the account and release payment.
The person who receives invoices should not be the same one who approves payment and sets up payees.
Turn on multi-factor authentication for all email accounts, especially those of executives, finance and HR staff. Review mailbox rules for unexpected forwarding. Set alerts for sign-ins from unusual locations.
Ask your IT provider to configure SPF, DKIM and DMARC for your domain, which help prevent others from sending email that appears to come from you. Enable warnings on messages from outside the organization.
Business office, accounts payable and payroll staff should receive specific training with real-looking examples. Give them explicit permission to pause a payment and question a request, even if it appears to come from the top.
Contact your bank immediately and ask whether the payment can be recalled. Speed matters a great deal.
Notify your IT provider so that affected mailboxes can be secured and reviewed.
Report it to the FBI's Internet Crime Complaint Center (IC3), and to your cyber insurance carrier if you have a policy.
Preserve the original emails, including headers.
Review whether any protected health information was exposed. If a mailbox was compromised, the contents may need to be assessed under the HIPAA Breach Notification Rule.
Staff are more likely to stop a scam if the process is routine and leadership supports it. Executives should say aloud, "If I ever email you for an urgent payment, call me first." That one sentence can prevent a serious loss.
We help healthcare organizations secure email, configure domain protections and write payment verification procedures that accounting teams can actually follow. If you would like a quick review of your email security and payment approval process, we can walk through it together.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172