CEO Fraud

CEO fraud is an attack in which someone impersonates a senior executive to instruct an employee to move money or release sensitive data. It is a subtype of business email compromise, distinguished by who is impersonated and by what it exploits: not a technical vulnerability, but the reluctance of a junior employee to question an urgent instruction from the top.

Also called Executive impersonation, whaling, CEO scam
Relationship to BEC A subtype — BEC also covers vendor invoice fraud, payroll diversion and attorney impersonation
Impersonated A CEO, CFO or other senior figure with authority to direct payments
Targeted Finance and accounts payable staff, and executive assistants
Typical pretext An urgent confidential transaction, an acquisition, a supplier that must be paid today
Delivery Spoofed or lookalike email domains, compromised mailboxes, and now voice and video
Exploits Authority, urgency and confidentiality — not a software flaw
Escalation since 2024 Real-time deepfake audio and video used to impersonate executives on calls

How it works

The attack begins with research. Company filings, press releases, LinkedIn and out-of-office replies give the attacker the executive’s name and travel patterns, the finance team’s structure, and the vocabulary the organization uses internally. None of it requires access to anything.

The message then arrives with three properties working together. Authority — it appears to come from someone whose instructions are not normally challenged. Urgency — a deadline that makes verification feel obstructive. Confidentiality — a reason not to discuss it with anyone, which neatly disables the one control that would stop it.

Delivery ranges from crude to indistinguishable. A lookalike domain swapping one character. A reply-to address differing from the display name. A truly compromised executive mailbox, which defeats every technical email control because the message really is from the right account.

The deepfake escalation

The standard advice for years was to verify out of band: call the executive and confirm. That advice now has a gap in it.

Synthetic audio can reproduce a named individual’s voice from a small sample — a conference talk, an earnings call, a podcast. Video conferencing has followed. The most cited case involved a finance employee joining a video call with what appeared to be several colleagues, including the CFO, all of them synthetic, and authorizing transfers worth tens of millions.

The consequence is specific and worth stating plainly: a callback to a number the attacker supplied, or a video call the attacker convened, is no longer verification. What survives is out-of-band contact through a channel the recipient initiates from independently held details, and payment controls that do not depend on recognizing a person at all.

This is where deepfake detection stops being a fraud-team abstraction and becomes a finance-process problem. GenAI detection and deepfake analysis addresses the media itself, and GenAI and deepfake fraud controls matter precisely because the human verification step they target was the last line.

Controls that work

Control Why it holds
Callback on independently held contact details Defeats a spoofed sender; only works if the number comes from internal records, never from the message
Dual authorization above a threshold Removes the single point of failure the attack depends on
A mandatory delay on new payees Urgency is the attack’s main tool; a cooling-off period disarms it
Verified change-of-bank-details process Closes the vendor variant, which is the more costly one in aggregate
Explicit permission to question executives The social control — and often the missing one

The last row is not a soft recommendation. The attack works because juniors do not challenge seniors. An organization where finance staff are told, by the executives themselves, that verifying an instruction is expected rather than insubordinate has removed the mechanism the fraud runs on.

What CEO fraud isn’t

It is not a hack in most cases. Usually no system is breached; a person is persuaded. Technical controls help at the margin and do not address the core.

It is not stopped by email filtering alone. A message from a compromised executive mailbox passes authentication because it is authentic.

It is not only a large-company problem. Smaller organizations are targeted precisely because they lack dual authorization and formal payment controls.

A voice or a face is no longer proof. Any control resting on recognizing someone on a call needs rebuilding around process rather than recognition.

Frequently asked questions

What is the difference between CEO fraud and business email compromise?

CEO fraud is one type of business email compromise. BEC is the umbrella term covering the impersonation of any trusted party to induce a payment or data disclosure — including vendors sending false invoices, attorneys demanding confidential transfers, and payroll diversion. CEO fraud specifically impersonates a senior executive.

Can deepfakes be used in CEO fraud?

Yes, and they are. Synthetic audio can reproduce an executive’s voice from publicly available recordings, and synthetic video has been used in live conference calls. This directly undermines the traditional advice to verify by calling or video-calling the person, unless the recipient initiates contact using independently held details.

How do you verify an urgent payment request?

Contact the requester through a channel you establish yourself, using contact details held in internal records — never a number or address supplied in the request. Combine that with dual authorization above a threshold and a mandatory delay on payments to new payees, so no single verification step carries the whole decision.

Why do employees fall for CEO fraud?

Because the attack is engineered around organizational reality rather than technical weakness. It combines apparent authority, artificial urgency and a request for confidentiality, which together make verifying feel like both insubordination and obstruction. Cultures where questioning an executive instruction is explicitly encouraged are markedly more resistant.

Related reading

  • Business email compromise — the parent category, including the vendor and payroll variants
  • Deepfake — the technology that broke the callback control
  • Phishing — the broader technique, and how targeted attacks differ from mass campaigns
  • Money mule — where the funds go once an authorized payment has been induced

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data