What Is Business Email Compromise and How Do Healthcare and Manufacturing Organizations Stop It?

Business email compromise (BEC) is a fraud attack in which an attacker impersonates a trusted person — typically an executive, a vendor, or a colleague — to manipulate a target into transferring money, redirecting a payment, or sharing sensitive information. It caused $2.9 billion in verified losses in the most recent FBI reporting period, making it one of the most financially damaging cyber threats facing organizations today. Stopping it requires three controls applied together: MFA on all email accounts, out-of-band verification for financial transactions, and security awareness training specific to impersonation tactics.

How Does Business Email Compromise Work?

BEC works by exploiting trust rather than technology. The attacker doesn’t need to breach a firewall or deploy malware. They need a believable identity and a target who acts before verifying.

The most common BEC scenarios follow recognizable patterns:

BEC Scenario

How It Works

Target

Executive impersonation

Attacker spoofs or compromises the CEO or CFO’s email; requests urgent wire transfer.

Finance staff, controllers

Vendor payment redirect

Attacker impersonates a known vendor; sends updated banking details before a payment is due.

AP departments, office managers

Payroll diversion

Attacker impersonates an employee; requests direct deposit account change.

HR, payroll administrators

Invoice fraud

Attacker sends a convincing invoice from a spoofed vendor domain.

Anyone with payment authority

Account takeover

Attacker gains access to a real email account; uses it to conduct BEC from inside the organization.

Anyone the compromised account communicates with

The account takeover scenario is the most dangerous because the email is genuinely from the legitimate account; in other words, it’s NOT a spoof. There’s no suspicious sender address to flag. The communication looks exactly like every other email from that person.

Why Are Healthcare and Manufacturing Organizations Targeted by BEC?

Healthcare and manufacturing organizations are targeted by BEC because both industries handle high-value transactions, operate under time pressure, and maintain complex vendor and supplier relationships that create realistic impersonation opportunities.

In healthcare, BEC targets include medical supply payments, insurance reimbursements, payroll for large clinical staff, and executive financial approvals. The clinical urgency that characterizes healthcare workflows — where speed matters and staff are often context-switching — creates an environment where a request that looks legitimate gets acted on before it gets verified.

In manufacturing, the attack surface includes supplier payments, equipment purchases, logistics invoices, and procurement approvals. Supply chain relationships with dozens or hundreds of vendors create a large pool of trusted identities for attackers to impersonate. Changes in banking information, new invoicing contacts, and payment deadline urgency are all realistic scenarios that give BEC attempts cover.

Both industries also tend to have the organizational structure BEC exploits: a small number of people with payment authority, a culture of deference to executive requests, and communication patterns that make an urgent email from leadership feel normal rather than suspicious.

What Controls Actually Stop Business Email Compromise?

Three controls, applied together, stop the majority of BEC attempts: MFA on all email accounts, out-of-band verification for financial transactions, and security awareness training that specifically addresses impersonation.

Multi-factor authentication on email eliminates account takeover as an attack vector. If an attacker obtains email credentials through phishing or credential stuffing, MFA prevents them from accessing the account. This doesn’t stop spoofing — an attacker can still send email that looks like it comes from an executive — but it closes the most dangerous BEC variant, in which the email actually comes from a compromised legitimate account.

Out-of-band verification means confirming any financial transaction initiated by email through a separate, independent channel before the transaction is executed. This means calling a known phone number, confirming through a second communication channel, or using an internal approval workflow that requires a second authorized person. The rule should be simple and written down: no wire transfer, no banking change, and no payment redirect is executed based solely on an email request.

Security awareness training specific to BEC teaches staff to recognize impersonation tactics: urgency language, unusual requests from executive accounts, vendor email domains with subtle variations, and requests to bypass normal approval processes. Generic phishing training that focuses on malicious links and attachments doesn’t fully address BEC, because many BEC attempts don’t contain either. Training has to be specific to the scenarios staff will actually encounter.

What Should Healthcare and Manufacturing Organizations Do if They Receive a Suspicious BEC Email?

If staff receive a suspicious BEC email, they should not reply to it, not act on any financial request it contains, and report it immediately to IT or the security team using the organization’s established reporting process.

The most important behavioral instruction is the one that’s hardest to follow under pressure: slow down. BEC attempts almost always include artificial urgency, such as “the CEO needs this done before end of day,” or “the vendor will lose the contract if payment isn’t redirected by Friday.” That urgency is engineered. It’s designed to compress the time between receiving the email and acting on it, because verification is what BEC attempts can’t survive.

A documented, trained response process gives staff something to fall back on when the pressure is high: here is what I do when I get a request that asks me to move money or change payment information. I call this number. I contact this person. I do not act until I hear back.

Vertikal6’s ADVANTAGE service works with healthcare and manufacturing organizations to build the security awareness programs and financial control processes that stop BEC before it costs anything. The controls aren’t complicated. What they require is intention and specificity.

Recent Posts

We use cookies to improve your experience on our website. By browsing this website, you agree to our use of cookies.