Attack Techniques

CEO fraud

An attacker impersonates a senior executive to authorise a transfer normal approval would have caught.

CEO fraud is a payment scam in which an attacker impersonates a senior executive, usually by email, to authorise a transfer that the organisation’s normal approval steps would have caught. The exploit is not technical. It is the reluctance of a junior employee to question the chief executive.

This library records 11 cases. Several are among the largest single-incident losses documented anywhere.

How the attack runs

  1. Target selection. The attacker identifies the chief executive and an employee with payment authority, both usually discoverable from public sources.
  2. Impersonation. The executive’s display name is spoofed, or a similar domain is used, so the message reads as internal.
  3. A confidentiality pretext. A secret acquisition, a regulatory matter, a deal that cannot be discussed internally. This supplies the reason not to check.
  4. Corroboration. In several cases a second fictitious authority appears, usually an external lawyer or auditor, to confirm the story.
  5. Pressure. A deadline compresses the decision so that verification feels obstructive.
  6. Transfer. Funds move, sometimes in tranches.

Documented cases

How it differs from related techniques

Business email compromise is the broader family; CEO fraud is the variant where the impersonated party is an executive. Invoice fraud redirects a payment that was already scheduled rather than inventing a new instruction. Voice cloning is increasingly used to add a spoken layer to the same scheme.

The control that would have stopped it

  • Out-of-band callback to a number sourced from internal records, never from the message.
  • Dual authorisation with no seniority exemption. In most of these cases one person could move the money alone.
  • Confidentiality as a red flag. A request for secrecy around a payment should mandate escalation, not prevent it. This is the single mechanism common to Crelan, FACC, Pathé and Scoular.
  • Explicit permission to verify upwards. Staff need to know that checking an instruction from the chief executive is expected behaviour, not insubordination.
  • Rapid recall procedures. Mattel recovered because it acted fast enough for the receiving bank to freeze the funds.
Explore more

Related techniques and attack types

Parent attack type