MinnovateNetworks

The phishing that costs a practice real money does not look like phishing. There is no misspelled bank name and no prince. It looks like an invoice from a supplier you genuinely use, arriving in a thread you genuinely started, from the address you have always emailed.

That is not a metaphor. It is frequently the literal case, because the supplier’s mailbox was compromised before yours was.

Why the gateway misses it

Email filtering evolved to sit at the boundary and inspect messages arriving from outside. It is good at what it was built for: known bad senders, malicious attachments, domains registered yesterday, links to sites already on a blocklist.

Now think about the attack described above from the filter’s point of view. The sending domain is legitimate and years old. It passes SPF, DKIM and DMARC, because the mail really is being sent by that domain’s mail server. The account has a clean reputation. There is no malicious attachment, just a PDF. There may be no link at all, only new bank details in the body.

There is nothing for a perimeter check to object to. Every signal it evaluates is genuine. The message is fraudulent anyway, and no amount of tuning the gateway changes that, because the fraud is not in the envelope.

What actually distinguishes it

The signals that give this away are relational rather than technical, and they only exist inside the mailbox.

  • This supplier has emailed you for three years and never once mentioned changing bank details.
  • The writing style shifted. Different greeting, different sign-off, different sentence rhythm.
  • The reply-to is subtly different from the from address.
  • The thread was resurrected after being dormant for months, which is a common move because it inherits trust.
  • Six people in the practice received a near-identical message within a few minutes.

None of that is visible from the perimeter. All of it is visible from inside, where the history of who normally talks to whom already exists.

Why we use Ironscales

This is the reason we run mailbox-level email security rather than relying on filtering alone. Sitting inside Microsoft 365 or Google Workspace rather than only in front of it means the system can compare a message against how that sender has actually behaved before, and can spot impersonation and account-takeover patterns that are invisible at the boundary.

The capability that matters most in practice is less glamorous: when one person reports a message, it is pulled out of every other inbox it reached, automatically. Phishing campaigns are not sent to one person. By the time your front desk flags something, it is sitting in five other mailboxes, and the traditional answer is an all-staff email saying “do not click this” that arrives after somebody already did.

Reporting also has to be easy or it does not happen. A button in Outlook gets used. A process that involves forwarding something to an address nobody remembers does not.

The process control that beats every technical one

Here is the part no security product can do for you, and it is the single highest-value thing in this article.

Any change to payment details is verified by phone, on the number you already had, never a number in the email. No exceptions, no matter how senior the person appearing to ask, and explicitly including anything that appears to come from the practice owner.

Write it down, tell every person who can move money, and make it a rule rather than a judgement call. Judgement fails under time pressure, and creating time pressure is precisely what these messages are engineered to do. A rule that “we always call to confirm” gives your staff permission to slow down, which is the entire objective.

A reasonable baseline

If you want to improve this without changing anything you buy, three things help immediately:

  • Turn on multi-factor authentication for every mailbox, without exception. A compromised mailbox in your practice is what makes your patients and suppliers the next target.
  • Check whether any mailbox has forwarding rules you did not create. Attackers create them constantly to keep reading mail quietly after a password change.
  • Adopt the phone-verification rule above and tell your suppliers you have one, so that when you call them to check, it is not awkward.

The mailbox is where most breaches begin, and it is the one part of the environment that every member of staff touches all day. It deserves more than a filter that was designed for a different era of attack.

Want this handled for you?

The assessment is free, takes about an hour on site, and you keep the documentation whether or not you hire us.

Book a free consultation