HHS Issues Warning to HPH Sector About Business Email Compromise Scams
The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) has issued a warning to the healthcare and public health (HPH) sector about business email compromise (BEC) scams. BEC, also known as email account compromise (EAC), is one of the costliest types of cybercrime. According to the Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3), more than $2.9 billion was lost to BEC attacks in 2023, with average losses of $125,000. Between October 2013 and December 2022, IC3 received 277,918 domestic and international reports of BEC attacks and reported losses of $50,871,249,501.
BEC is a sophisticated scam that targets businesses in multiple sectors, including healthcare. BEC attacks typically start with phishing emails. The threat actor uses phishing to steal the credentials for a business email account and searches the account to identify information that can be used in the scam and potential targets.
Emails are then crafted that impersonate the legitimate account holder and social engineering techniques are used to trick victims into disclosing sensitive information, such as W-2 information, or making fraudulent wire transfers. The scammer may generate fake invoices or ask for changes to be made to bank account information for upcoming payments.
Since the emails are sent from legitimate and trusted email accounts and they lack suspicious links and attachments, they are often not detected as malicious by email security solutions or put in an email sandbox. The threat actor learns the writing style of the person they are impersonating which makes it difficult for victims to identify the scam. When changes are made to account information, the scam is often only detected when the vendor queries why a payment has not been made, by which time the scammer has withdrawn the funds from their account.
Two of the most common types of BEC attacks are attorney impersonation and CEO fraud. Attorney impersonation involves an urgent request for a wire transfer. Low-level employees often comply with a request from a lawyer as they do not know how to validate the request and want to avoid negative consequences. With CEO fraud, the attacker compromises the email account of the CEO or another C-suite executive and uses it to send requests for wire transfers or gift card purchases. This type of BEC attack takes advantage of the power dynamic within the company, with employees often falling for the scam as they are unwilling to question any requests from the CEO or C-Suite executives.
BEC attacks involve deep reconnaissance and research, which is often conducted over several days or weeks. The attackers learn as much as possible about the company from emails and other research, including business processes and workflows, who is responsible for making payments and invoicing, and details about payments to vendors and billing schedules. BEC attacks are often meticulously planned.
These attacks exploit human rather than technical weaknesses so the first line of defense against BEC attacks is a well-informed workforce. Employees should be provided with regular security awareness training and be educated about BEC attacks and verifying sender information. Phishing simulations should be conducted on the workforce to test responses to the different types of BEC attacks. Phishing simulations help to reinforce training and give employees practice at identifying and reporting potential scams.
Policies should be implemented that require employees to verify certain requests with a call to a verified phone number, such as any request to change banking information or to make an out-of-band wire transfer. Attacks may spoof internal email accounts, so adding a banner to emails from external sources can help employees identify spoofed emails. Advanced email security and anti-phishing solutions with AI and machine learning capabilities can identify red flags in BEC attacks and add warnings to emails to alert employees about a potential threat and DKIM, SPF, and DMARC should be used for sender verification. Healthcare organizations should also implement multifactor authentication on all email accounts to protect against phishing and conduct regular security audits to identify vulnerabilities in the email system.