Not every cyberattack involves ransomware or locked screens. One of the quietest and costliest is business email compromise, often shortened to BEC. A criminal pretends to be a vendor, an executive or a coworker and persuades someone to send money or change payment details. There is no malware and nothing to detect on a computer. The attack succeeds through a convincing email and a hurried employee.
Business offices at nursing homes and senior-living communities are natural targets. They pay many vendors, handle payroll and answer to administrators who are often away from their desks. This guide covers how the scam works and a routine that stops most attempts.
An email that appears to be from the administrator or owner asks the business office manager to make an urgent wire transfer, buy gift cards or pay an invoice. The sender address may be a lookalike domain, or the display name may simply match.
An attacker gains access to a real vendor's mailbox, reads the conversation about an invoice, and sends a message in the same thread with "updated" bank details. Because it arrives in the middle of a genuine conversation, it feels legitimate.
A message that looks like it came from an employee asks HR to change direct deposit information to a new account.
A staff member's mailbox is compromised through phishing. The attacker sends requests from the real account, often creating hidden forwarding rules to monitor replies.
Urgent or secret requests, especially ones that discourage verification
A change in bank account, routing number or payment method
Requests to pay by wire, gift card or cryptocurrency
Slight differences in the sender address, such as a swapped letter
Tone or phrasing that is unlike the usual sender
Requests that arrive when the real person is traveling or unreachable
Pressure to bypass normal approvals
The strongest defense is a simple procedure that does not depend on spotting every fake.
Verify any change in payment details by phone, using a number you already have on file, not one in the email.
Require two people to approve new vendors and changes to existing vendors.
Use a callback script with a question only the real vendor would know, such as a recent invoice number.
Set a payment threshold above which a second approval is mandatory.
Never act on gift card or wire requests by email. Confirm in person or by phone.
Hold new bank details for a waiting period before the first payment, when practical.
Treat payroll changes the same way. Confirm direct deposit changes with the employee in person or through the HR system.
Put the routine in writing and tell vendors you will follow it. Legitimate vendors will understand.
Multi-factor authentication on all email accounts, especially in finance and administration
Email authentication records (SPF, DKIM and DMARC) on your domain so that others cannot easily spoof it
External sender banners that flag messages from outside your organization
Alerts for mailbox forwarding rules and unusual sign-ins
Impersonation protection in your email filter, which detects lookalike domains and names
These measures do not catch everything, which is why the human routine remains essential.
Speed matters. If you suspect a fraudulent payment:
Call your bank right away and ask them to recall or freeze the transfer.
Notify your IT provider so the mailbox can be secured and reviewed.
Contact your cyber insurance carrier, since some policies cover social engineering fraud.
Report the incident to law enforcement, such as the FBI's Internet Crime Complaint Center.
Preserve emails and records for the investigation.
Consider whether any PHI was exposed in the compromised mailbox. If so, your HIPAA breach analysis applies.
Short scenarios work better than lectures. Spend ten minutes at a staff meeting walking through a fake invoice, a spoofed administrator request and a payroll change. Ask people what they would do. Reward the person who questions something suspicious.
Also make sure administrators know that they should never be offended when someone calls to confirm an unusual request. Verification is the policy, and it protects everyone.
Ask yourself a few questions. Who can approve payments? Can one person change bank details alone? Is MFA enabled on every finance mailbox? Does your email filter catch lookalike domains? If any answer is unclear, there is room to improve.
UnityCare IT helps healthcare organizations secure email, set up domain protections and write practical payment verification procedures. If you would like a review of your email security settings, we can start there.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172