Online scams are nothing new, but as email has evolved and improved, so have scammers and the messages they send. Nefarious emails, attachments and links now appear more sophisticated and convincing than ever, increasingly written or refined with the help of generative AI, and they can trick even the most meticulous user.
2026 Update
By Brad Wyro, Content Marketing Manager, MDaemon Technologies
Billions Lost to Business Email Compromise
Referred to by the FBI as one of the costliest forms of internet crime, Business Email Compromise (BEC) scams cost organizations over $3 Billion in 2025, according to the FBI's Internet Crime Complaint Center (IC3) 2025 Internet Crime Report, the second-highest loss category behind investment fraud, and part of a record $20.877 billion in total cybercrime losses reported that year, a 26% increase over 2024.
Healthcare organizations are among the top targets for cybercriminals, and healthcare has repeatedly been named among the most-targeted U.S. sectors for cyberattacks in recent FBI reporting.
International law enforcement has had some success fighting back. In one notable case, Interpol and Nigerian police arrested 11 members of the SilverTerrier BEC network, a group linked to the theft of hundreds of thousands of usernames and passwords. But arrests like this barely dent the overall problem: most BEC scams are never solved, and many victims never report the crime at all.
Five Reasons BEC Scams Work So Well
Highly Targeted: Scammers research a company's website and social media presence, and often groom targets with several seemingly innocuous emails before making their move, all while sidestepping traditional email filtering.
They Contain No Malware: Because there are no malicious links or attachments to catch, BEC emails often evade spam filters and raise no obvious red flags for scanning tools.
They Exploit Human Nature: These emails impersonate a real, trusted person (a CEO, vendor, or colleague) using authentic-looking addresses, formatting, company names and titles.
They Are Often Under-reported: Victims frequently don't realize they've been scammed until well after the fact, and many organizations avoid reporting incidents for fear of reputational damage, letting perpetrators move on to the next victim.
They're Increasingly Powered by AI: Generative AI now lets scammers write flawless, highly personalized emails in seconds, and even fake a colleague's voice or face on a phone or video call. Industry research puts the share of phishing emails containing AI-generated content above 80%. In one widely reported case, a finance employee at global engineering firm Arup was tricked into wiring roughly US$25.6 million after a video call in which every other “participant,” including the CFO, was an AI-generated deepfake.
Why Healthcare Is Especially at Risk
In 2025, a record 772 large healthcare data breaches were reported to the U.S. Department of Health and Human Services, and nearly one in four involved a compromised email account. The average cost of a healthcare data breach fell to $7.42 million in 2025, still the highest of any industry for the 14th consecutive year.
For healthcare, what begins as a simple phishing email can literally be life-threatening. A 2025 Proofpoint/Ponemon Institute study found that 62% of healthcare organizations experienced a BEC or email-impersonation attack in the prior 12 months, and 70% of those organizations said the attack disrupted patient care, including delayed procedures and tests.
Two recent examples illustrate the risk. Numotion, the largest wheelchair and mobility equipment provider in the U.S., reported that phishing attacks compromised employee email accounts and exposed the information of 529,004 individuals. Separately, Nephrology Associates Medical Group in California discovered a compromised employee email account in 2025 that exposed patients' Social Security numbers, dates of birth, and medical and insurance information.
Part of the problem is technical: the majority of healthcare domains still lack an enforced DMARC policy, leaving them more exposed to spoofing than they need to be. That's one reason the checklist below has been updated for 2026.
Learn How to Protect Against BEC Scams
Top 10 Business Email Compromise Protection Tips
The fundamentals of stopping BEC haven't changed, but the details have. Below is an updated Top 10 checklist for end users and administrators alike.
Top 10 Protection Tips for End Users
- Double-check the sender's email address and learn to recognize spoofing and impersonation. MDaemon Webmail lets you view the full email header (click here to learn how) to verify the true sender.
- Don't overshare on social media. The personal and business details scammers use to craft convincing emails often come straight from LinkedIn, Facebook, and company “About Us” pages.
- Don't open email from unknown or unverified sources.
- Verify every payment or wire-transfer request through a second, out-of-band channel using a known-good phone number, never a number or link supplied in the request itself. Phone and even video calls alone are no longer sufficient given the rise of deepfake voice and video fraud.
- Know your customers' and vendors' normal business practices and communication patterns, so anything unusual stands out.
- Keep antivirus and endpoint protection running and up to date on every device.
- Use phishing-resistant multi-factor authentication (security keys or passkeys) wherever it's offered. It's now the recommended standard over SMS codes or app-based push approvals, which can be bypassed. You can enable multi-factor authentication in MDaemon Webmail today.
- Forward, don't reply, to a message when you need to confirm a request. That way you're manually entering (or selecting from your own address book) a verified address rather than replying to a spoofed one.
- Learn to recognize AI-generated phishing and deepfake requests. Polished grammar and a familiar-sounding voice are no longer proof that a message is legitimate.
- Slow down on urgent, authority-based requests, and report anything suspicious to IT immediately. No one should be penalized for pausing to verify.
Top 10 Protection Tips for Administrators
- Enable reverse lookups to help verify sender legitimacy.
- Use antivirus in MDaemon and SecurityGateway to scan all inbound and outbound email. Basic spam filtering alone is no longer enough against modern BEC and AI-driven phishing.
- Require SMTP authentication.
- Publish SPF, DKIM & DMARC to secure your domain against spoofing, and move DMARC to an enforced “reject” policy rather than “monitor-only,” since a policy that only monitors provides no actual protection.
- Require phishing-resistant multi-factor authentication for all accounts, especially email and remote administration.
- Require strong, unique passwords and encourage the use of a password manager.
- Provide regular end-user training on all scam formats, including BEC, spear phishing, and AI-generated phishing.
- Keep antivirus and threat signatures continuously updated across every mail server and endpoint.
- Apply Zero Trust and least-privilege access controls so a single compromised account can't reach everything on the network.
- Vet and manage vendor and business-associate email security as part of your third-party risk program. A partner's weak email security can become your incident.
The Bottom Line
While traditional security measures such as network defenses and secure email gateways can be effective at blocking most varieties of spam, the bottom line remains the same in 2026: the most critical part of stopping BEC attacks is ongoing user awareness and education, paired with modern technical safeguards like phishing-resistant MFA and enforced email authentication.
Regulatory note: HHS has proposed updates to the HIPAA Security Rule that would make multi-factor authentication and encryption mandatory rather than “addressable.” As of this writing, the rule has not been finalized, but it signals where healthcare compliance is headed, and organizations that adopt these controls now will be ahead of the curve.
Learn more about how MDaemon Email Server and SecurityGateway can help protect your organization against phishing and Business Email Compromise attacks.


