Key Takeaways
- Business email compromise cost businesses $3.05 billion in reported losses in 2025, and the average incident now costs $137,000.
- The attack usually starts with a single phishing email, not a technically sophisticated hack, and one clicked link is enough to hand over a real inbox.
- Once inside, attackers watch quietly for weeks, studying invoicing and payment patterns before sending a fraudulent request that looks exactly like a real one.
- Multi-factor authentication on email blocks the vast majority of these takeovers, but it only works if it's enforced on every account, not just the ones a practice remembers to protect.
- A callback verification policy for any payment or banking change request is the single cheapest control that stops a BEC scam from succeeding.
A veterinary practice doesn't need a sophisticated hacker to lose tens of thousands of dollars. It needs one staff member to click one convincing email. Business email compromise is now one of the most expensive and most preventable threats a vet clinic faces, and most of what stops it costs nothing but a policy change.
What is business email compromise, exactly?
Business email compromise, or BEC, is a scam where an attacker gains access to a real email account, or convincingly impersonates one, to trick someone into redirecting money or sensitive information. Unlike ransomware, there's usually no malware and no locked screen. The email account itself just starts working for the attacker instead of the practice.
For a veterinary clinic, that usually means a fake invoice from a "vendor," a spoofed request from the practice owner, or a message that looks like it came from a trusted supplier asking for updated payment details.
Are veterinary practices actually targeted by business email compromise?
Yes, and the scale of the problem has grown every year. The FBI's Internet Crime Complaint Center logged 24,768 BEC complaints in 2025, totaling $3.05 billion in reported losses, up roughly 16% in complaint volume from the year before. The average loss per incident now sits at $137,000.
Healthcare has consistently been among the hardest-hit sectors by average cost per incident, and veterinary practices sit squarely inside that exposure even though they rarely think of themselves as a healthcare target. A small clinic holds exactly what a BEC attacker wants: recurring vendor payments, a practice management system full of client payment details, and often no dedicated IT security staff watching for the warning signs.
How does a business email compromise attack actually happen at a vet clinic?
It almost always starts the same way: a phishing email convincing enough that someone clicks. According to the American Veterinary Medical Association, that single click is still the most common way attackers get into a practice's systems in the first place, whether the end result is ransomware or business email compromise.
From there, the attack usually follows a pattern:
- Initial access. A phishing email tricks a staff member into entering their email credentials on a fake login page, or a weak, reused password gets guessed or leaked from another breach.
- Silent observation. The attacker doesn't act immediately. They sit inside the mailbox, often for weeks, reading how the practice actually communicates with vendors, what invoices look like, and who approves payments.
- The request. Once the attacker understands the pattern, they send a message that fits it exactly: a "updated" bank account number from a supply vendor, an urgent wire request that appears to come from the practice owner, or a fake invoice for software the clinic already uses.
- The payment. If nobody double-checks the request through a separate channel, the money goes out, and it is very rarely recoverable once it clears.
This patience is what makes BEC harder to catch than a generic phishing attempt. The message doesn't look like a scam. It looks like Tuesday.
What does a real business email compromise scenario look like?
Picture a clinic that uses the same practice management vendor for years, paying a predictable monthly invoice. An attacker who's compromised the office manager's inbox sends a message, timed to land right before the usual invoice date, saying the vendor has updated their banking details. The email address looks right. The invoice amount looks right. The tone matches how that vendor always writes.
Nothing about the message would raise a flag on its own. The only thing that stops it is a policy that says: banking changes get confirmed by phone, using a number already on file, not one in the email.
What email security controls actually stop business email compromise?
A handful of controls account for most of the real-world difference between a clinic that catches a BEC attempt and one that pays it.
| Control | What it actually does |
|---|---|
| Multi-factor authentication (MFA) | Blocks account takeover even if a password is stolen or guessed, since the attacker still needs the second factor |
| Email filtering and anti-spoofing (DMARC, SPF, DKIM) | Flags or blocks messages forged to look like they came from an internal address or trusted vendor |
| Callback verification for payment changes | Requires any banking or payment detail change to be confirmed by phone, using a number already on file |
| Managed endpoint detection and response (EDR) | Catches follow-on malware or unusual account activity after an initial compromise |
| Staff phishing training | Builds the habit of pausing on urgent, unusual, or payment-related requests before acting on them |
MFA does the most work of any single control here. It's also the one clinics most often assume is already in place, only to find it was enabled for some accounts and quietly skipped for others during a busy onboarding week. An email security policy is only as strong as its least protected inbox.
What should you do if you suspect your clinic's email has been compromised?
Act the same way you would for any other security incident: contain first, then investigate. If you've already read our guide to veterinary practice ransomware response, the sequence will look familiar, because the logic is the same.
- Reset the affected account's password immediately and force a sign-out of all active sessions.
- Enable MFA on the account if it wasn't already active, this is the single most common gap attackers exploit.
- Check the mailbox's forwarding rules and filters. Attackers frequently set up a hidden rule that silently forwards or deletes messages from specific vendors or the practice owner, so the real recipient never sees them.
- Contact your bank immediately if a payment already went out. Funds are sometimes recoverable within the first 24 to 48 hours, rarely after.
- Notify your managed IT or security provider so they can check for further access across your other systems, not just the one compromised inbox.
Any incident that exposes client payment information may also trigger state breach notification obligations, similar to what applies after a ransomware event. Our guide to PCI DSS compliance for veterinary practices covers what a clinic is still on the hook for when payment data is involved, even when a third-party processor handles the actual transaction.
Business email compromise doesn't announce itself with a locked screen or a ransom note. It just quietly redirects a payment that looks completely normal, until the real vendor calls asking where their money is. Multi-factor authentication, a callback policy for payment changes, and staff who know to pause on anything urgent close most of the gap attackers rely on. If you're not sure whether your clinic's email accounts are actually protected or just assumed to be, Crossguard Cyber's free assessment shows you exactly where the gaps are before an attacker finds them.