CyberSecure

THE MAGAZINE FOR UNION FUNDS

How Did the Bad Guys Get In? They Sent an Email.

 

Why benefit funds can’t train their way out of phishing — and the controls that actually stop it.

It didn’t arrive with flashing red lights, nor did it slip in in the dark of night. There was no malware alert. No dramatic breach notification. No obvious scammy subject line. It was the kind of email that slides into an inbox on an ordinary Tuesday and looks exactly like everything else. A familiar vendor name. A polite tone. The same signature block that the office had seen a hundred times before. Only one detail was different.

“We’ve updated our banking information. Please send future payments to the new account below.”

By the time anyone realized what had happened, the money was gone. But here’s what most benefit offices miss: that wire transfer wasn’t the main event. It was the opening act.

When cybercriminals get into a benefit fund’s email environment, they aren’t just hunting for a quick payday. They’re hunting for something far more valuable. They want to weaponize your email system and all the data it holds, and they are going to use it to hunt your vendors, partners, and members.

The Villain Isn’t an Obvious Scammer, It’s a Familiar-Looking Email

Business Email Compromise (BEC) has become one of the most successful crimes in the world precisely because it doesn’t feel like a cyberattack. There’s no smashed firewall or blinking dashboard. Instead, the attacker slips into the place your organization lives all day long: the email inbox.

They don’t kick down the door. They knock politely. And once they’re inside, they blend into the daily rhythm of the benefit office: A payment request that looks routine. A payroll question that feels urgent. A vendor invoice that seems routine. A board member asking for a document.

It’s fraud disguised as normal work. Benefit funds are uniquely vulnerable because your work is built on trust, relationships, and repeatable processes.

The Stakes Are Bigger Than a Fraudulent Wire Transfer

Most benefit offices don’t think of themselves as high-profile targets. You’re not a bank. You’re not a tech company. You’re not a household name. But you have something they want. You’re a vault — not just of money, but of identity.

Benefit offices naturally hold the raw materials of a member’s life: Social Security numbers, dependent records, banking information, claims documentation, and beneficiary forms. On the dark web, criminals refer to complete identity packages as "FULLZ." And the frightening reality is simple: benefit offices generate FULLZ as part of routine operations.

While the stolen wire transfer makes headlines, the quiet theft is often the real prize. Money can sometimes be recovered. A member’s identity cannot.


The False Fix: “Just Train People Better”

At this point, many organizations resort to the most common defense: train people to spot phishing emails. That’s not to say this isn’t a good plan of action. Awareness matters — nobody’s arguing against common sense. But here’s the uncomfortable truth: you cannot train a human being to reliably detect a perfectly written scam email from a real vendor account at 4:58 p.m. on payroll day.

Modern attackers don’t send sloppy scams anymore. They send clean, context-aware messages, often written with AI. The old red flags are gone. Which means the goal isn’t perfect detection, it’s reducing what a single email can do.


The Better Plan: Make Email Boring Again

Micro-analyzing every message doesn’t actually work. What actually works is building systems that prevent email from becoming catastrophic.

Part One: Secure the Mailbox (Because Email Is the Master Key)
If attackers gain control of an inbox, they gain control of the fund’s voice, along with all the background information stored in that account and the digital rolodex of everyone who has ever sent or received an email from it.

How do you make a scam email seem legitimate? You send it from a legitimate account. That’s why every benefit office should treat email security like the front door of the building: multi-factor authentication everywhere, no exceptions, stronger methods than text-message codes, and no legacy logins lingering in the background.

If the inbox fails — especially in a Microsoft- or Google-hosted environment — everything downstream is exposed.

Part Two: Take Money Movement Out of Email
Next, remove money movement from email altogether. One of the simplest rules a fund can adopt is also one of the strongest: Email can request a change, but email can never approve it.

Banking changes, ACH updates, and wire instructions should never be authorized through an email thread. Verification must happen outside the inbox, through a process that urgency can’t override. Like a phone call to a known number, for example. Criminals exploit speed. Controls slow things down.

Part Three: Protect the Long-Term Asset: Member Data
Benefit office inboxes often serve as informal filing cabinets for PHI and PII — claims documents, enrollment forms, and copies of IDs. That data doesn’t expire. Moving sensitive documents into secure portals, limiting what is sent by email, and applying retention policies are not “IT projects.” They are fiduciary protections.

Part Four: Treat Vendors as Outside Doors Into the Fund
Attackers don’t always target the fund directly. They target the weakest-connected organizations: payroll vendors, TPAs, and claims processors. A compromised vendor account can become a trusted pipeline into your workflows. That’s why vendor access, MFA requirements, and quarterly reviews matter. The fund doesn’t need to be hacked if the vendor already was.

Part Five: Have a Stop-the-Bleeding Playbook
Even with strong controls, incidents happen. The difference is response speed. Every fund should know what happens in the first hour: who locks accounts, who calls the bank, who engages legal and forensics, and how trustees are informed.

Cyber incidents are not just IT events. They are fiduciary events. Minutes matter.


The Bottom Line
The question is not, “Could someone be tricked?” Of course they can. The real question is, “Could one email cause irreversible harm?” Because the most valuable thing a benefit fund holds is not the checkbook. It is the lifetime identity of every member it serves. And protecting that is fiduciary prudence.

Cybercriminals don’t need to break into benefit funds anymore. They just need to blend in. They send an email, and they wait for trust to do the rest.

The good news is that prevention is not mysterious. It’s not about perfect staff instincts, it’s about controls. Training helps, but controls protect. And in today’s world, protecting member data isn’t optional, it’s a fiduciary responsibility.


CYBERSECURE TAKEAWAY:

Make email boring again:

  • MFA everywhere
  • No payment changes by email
  • Sensitive documents belong in secure portals
  • Vendors are risk surfaces
  • Incident response is a fiduciary response

The Benefit Office Verification Script

When a vendor requests a payment change, staff should have a simple, rehearsed response:

“Thanks — we can’t process banking changes over email. We’ll call you back using the number we already have on file to confirm.”

This isn’t just a good idea, it’s a widely recommended defense against Business Email Compromise.

According to the FBI’s Internet Crime Complaint Center (IC3), organizations should use secondary channels to verify requests for changes in account information, rather than relying on email alone.

Email can request a change, but email can never approve it.


What’s Sitting in Your Inbox Right Now?
Benefit office inboxes often contain more sensitive identity data than anyone realizes:

  • Social Security numbers and dependent records
  • Copies of driver’s licenses and voided checks
  • Claims, appeals, and medical documentation
  • Beneficiary disputes and hardship requests

That information doesn’t expire. It can be exploited for years. There’s also a cultural trap here. In many offices, the person who can dig up a 10-year-old email attachment at the last second becomes the hero — so people start saving everything, just in case.

Over time, inboxes turn into archives. Staff become accidental email hoarders. And the organization quietly accumulates a massive cache of PII and PHI in the least-protected filing cabinet imaginable.

If email is the attacker’s doorway, your inbox is the filing cabinet. Protect it accordingly.

 

CyberSecure

Filter articles

Let’s build something better - together.

The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.

Don’t leave your prudent process to chance. Reasonable safeguards, independently checked and documented — Cyber Prudence™ for union funds.

Thank you for your inquiry. Your submission request has been received.
Onsite Logic