← All terms

CEO Fraud

CEO fraud is a social engineering attack where criminals impersonate a senior executive to pressure an employee into urgent wire transfers or data disclosure.

CEO fraud is a form of business email compromise in which the attacker impersonates a senior executive — most often the CEO or CFO — and instructs an employee to make an urgent payment, buy gift cards, or hand over sensitive data. Where whaling targets the executive, CEO fraud weaponizes the executive's authority against their own staff.

How it works

The attacker first researches the organization: who runs it, who works in finance, who has payment authority, and when the real executive is traveling or unreachable (public speaking schedules and out-of-office replies are gold for this). They then contact a target in finance or accounting using a spoofed email address, a look-alike domain, a compromised mailbox, or increasingly a deepfake voice call or video message.

The message follows a reliable psychological formula: authority ("this comes directly from me"), urgency ("the deal closes today"), and secrecy ("this acquisition is confidential — do not discuss it with anyone"). That combination is designed to override normal process. The employee, wanting to be responsive to the boss, initiates the wire transfer before anyone can question it. By the time the real executive surfaces, the money has been layered through mule accounts and is usually unrecoverable.

How to defend against it

Process beats vigilance here. Enforce out-of-band verification for every payment request or banking change above a threshold — a phone call to a number already on file, never to a number supplied in the email. Make dual approval mandatory for wires, with no executive override; the whole point of the attack is that "the CEO said so" should never be sufficient authorization. Flag external emails visibly, monitor for look-alike domain registrations, and lock down executives' public travel information where possible.

Just as important is culture: employees must know, explicitly and from the executives themselves, that they will be praised — not punished — for pausing a "CEO request" to verify it. Test that reflex with realistic simulations that mimic authority and urgency, and track which teams remain susceptible over time. The same authority-plus-urgency script also drives the lower-value gift card scam — and the policy answer is identical: verify out-of-band, every time.

Related terms

Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.WhalingWhaling is a spear phishing attack specifically targeting senior executives or high-value individuals within an organization.DeepfakeA deepfake is AI-generated synthetic media — audio, video, or images — used in social engineering to impersonate trusted individuals convincingly.Invoice FraudInvoice fraud tricks a company into paying a fake or altered invoice, typically by impersonating a real supplier and changing the bank account details.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo