CEO Fraud
CEO fraud is a social engineering attack where criminals impersonate a senior executive to pressure an employee into urgent wire transfers or data disclosure.
CEO fraud is a form of business email compromise in which the attacker impersonates a senior executive — most often the CEO or CFO — and instructs an employee to make an urgent payment, buy gift cards, or hand over sensitive data. Where whaling targets the executive, CEO fraud weaponizes the executive's authority against their own staff.
How it works
The attacker first researches the organization: who runs it, who works in finance, who has payment authority, and when the real executive is traveling or unreachable (public speaking schedules and out-of-office replies are gold for this). They then contact a target in finance or accounting using a spoofed email address, a look-alike domain, a compromised mailbox, or increasingly a deepfake voice call or video message.
The message follows a reliable psychological formula: authority ("this comes directly from me"), urgency ("the deal closes today"), and secrecy ("this acquisition is confidential — do not discuss it with anyone"). That combination is designed to override normal process. The employee, wanting to be responsive to the boss, initiates the wire transfer before anyone can question it. By the time the real executive surfaces, the money has been layered through mule accounts and is usually unrecoverable.
How to defend against it
Process beats vigilance here. Enforce out-of-band verification for every payment request or banking change above a threshold — a phone call to a number already on file, never to a number supplied in the email. Make dual approval mandatory for wires, with no executive override; the whole point of the attack is that "the CEO said so" should never be sufficient authorization. Flag external emails visibly, monitor for look-alike domain registrations, and lock down executives' public travel information where possible.
Just as important is culture: employees must know, explicitly and from the executives themselves, that they will be praised — not punished — for pausing a "CEO request" to verify it. Test that reflex with realistic simulations that mimic authority and urgency, and track which teams remain susceptible over time. The same authority-plus-urgency script also drives the lower-value gift card scam — and the policy answer is identical: verify out-of-band, every time.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo