Cyber claims case study: Nursing home hoax
After a CEO's email account is hacked, a care home faces huge financial loss from social engineering
Social engineering involves the use of deception to manipulate individuals into carrying out an act, such as transferring money, handing over confidential information, or clicking on a malicious link, and it’s causing serious financial harm to organizations around the world.
Any organization that transfers funds electronically can be susceptible to social engineering attacks, and entities operating in the care sector are no exception to this. Many care homes not only receive funds electronically in the form of payments from residents and their families or funding from government bodies, but they also disburse large amounts of money in the form of payments to members of staff and to third party suppliers and contractors. All these transactions make for a tempting target for cybercriminals, who are constantly on the lookout for opportunities to intercept fund transfers and divert them to fraudulent accounts.
One of our policyholders affected by such a loss was a company providing assisted living facilities for elderly residents across three sites.
In this case, the care home was the victim of what is sometimes known as “CEO fraud”. CEO fraud typically describes a situation in which a fraudster impersonates the CEO or another senior executive of an organization and instructs an employee to make an urgent payment to a fraudulent account for a particular reason.
Password protection problems
In this instance, the fraud appears to have stemmed from a targeted brute force attack on the care home’s CEO’s business email account. A brute force attack is where a hacker uses a computer program to crack passwords by trying numerous possible password combinations in rapid succession, with the program typically trying a long list of the most commonly used passwords. The longer and more complex the password, the more difficult and time consuming it is for the program to crack.
Unfortunately, the CEO’s email account did not have a strong password in place. With the password lacking in both length and complexity, the program was able to crack it.
Unfortunately, the CEO’s email account did not have a strong password in place. With the password lacking in both length and complexity, the program was able to crack it. To make matters worse, the care home did not have multi-factor authentication enabled for remote access to email accounts, meaning that as soon as the CEO’s password was cracked, the hacker was able to gain access to his account without having to go through a second verification procedure, such as inputting verification code or number.
Having gained access to the CEO’s email account, the fraudster was able to spend time perusing the CEO’s inbox and outbox, gathering valuable information about how wire transfers were processed at the company as well as establishing the working relationship that the CEO had with members of the care home’s finance team. What’s more, the fraudster was also able to access the CEO’s calendar and establish what the CEO would be doing on any
Having worked out the CEO’s schedule from his calendar, the fraudster waited until the CEO was on holiday. With the CEO not on site at the care home and with reduced chances of the scam being uncovered, the fraudster chose this moment to strike.
The first step was to send an email impersonating the CEO to a member of the care home’s finance team. The fraudster used a method known as email spoofing, which is when someone sends an email from one email address but labels it as being sent from a different address. Fraudsters use programs or websites which enable them to make an email look as though it has come from a legitimate email address, as well as allowing them to alter the address that the recipient responds to. The fraudster sent an email that appeared to come from the genuine email address of the care home’s CEO, and any response to the email was sent to a remarkably similar looking email address set up by the fraudster.
So while the emails sent by the fraudster appeared to come from the CEO’s genuine email address of Joe.Bloggs@XYZresidentialcare.com, any response to that email would automatically be sent to Joe.Bloggs@XYZresidentilcare.com, ensuring that the CEO wouldn’t see any response from the member of the finance team to the email and uncover the scam.
The fraudulent email explained that the CEO had received notice of an outstanding payment of $47,584 that needed to be paid urgently to a firm that had supposedly provided some management consultancy work for the care home a few months ago. The email included the account details that the funds needed to be sent to and the fraudster was keen to stress that the payment had to be made the same day.
Not wanting to disturb the CEO while on holiday and conscious that the payment was urgent, the employee paid the funds into the account and sent an email confirming this back to the fraudster.
Fine tuning the scam
The fraudster also added some subtle touches to the email to make it look as authentic as possible. The CEO addressed the member of the finance team using an abbreviated version of her full name, which the fraudster appears to have picked up from viewing previous email correspondence between the CEO and this member of the finance team. The fraudster also mentioned that he was enjoying his holiday and would be busy all day and signed off with the CEO’s genuine email signature.
In normal circumstances, the member of the finance would have confirmed the details of the transfer with the CEO in person. But with
the CEO on holiday, and with the email appearing to come from the correct address, along with the use of her nickname and a genuine email signature, the employee assumed that the request was genuine. Not wanting to disturb the CEO while on holiday and conscious that the payment was urgent, the employee paid the funds into the account and sent an email confirming this to the account run by the fraudster.
Seeing that the initial ruse had worked, the fraudster sent a similar email the following day, this time requesting a payment be made for $39,731 to another account. The employee arranged the payment once more, meaning that some $87,315 in total was transferred to accounts controlled by the fraudster.
The scam was only discovered a week later when the CEO returned to the office and the payments were brought up in conversation. The care home reported the incident to local law enforcement and tried to get the recipient banks to recover the funds, but most of the money had been withdrawn from the accounts. One of the banks was able to recover a meager $600, leaving the care home $86,715 out of pocket. Fortunately, the care home had purchased cybercrime cover on their cyber policy with CFC and were able to recover most of the loss.
The key driver for cyber claims? Human error
This claim firstly illustrates how CEOs and senior executives are prime targets for cybercriminals. These individuals usually act as the face of their companies and tend to have bigger profiles on company websites and social media accounts, allowing cybercriminals to gather valuable information about them. In addition, cybercriminals know that employees are instinctively less likely to question instructions from CEOs and other senior executives. Individuals in leadership roles need to be especially conscious of sticking to good cybersecurity practices, such as having good password management in place. Likewise, employees need to be alert to suspicious emails from senior executives, particularly in instances where an urgent payment request is made, and have robust callback and authentication procedures in place.
Cybercriminals know that employees are instinctively less likely to question instructions from CEOs and other senior executives.
Finally, this claim also discredits one of the most common objections to cyber insurance: namely that by investing in IT security, organizations have no need for cyber insurance. But most cyber incidents are a result of human error. With increasingly sophisticated attacks like this on the rise, it makes it very difficult for employees to tell the difference between a real email and a fake one. Furthermore, with more and more financial transactions being carried out electronically, the number of opportunities for cybercriminals to steal these funds has never been greater. Having good training and authentication procedures can certainly help reduce the risk of an event like this, but it’s impossible for any business to be completely impervious to attacks. This is why cyber insurance should be a part of any prudent organization’s risk management program, acting as a valuable safety net should the worst happen.