8 September 2022 • Phishing
What do CEO fraudsters do?
CEO fraud — also known as Business Email Compromise (BEC) — is a type of social engineering attack where criminals impersonate a high-ranking executive to trick employees into transferring money or sharing sensitive information. It is one of the most financially damaging forms of cybercrime, with the FBI reporting billions of dollars in losses globally each year.
In this article, we explain how CEO fraud works, show real-world examples, and share practical steps to protect your organization.
How does CEO fraud work?
CEO fraudsters abuse authority. For example, the fraudster sends an email on behalf of a high-ranking person within the company. This is where the term CEO fraud comes from. For example, a fraudulent payment order is sent to an administrative employee of your company, in which you request to deviate from the regular payment process because there is an exception or an emergency. The fraudster can also request to change a specific account number. Fraudsters often seek contact by e-mail or telephone.
How do criminals carry out fraud?
Cybercriminals often conduct thorough investigations before actually committing fraudulent activities. They often use various techniques, including social engineering. This technique attempts to crack the weakest link (humans) in computer security.
Phishing
In the case of phishing, cybercriminals try to gather relevant information about your company. These criminals try to trick employees into providing private information via email, text, or phone calls. For example, they may pretend to be a bank or a reputable government agency. Cybercriminals also sometimes build fake websites that look exactly like real websites. Important private data thus gets to the cybercriminals and they can use it to properly execute the CEO fraud attack.
Spear phishing is a targeted method of phishing that targets a specific company or employee. Spear phishing is therefore more often used by CEO fraudsters. Often, cybercriminals send a message via email from a legitimate sender. They can do this by hacking the email addresses of employees.
Pretexting
Another common method used by cybercriminals is pretexting. The attacker concocts false circumstances to trick the victim into accessing sensitive information or protected systems.
CEO fraud examples
CEO fraud can be recognized by several characteristics. In this section, we discuss some examples of CEO fraud.
Abusing the hierarchy
CEO fraud abuses the authority of a CEO. The fraudster places a payment order with an employee. If this is not paid, the so-called CEO threatens major consequences.
Sometimes the employee also receives compliments from the fraudster. The fraudster indicates that the employee has exceptional qualities and is therefore allowed to carry out the assignment in secret.
Emphasizing Confidentiality
The so-called CEO indicates in this case that this is a confidential transaction and that it may not be shared with anyone within the company. Strict privacy legislation is being abused. The so-called CEO emphasizes that the assignment may not be shared with other colleagues. The main goal is to keep the fraudulent activities secret for as long as possible.
Fake emails
Often the emails are sent with a fake email address. The e-mail address is very similar to the real e-mail address, but often they are slightly different. In some cases, the fraudster may send messages from a verified email address. Through phishing, criminals obtain passwords, which they use to log in to email addresses and then send fraudulent messages.
Protect your company against CEO fraud
CEO fraud can have devastating consequences — from significant financial losses to reputational damage. The good news is that most CEO fraud attacks can be prevented with the right measures in place.
Train your employees to recognize social engineering
The most effective defense against CEO fraud is security awareness training. When employees understand how social engineering works and can spot the warning signs, they are far less likely to fall for a fraudulent request. Training should cover phishing, pretexting, and authority-based manipulation.
Run phishing simulations
Regular phishing simulations help you test whether employees can apply what they have learned. Simulations that mimic CEO fraud scenarios — such as urgent payment requests from a fake executive — are particularly effective.
Implement a verification procedure for payments
Never process unusual payment requests based on a single email or phone call. Require a second person to verify any payment that deviates from the normal process, especially when urgency or confidentiality is emphasized. A simple callback to the supposed sender using a known phone number can prevent most CEO fraud attempts.
Be alert to irregular payment requests
Make sure all employees know how to recognize suspicious requests. Red flags include: requests to bypass normal approval procedures, emphasis on secrecy, unusual urgency, and unfamiliar bank account numbers. New employees should be informed about these risks during onboarding.
Be careful when disclosing company information
CEO fraudsters often do extensive research before launching an attack. Information published on your website — such as employee names, roles, and email formats — can be used against you. Be selective about what you share publicly, especially regarding your organizational hierarchy and financial procedures.
By combining employee training, clear verification procedures, and careful information management, you can significantly reduce the risk of CEO fraud in your organization.
We are always there for you, promise!
Register now for free and never stress about cyber crime again.
Start 14-day free trialProtect yourself better with a virtual private network
With a virtual private network, you are less visible on the internet. All employees of your company leave traces on the internet. This can also be company-sensitive information. For that reason, it’s not a bad idea to use a VPN. This is an encrypted connection between your computer and the internet. With a VPN connection, you can access the internet anonymously.
What should you do if your company is a victim of CEO fraud?
Has your company unexpectedly fallen victim to CEO fraud? Then it is important to take action as quickly as possible. Notify your bank’s cyber department as soon as possible. In some cases, a transaction can still be canceled. Also, contact the police and the fraud helpdesk.
It is also wise to take action within the company itself. Notify all staff of the circumstances and schedule an emergency meeting. It is then important to take measures to prevent more fraudulent activities.
Do you also want to be better protected against CEO fraud? Sign up now for the free 14-day trial at Guardey.
We are always there for you, promise!
Register now for free and never stress about cyber crime again.
Start 14-day free trial