Cyber Case Study – Nursing home suffers cyber attack

Cyber Case Study – Nursing home suffers cyber attack

After a CEO’s email account was hacked, a care home faced huge financial losses from a social engineering cyber attack.

What happened?

This cyber incident appeared to have stemmed from a targeted brute force attack on a care home’s CEO’s business email account. A brute force attack is where a computer program is used to crack passwords by trying numerous possible password combinations in rapid succession, with the program typically trying a long list of the most commonly used passwords. The longer and more complex the password, the more difficult and time-consuming it is for the program to crack. Unfortunately, the CEO’s email account did not have a strong password in place. To make matters worse, the care home did not have multi-factor authentication enabled for remote access to email accounts, meaning that as soon as the CEO’s password was cracked, the hacker was able to gain access to his account without having to go through a second verification procedure, such as inputting a verification code or number.

Having gained access to the CEO’s email account, the fraudster was able to spend time perusing the CEO’s inbox and outbox, gathering valuable information about how wire transfers were processed at the company as well as establishing the working relationship that the CEO had with members of the care home’s finance team. What’s more, the fraudster was able to access the CEO’s calendar and establish what the CEO would be doing on any given day.

Having worked out the CEO’s schedule from his calendar, the fraudster waited until they were on holiday, to reduce the chance of the scam being uncovered.

The first step was to send an email impersonating the CEO to a member of the care home’s finance team. The fraudster used a method known as email spoofing – sending an email from one email address but labelling it as being sent from another. Fraudsters use programs or websites which enable them to make an email look as though it has come from a legitimate email address, as well as allowing them to alter the address that the recipient responds to.

The fraudster sent an email that appeared to come from the genuine email address of the care home’s CEO, and any response to the email was sent to a remarkably similar looking email address set up by the fraudster. So while the emails sent by the fraudster appeared to come from the CEO’s genuine email address, any response to that email would automatically be sent to a slightly different address, ensuring that the CEO wouldn’t be alerted to the scam. The fraudulent email explained that the CEO had received notice of an outstanding payment of £47,584 that needed to be paid urgently to a firm that had supposedly provided some management consultancy work for the care home a few months ago. The email included the account details that the funds needed to be sent to and the fraudster was keen to stress that the payment had to be made the same day.

The fraudster also added some subtle touches to the email to make it look as authentic as possible. The CEO addressed the member of the finance team using an abbreviated version of her full name, for example, which the fraudster appears to have picked up from viewing previous email correspondence. The fraudster also mentioned that he was enjoying his holiday and would be busy all day and signed off with their genuine email signature.

In normal circumstances, the member of the finance team would have confirmed the details of the transfer with the CEO in person but with them on holiday, and with the email appearing to come from the correct address, along with the use of her nickname and a genuine email signature, the employee assumed that the request was genuine. Not wanting to disturb the CEO while they were on holiday, the employee paid the funds into the account and sent an email confirming this to the account run by the fraudster.

Seeing that the initial ruse had worked, the fraudster sent a similar email the following day, this time requesting a payment be made for £39,731 to another account.

The employee arranged the payment, meaning that £87,315 in total was transferred to accounts controlled by the criminals.

How cyber insurance helped

The scam was only discovered a week later when the CEO returned to the office and the payments were brought up in conversation. The care home reported the incident to local law enforcement and tried to get the recipient banks to recover the funds but most of the money had been withdrawn from the accounts by that point. One of the banks was able to recover a meagre £600, leaving the care home £86,715 out of pocket. Fortunately, the care home had purchased cyber crime cover on their cyber policy with CFC and was, therefore, able to recover most of the loss.

Case Study takeaways

Senior team members are often prime targets for cyber criminals; these individuals usually act as the face of the company and as such, have bigger profiles on company websites, and social media accounts, allowing cyber criminals to gather valuable information about them.

Cyber criminals are becoming much more sophisticated so it can be much harder to identify attack attempts.

Most cyber incidents occur as a result of human error, highlighting the importance of having a cyber insurance policy in place, even if a business has prudent risk management controls in place.

We hope we have provided context on cyber-related risk and demonstrated how a robust insurance policy can help manage those risks effectively. With access to several cyber liability products which can be tailored to your needs, McClarrons can help find the right cyber policy and cover for your business, giving you peace of mind around your protection.

For more information, or if you would like a complimentary insurance review, please do not hesitate to contact our Commercial Team on tel: 01653 609151 or by emailing commercial@mcclarroninsurance.com.

Share this article

Post Info

Continue Reading

Related Articles

Here, we share a case study of how McClarrons’ quick response helped one of our rural clients avoid prosecution and large fees when the HSE were investigating an incident involving one the employees falling off a cherry picker.
One of our clients faced a situation where their insurer was unwilling to pay out on a claim as they believed the client had failed to disclose pertinent information. Read on to discover how we helped turn the situation around, and why transparency at policy inception matters.
Here, we revisit a claim from the summer of 2024, where one of our farming clients experienced a devastating loss when their combine and drill were destroyed in an unexpected third-party fire.
Accidents happen, and when they do, it’s important your insurance supports you in the way you would like. When an incident occurs that is not your fault, leaving you with uninsured losses, Legal Expenses can become an invaluable policy to assist you.
Household fire risks do not disappear in summer; they evolve. Changes in temperature, light and day-to-day behaviour can turn ordinary items into unexpected sources of fire and property damage.
Here, we discuss how our in-house Claims Team guided a client through the aftermath of a house fire, ensuring the claims process was handled efficiently and with minimal stress.