• CEO fraud: how to recognize and avoid impersonation scams

Increasingly, cybercriminals are trying to deceive companies with targeted scams. In the case of ‘CEO fraud’, they use trust, authority and state-of-the-art technologies to induce and pressure employees into taking certain actions, including financial transactions. A single successful attack can have significant economic and legal consequences. This makes it even more important to understand the methods involved—so you can spot warning signs early and prevent successful attacks more effectively.

Mission Security

The most important aspects

Businessman talking on the phone while checking his smartphone at an office desk

CEO fraud uses authority, time pressure, and secrecy to harm companies.

Smiling woman participating in a video conference on a laptop

Criminals are increasingly using deepfake technologies, which help make attacks feel more realistic.

Businesswoman discussing information on a tablet with a male colleague in an office

Clear processes, healthy skepticism and technical checks are the most effective methods to protect companies from such fraud.

CEO Fraud

CEO fraud is one of the most dangerous forms of social engineering, as attackers exploit authority, urgency, and trust.

This episode of the CyberSecure podcast shows common tactics, real-world examples, and practical defenses for organizations and employees.

What is CEO Fraud?

In this type of scam, criminals impersonate a CEO or senior executive. Their aim is to put pressure on employees to transfer large sums of money to fraudulent accounts.

The deception is often well planned: e-mails, messenger messages or telephone calls appear convincing. More recently, cyber criminals have begun to use video conferencing with deceptively realistic Deepfakes. If you’re caught off guard and under pressure, it’s easy to fall for these tactics.

Related types of fraud

Blue phishing email icon with an exclamation mark

Business Email Compromise (BEC):

The scam is carried out via fake or compromised email accounts. Instead of redirecting payments from a hacked account, attackers use spoofed or compromised business email addresses (e.g. look-alike domains) and take over communication. They observe existing processes, then target the Accounting/Finance department of the target company with an “urgent payment request”, requesting that funds are transferred to an attacker-controlled account.

Blue information icon on a document with an orange alert symbol

Fake invoices:

Criminals send authentic-looking invoices with manipulated bank details. These invoices often include real logos, project names, or references – in some cases for services actually ordered. The deception often comes in the payment information (e.g. a changed IBAN) or in “small” amounts that may slip through routine checks.

Blue icon showing two people exchanging information in a quid pro quo scheme

Supplier fraud:

Here, perpetrators pose as an existing service provider/supplier and request a change of bank details (by email, letter or phone call, often with forged documents). Once the change is accepted, payments for real deliveries/services are redirected to the fraudulent account, it often only comes to light when the real supplier sends a payment reminder.

Invoice Redirection Fraud

StayInformed

Attackers manipulate genuine-looking invoices or payment instructions to divert money to their own accounts. Often, they compromise supplier email accounts or imitate them convincingly.

How to protect against it:

  • Implement strict internal approval workflows for financial transfers.
  • Check regularly for any changes in name, address or account details.
  • Make a ‘Whitelist’ of genuine payment accounts.
  • Check any changes in payment details by using the dual verification principle as a minimum. This means ensuring that sensitive data requires at least two users to authorize changes.
  • If you receive any requests from the supplier to change account details, verify them request by contacting the supplier via a known channel.
  • Let your payment recipient know that you have made the payment – this way you will be able to identify any incorrect payment details before it is too late.
  • Do not make supplier information - for example, company names of your suppliers - publicly available – cyber criminals often get their information from publicly accessible sources.

How do cyber criminals prepare for CEO fraud?

Before they take action, fraudsters collect targeted information. Public sources such as company websites, trade registers, press reports or social networks such as LinkedIn, provide them with details about executives, projects and structures. Based on this information, they build a credible story - for example, creating an allegedly highly confidential transfer.

Next, they look for a suitable target, often employees from the finance department or people with signing authority. The contact is then made via fake e-mail addresses, messengers or increasingly by telephone or video call. Under the pretext of urgency and secrecy, the cyber criminals push for a payment, usually abroad and sometimes split into multiple transfers.

illustration of how ceo fraud works

Real cases of CEO fraud

  • Singapore (Deepfake “CEO + executives” video call)
    What happened (March 2025): A finance director at a multinational company was contacted via WhatsApp by someone impersonating a senior executive and was drawn into a Zoom call where the “CEO and others” were represented by deepfakes. He was instructed to transfer US$499,000 from the company’s bank account.

  • India (WhatsApp impersonation of Managing Director)
    What happened (early June 2025): Fraudsters created a WhatsApp profile using the Managing Director’s photo, impersonating him to pressure internal staff/CFO into making “urgent” payments of approximately US$299,053 to a fake recipient account.

Warning signs for CEO fraud

There are several common indicators in most CEO-fraud attempts:

  • The request supposedly comes directly from a senior executive.
  • Strong time pressure is applied, with targets told to act immediately.
  • Absolute secrecy is demanded – no one else should be involved.
  • Negative consequences are threatened if the target does not cooperate.

By looking out for these indicators, you’ll spot scam attempts faster. Stay alert.

How to protect yourself and your company from CEO fraud

  • Communicate only through official channels used in your organization, such as professional email accounts or Microsoft Teams. Distrust messages from private email addresses, unknown phone numbers or contacts outside your organization.
  • For calls and videocalls: ask questions that only the real person can answer, as deepfakes can look and sound convincingly real.
  • Follow internal approval processes: the four-eye principle and clear workflows provide reliable protection, even when pressure or secrecy are required.
  • Pay attention to unusual transaction instructions: transfers abroad or to unknown accounts are always a warning sign.
  • If you have any concerns, end the conversation and verify the request by contacting the person via a known phone number or email address.

Frequently asked questions about CEO fraud

Show content of How do I detect fake emails?

Be aware of sender address discrepancies, unusual phrasing, or external markings ("External") in the email. Also check if the email address contains small spelling errors or special characters instead of the correct alphanumeric charters.

Show content of Can the phone number on the screen be fake?

Yes. Criminals use "call ID spoofing" to disguise their real phone number. In case of doubt, call back using a known, official number of the senior executive.

Show content of What should I do if I suspect a fraud attempt?

  • Tell your supervisor immediately if you suspect a fraud attempt.
  • Do not make any payments or other transactions without first conferring with your manager or the relevant authorities and following their instructions. Make sure that you contact the person responsible via known email addresses or telephone numbers.
  • Immediately involve your company's IT or security teams if you suspect fraud, so that the incident can be investigated and appropriate protection measures can be initiated.