Ten Charged with BEC Healthcare Scheme That Took More than $11 Million

Stu Sjouwerman | Dec 14, 2022

BEC Healthcare ScamTricking five state Medicaid programs, two Medicare Administrative Contractors, and two private health insurers, the scammers posed as hospitals to alter payment details.

Apparently, all it takes is some rather simple impersonation of a legitimate business and some savvy social engineering to take in millions. According to the U.S. Department of Justice, a group of ten scammers based in Georgia and Virginia were indicted on charges of business email compromise and money laundering.

The group pretended to be legitimate hospitals, communicated with Medicare, Medicaid, health insurance companies, and other victims, using well-crafted email communication to trick unsuspecting victims into modifying payment details to send reimbursement payments to scammer-controlled bank accounts.

In total, $4.7 million in losses were experienced by Medicare, Medicaid, and private health insurers, with $6.4 million in losses to other federal government agencies, private companies, and individuals.

Phishing, as part of a BEC attack, is an effective tool – especially when the recipient isn’t observant, particularly when it comes to requests to change banking information (which should be a red flag). Organizations who make their employees undergo continual Security Awareness Training are less prone to such attacks, as malicious emails can easily be spotted by the recipient and discarded before they can do financial damage.

Get Your CEO Fraud Prevention Manual

CEO-Fraud-Prevention-Manual-WP-FannedCEO fraud has ruined the careers of many executives and loyal employees, causing over $26 billion in losses. Don’t be the next victim. This manual provides a thorough overview of how executives are compromised, how to prevent such an attack and what to do if you become a victim.

Get Your Manual

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.