Business Email Compromise in Dental Offices: The $50k Wire-Fraud Pattern
How BEC and wire fraud actually unfold in a dental practice — the supplier-impersonation pattern, the inbox-rule trick, the controls that catch it.
Read articleThreat Intelligence & Incident Response
A scenario walkthrough of an adversary-in-the-middle phish on a dental practice, an inbox rule staged for wire fraud, and the ITDR chain that broke it.
This is a scenario walkthrough, not a client engagement summary.
The narrative below is a composite drawn from publicly reported patterns in small dental practices; no real practice is described, and specific dollar amounts, timing, and operational details have been chosen to illustrate the mechanism rather than to identify any real office.
The threat-actor techniques described — adversary-in-the-middle session-token theft and mailbox-rule wire-fraud staging — are documented in the 2024–2025 Coveware quarterlies, the Sophos State of Ransomware in Healthcare 2024 report, FBI IC3 BEC public service announcements, and HHS OCR breach disclosures.
Assume a small single-location dental practice on Microsoft 365 Business Premium with Dentrix on a local server. An office manager handles billing, lab orders, and most vendor payments — the usual single-point-of-trust arrangement in a small dental office.
The practice has been running Obsidian Ridge's Ridge Plus tier, which includes MDR, Managed ITDR, and security awareness training, for a few months. That prior decision is what makes the rest of this walkthrough possible.
The office manager receives an email styled as an ADA membership renewal and clicks through to what looks like a clean Adobe sign-in page. She enters her M365 password, approves the Authenticator push, and the page redirects to a generic landing. Nothing feels wrong.
The page is an adversary-in-the-middle proxy — the EvilProxy family being the best-documented, with Tycoon and Mamba 2FA in the same category — that captures both her password and the post-MFA session token.
Within seconds the kit replays that token from a foreign IP and signs in as her, fully authenticated, no second prompt. The distinction that matters here is what got taken. The password is only half of it.
The stolen artifact is the session cookie the tenant issued after MFA succeeded, and that cookie is treated by Microsoft 365 as proof the login already passed every check. A password reset alone will not stop the attacker while that cookie is alive.
The attacker then does the thing that gives this attack pattern away. A mailbox rule is created:
wire, ACH, routing, or account number.That rule is a well-known wire-fraud staging signature. Managed ITDR fires three correlated alerts:
The office manager is still seeing patients between appointments. She does not know any of this has happened.
The 24/7 SOC revokes the active session and disables the OAuth consent grant as the first containment step — kill the stolen cookie, because a password reset alone does not. That is the 24/7 half, and it does not wait for business hours.
Obsidian Ridge picks up everything past containment — the forensic capture, the rotation, and the call to the practice owner — within one business day.
The malicious mailbox rule is preserved for forensic capture, then removed. The password is force-rotated, MFA is re-registered to a fresh authenticator profile, and every active session across every device is revoked in a single sweep.
A short review through the Unified Audit Log and Entra sign-in logs confirms the scope: no patient records accessed, no other mailboxes touched, no outbound mail sent.
The attacker set the trap and never got to spring it. Sitting in the office manager's inbox is the dental lab's monthly invoice — the wire the rule was built to redirect.
Mailbox-rule anomaly detection tuned for the BEC keyword family.
The wire / ACH / routing pattern is a documented wire-fraud staging signature, and rule creation is itself the monitored event — the detection fires on the staging step, before the wire is ever initiated, rather than on the transfer afterwards.
A 24/7 SOC that acts, and a named owner for everything after it. The practice owner does not have to interpret an alert during patient care. The SOC reads it and contains it around the clock; Obsidian Ridge takes it from there within one business day.
Session-token revocation as the first move, not a password reset. AiTM attackers hold a cookie, not a credential. Killing the cookie is what actually breaks their access.
Audit-log preservation before rule deletion. Forensics first, cleanup second. The insurance and audit file needs the evidence intact.
A pre-existing relationship. The practice is not working out who to contact after the fact. The scope, the escalation path, and who handles what are agreed before anything happens.
MFA did not save the day, and the office manager did not fail. AiTM kits like EvilProxy, Tycoon, and Mamba 2FA are designed specifically to bypass MFA by stealing the post-authentication session token.
Once that cookie is replayed the tenant treats the attacker as fully authenticated. Detection at the identity-behavior layer is what catches this. MFA is necessary; it is not the finish line.
If you run a dental practice and want to know what a Ridge Plus managed program actually does on the afternoon a phish lands, start at the dental practice page or Talk with us about your practice.
The mechanism generalizes — the vendor names, the mailbox-rule keywords, and the audit-log pattern show up the same way across the SMB market.
Last updated
September 30, 2026. We refresh this content as the threat landscape and tools evolve.
Related reading
How BEC and wire fraud actually unfold in a dental practice — the supplier-impersonation pattern, the inbox-rule trick, the controls that catch it.
Read articleWhy ransomware operators target dental practices, how attacks land on Dentrix and Eaglesoft, what a real incident week looks like.
Read articleDMARC in plain English for dental offices: what it does, why most local practices we checked don't have it, and how to add it without breaking reminders.
Read article