Ransomware and Invoice Fraud: The Two Cyber Threats Costing Health Practices the Most
The Australian Signals Directorate's Annual Cyber Threat Report for 2024-25 contains one figure that should stop any practice owner mid-scroll: ransomware incidents against the healthcare sector doubled compared with the year before, and malicious actors successfully compromised 95 percent of the healthcare and social assistance incidents ASD's Australian Cyber Security Centre responded to, against a success rate of roughly 52 percent across all sectors combined (cyber.gov.au).
That gap matters. It's not that health is being targeted more than everyone else and holding its own. It's being targeted more and losing more often, at a time when other industries are getting comparatively better at stopping the same attacks.
Two threats sit behind most of that damage: ransomware and business email compromise. They work differently, they need different defences, and most small practices have thought seriously about neither.
Ransomware, in practical terms
For a small practice, ransomware usually doesn't look like a dramatic hollywood-style hack. It looks like arriving on a Monday morning to find the practice management system won't open, patient files are inaccessible, and there's a message demanding payment to get them back. Appointments can't be checked, referral letters can't be pulled up, and the practice is effectively unable to operate clinically until the situation is resolved.
The Australian Cyber Security Centre's consistent advice is not to pay. Payment doesn't guarantee data is returned intact, it funds further attacks, and it doesn't undo the fact that patient information was likely accessed or exfiltrated before the encryption even happened, which is its own notifiable event under the Privacy Act.
The defences that matter most here are the ones covered in our Essential Eight overview: patched systems, multi-factor authentication, restricted admin rights, and backups that are actually tested and kept isolated from the network they're backing up. That last point is worth repeating on its own: ransomware that can reach your backup destroys the one thing that would have let you recover without paying anyone.
Business email compromise, a different kind of theft
Business email compromise, or BEC, works on trust rather than technical access. An attacker either compromises a mailbox or convincingly spoofs one, then sends a message that looks routine: a supplier updating their bank details, a practitioner asking for an urgent transfer, an admin request to change payroll information. There's no malware and often no obvious red flag until the money is already gone.
It's an expensive category of crime. In FY2023-24, self-reported BEC losses to the ACSC's ReportCyber platform totalled almost $84 million, from more than 1,400 reports that resulted in a financial loss, with the average confirmed loss sitting above $55,000 per incident. Queensland recorded more BEC reports than any other state that year, at 434 (cyber.gov.au). The following year, BEC with a confirmed financial loss made up 15 percent of everything reported to ACSC, and small businesses saw their average loss per cybercrime report climb 14 percent to $56,600 (cyber.gov.au, 2024-25 factsheet).
None of that requires a sophisticated attacker either. It requires someone willing to act on an email that looks plausible enough, under just enough time pressure not to double check.
What actually reduces exposure to each
For ransomware, the priorities are the same ones covered in our checklist: patch on a schedule, keep at least one backup copy genuinely offline or isolated, and don't let every staff account run with administrator rights it doesn't need day to day.
For business email compromise, the fix is mostly procedural rather than technical:
- Any request to change bank details or payment instructions is verified by phone, using a number your practice already has on file, never one supplied in the email or message itself
- Payments above a set threshold require sign-off from a second person before they go out
- Staff are told, plainly, that urgency and authority are the two levers scammers lean on hardest, and that it's fine to slow down and check even if a request claims to be from the practice owner or a long-standing supplier
- Email authentication is configured properly, covered in our SPF, DKIM and DMARC guide, so it's harder for anyone to convincingly impersonate your practice's domain in the first place
The bigger picture
Ransomware and BEC sit at opposite ends of the technical spectrum, one relies on breaking in, the other relies on being believed, but they share a common thread: both are consistently beatable with unglamorous, well-established controls, not with anything exotic. The practices that get hurt hardest tend to be the ones that never got around to putting those basics in place, not the ones facing an unusually sophisticated attacker.
.jpg&w=3840&q=75)