Business email compromise (BEC) can look deceptively simple at first.

A healthcare employee’s Microsoft 365 account is compromised. Maybe someone clicked a convincing sign-in link, approved an unexpected MFA request, or entered credentials into a page that looked legitimate. The organization resets the password, regains access to the account, and assumes the immediate problem has been solved.

But regaining control of the mailbox is only the beginning.

In a healthcare environment, a compromised email account can give a threat actor access to far more than email. The account may contain protected health information (PHI), personally identifiable information (PII), payment information, employee records, confidential business communications, or credentials and links to other systems. An attacker may also use a trusted employee’s identity to communicate with patients, vendors, executives, or other employees.

At that point, you are no longer dealing with just an email problem. You may be dealing with an identity compromise, financial fraud, privacy incident, and broader security event simultaneously.

What your organization does during the first 24 hours is absolutely critical.

Contain the Compromised Identity

The immediate objective is to stop the attacker from continuing to use the compromised account and search for additional accounts and services that may have been impacted.

This typically means disabling affected sign-ins, revoking all active sessions, resetting credentials, re-registering MFA where appropriate, and identifying and blocking suspicious applications or devices.

But speed beyond containment should not come at the expense of evidence.

One of the biggest mistakes organizations can make (especially those that are regulated) during a BEC incident is rushing to clean up the environment before looking for and preserving the information needed to understand what happened.

Deleting suspicious messages, removing inbox rules, or making widespread changes without first documenting the environment can destroy valuable evidence. This also puts you at a major disadvantage when dealing with post-event regulatory, legal, and criminal investigations that often occur.

The objective is not simply to get the employee back into their email; it is to eject the criminal attacker while preserving your ability to investigate them.  Changing a password is not an investigation or risk assessment, which is required after such an event in a healthcare and other regulated environment.

Preserve the Evidence Before You Clean Up

Once the immediate threat is contained, preserve the evidence surrounding the compromised identity.

Gather audit logs quickly as they may overwrite with time or space limitations. Get logs for sign-in and suspicious messages (including, sent, received, forwarded or deleted). Then check and get logs for inbox and forwarding rules, MFA changes, OAuth permissions, mailbox delegates, unusual searches or downloads, and other activity may help establish how the attacker gained access and what they did in the environment. This is vital because if the incident is investigated by state and federal law enforcement, or you receive a subpoena or other inquiry that requires facts, you will need them.

Accurately record actions taken during the response. Capture who did them and when they occurred. Preserve suspicious communications rather than simply deleting them. If possible, maintain a clear chain of custody for evidence that could become relevant to an insurance claim, legal review, regulatory inquiry, or forensic investigation.

Your goal is to understand what happened before, during, and after the initial compromise.

Determine What the Attacker Could Access

Once the account is contained and evidence is preserved, the next question is scope.

Start with the affected identity, but do not assume the incident ends there. Use the logs you gathered and current settings to determine whether the attacker accessed additional accounts, established forwarding rules, added mailbox delegates, registered new MFA methods, granted OAuth applications access, or used the compromised account to target other employees.

You must assume that whatever the criminal actor had access to, they viewed or copied. This could be by forwarding, printing, screenshots, or even camera images.  With this in mind, carefully inventory the data in the impacted accounts and consider what could have been taken. For a healthcare organization, that means asking questions such as:

  • Was PHI or PII present in the mailbox or its attachments?
  • Were messages viewed, searched, downloaded, exported, deleted, or forwarded?
  • Which patients, employees, vendors, or other individuals may have been involved?
  • Was institutional financial, payroll, or individual payment information accessible?
  • Did the attacker communicate with patients, payers, vendors, executives, or employees?
  • Is there evidence of activity elsewhere in the environment?

The goal is to establish what sensitive information may have been viewed or taken and who would be impacted.

Treat Potential Payment Fraud as an Immediate Priority

BEC frequently succeeds because the attacker does not need to defeat another technical control. They can simply exploit the trust associated with the account they already control.

A compromised executive, physician, finance employee, or vendor account can be used in many nefarious ways:

  • Medical identity theft through unauthorized access to patient records, insurance information, Social Security numbers, and protected health information (PHI).
  • Financial fraud by requesting fraudulent wire transfers, creating unauthorized payments, or redirecting customer and vendor funds.
  • Payroll diversion by changing direct deposit or ACH information and rerouting employee paychecks to attacker-controlled accounts.
  • Vendor payment fraud by altering vendor banking details, intercepting invoices, or submitting fraudulent invoices that appear legitimate.
  • Patient and organizational extortion by threatening to release stolen medical records, financial information, confidential communications, or sensitive business data.
  • Insurance fraud through the submission of false claims or manipulation of patient billing information.
  • Prescription and healthcare fraud by gaining access to clinical systems, patient portals, or prescribing workflows.
  • Contract and invoice manipulation by modifying payment terms, account numbers, refund instructions, or purchase orders.
  • Credential harvesting and lateral movement by using the compromised account to target additional employees, executives, patients, or business partners.
  • Reputational damage resulting from public disclosure of compromised patient information, financial losses, regulatory investigations, and loss of stakeholder trust.

If there is any possibility that financial instructions were affected, pause unverified transactions associated with the incident until they can be independently confirmed.

And independently is the important word.

Do not verify a banking change by replying to the same email. Do not call a phone number supplied in the suspicious message. Do not assume a vendor portal is legitimate simply because a link was provided. Use a previously known telephone number or a separately verified trusted system to confirm the request.

If funds may have already moved, contact the appropriate financial institution immediately and preserve the receiving account and transaction information.

BEC can turn from an email incident into a significant financial loss or privacy breach very quickly.

In Healthcare, You Also Have to Ask: Was Protected Health Information (PHI) Involved?

Healthcare organizations have an additional layer of responsibility because a compromised mailbox may contain or provide access to PHI.

Was PHI present? Could the compromised account access it? Is there evidence that messages containing PHI were viewed, searched, exported, downloaded, or forwarded? Was the information encrypted or otherwise protected?

Those questions should be addressed as part of a documented privacy and breach assessment with the appropriate legal, privacy, cyber insurance, and qualified incident-response resources.

The technical investigation and privacy breach risk assessment should inform one another.

Your technical team needs to determine what occurred. Your legal and privacy teams need reliable evidence to evaluate what that means for your organization.

A Password Reset Does Not Remove Persistence

Endpoints used during the compromise should also be investigated where appropriate to be sure no access tools or malware were left behind.

The Next BEC May Not Look Like the Last One

BEC has evolved well beyond the badly written phishing emails many employees have been taught to recognize.

Healthcare employees should be prepared for executive and physician impersonation, vendor invoice changes, payroll direct-deposit requests, fake Microsoft 365 sign-in prompts, MFA fatigue attacks, QR-code phishing, secure-message or e-fax lures, overdue-payment notices, and urgent requests designed to bypass normal processes.

Attackers understand that urgency changes behavior.

A request appearing to come from a physician between patients, an executive traveling, a vendor waiting on payment, or a patient needing immediate assistance can pressure an employee into acting before verifying.

That is why the simplest response can also be one of the most effective:

Stop. Verify independently. Escalate.

Employees should know how to report suspicious activity, and they should be empowered to slow down an unusual request without worrying that they are obstructing the business.

After the Incident, Fix the Process That Allowed It to Succeed

Recovering the compromised account should not be the end of the response.

The incident should tell you where your controls need to improve.

For identity and access, that may mean requiring MFA across users and administrators, moving toward phishing-resistant authentication for higher-risk roles, blocking legacy authentication, applying Conditional Access, separating administrative accounts, and enforcing least privilege.

For email, it may mean strengthening anti-phishing and impersonation protection, malicious-link inspection, attachment sandboxing, external-sender labeling, SPF, DKIM, and DMARC.

For mailbox security, external forwarding may need to be disabled or tightly controlled, with alerts for new forwarding rules, delegate changes, suspicious OAuth consent, mass deletions, and anomalous mailbox activity.

And some of the most important improvements may have nothing to do with the mailbox itself.

Payment changes should never be approved solely through an email or incoming phone call. Wire transfers, ACH changes, refunds, payroll changes, and vendor banking updates should have documented verification procedures and, where appropriate, dual approval.

The objective is to build a process where compromising one employee’s email account is not enough to authorize a significant financial or operational action.

What the Next 30 Days Should Accomplish

After the immediate incident is contained, use the next several weeks to make the organization materially harder to compromise again.

Validate MFA coverage. Remove unauthorized access. Harden administrator accounts. Disable uncontrolled forwarding. Review finance, payroll, refund, and vendor-change workflows. Make sure high-risk alerts have an owner and escalation path.

Then train the people most likely to encounter these attacks: executives, clinicians, finance teams, HR, help desk personnel, and administrative staff.

Finally, test the response.

A tabletop exercise can expose gaps that are difficult to see on paper. Can employees report suspicious activity quickly? Does IT know who to escalate to? Does finance know how to verify a payment change? Does leadership know when legal, privacy, insurance, or outside incident-response resources need to become involved?

An incident response plan is only useful if the organization can execute it under pressure.

BEC Is Not Just an Email Problem

When a healthcare organization discovers a compromised email account, the objective should not simply be to reset the password and move on.

You need to determine how the attacker got in, what they accessed, what they changed, who they communicated with, whether sensitive information or financial transactions were affected, and whether they established another way back into the environment.

The first 24 hours can significantly influence how effectively you answer those questions.

Contain the identity. Preserve the evidence. Determine the scope. Protect financial workflows. Assess potential PHI exposure.

Then use what you learn to close the gaps that allowed the incident to happen in the first place.

If your healthcare organization is dealing with a suspected business email compromise, Alvaka is available 24/7, 365 days a year to help contain the incident, investigate the scope, and determine the path forward.

 

Written by Sarah Accongio, Market Development Specialist at Alvaka