SardineCon SF/2026

Learn More
Fraud types4 min de lectura

¿Qué es CEO fraud?

SUBSCRIBE

CEO fraud is a type of business email compromise where the fraudster poses as a senior boss, usually the CEO or CFO, to pressure staff into urgent, secret, off-process payments. People rarely question the boss, so the request gets rushed through.

What is CEO fraud, in plain English?

CEO fraud is a targeted scam in which the attacker impersonates a senior executive, most often the CEO or CFO, and leans on that authority to make an employee act fast and quietly. The classic ask is an urgent wire transfer or a batch of gift-card purchases that must happen now and stay confidential. Because the request appears to come from the top, staff are reluctant to challenge it or slow it down.

It is a specific variant of business email compromise. The fraudster either spoofs a lookalike email address or hijacks a real executive mailbox, then sends instructions that skip the normal payment process. There is usually no malware and no technical breach on the finance team's side; the entire attack runs on authority, urgency, and secrecy.

For fraud teams, the important insight is that CEO fraud targets people and process, not systems. The employee who sends the money is doing what they believe the boss asked. The only durable defense is a payment process strong enough that even a convincing message from the CEO cannot bypass verification.

How a CEO-fraud attack works

  1. Target — Pick the right employee. The attacker finds someone who can move money, often in finance, and learns the reporting lines.
  2. Time it — Wait for cover. They strike when the executive is traveling or hard to reach, so verification is inconvenient.
  3. Pressure — Make the urgent ask. Posing as the boss, they demand a secret, time-critical wire or gift-card purchase, off the usual process.
  4. Extract — Money moves. The rushed payment lands in the fraudster's account and is quickly moved on before anyone checks.

The three hooks it uses

Hook

How it manipulates the target

Authority

The request appears to come from the CEO or CFO, and few employees push back on the boss.

Urgency

A deal or deadline that cannot wait pressures the employee to act before verifying.

Secrecy

The matter is framed as confidential, discouraging the employee from asking colleagues to confirm.

Off-process

The payment is routed around normal controls, framed as a special exception.

What it looks like in practice

In practice

A finance associate gets an email that looks like it is from the CEO, who is known to be traveling that week. The message says a confidential acquisition is closing and a wire must go out today to secure it, with a request to keep it quiet until the announcement. The tone is warm but firm, and it stresses that time is short.

Everything about it is engineered to short-circuit caution: authority from the top, urgency from the deadline, and secrecy to stop the associate checking with anyone. But company policy requires a callback to the executive on a known internal number for any wire above a set amount, and two approvers regardless of who requests it. The associate makes the call, reaches the real CEO who knows nothing about it, and the payment never leaves. The enforced process, not the associate's vigilance under pressure, is what saved the money.

Why it matters to operators

CEO fraud produces fast, large, hard-to-recover losses, and it defeats controls aimed at stolen credentials or malware, because the employee genuinely authorizes the payment. The attack is designed to exploit the exact moment when questioning authority feels awkward and the clock is ticking. Relying on employees to stay sharp under that pressure is not a strategy.

The real fix is an enforced process: firm payment-verification rules, callbacks to known numbers for any change or urgent request, and flags on first-time payees requested by senior staff. When the rule is that no wire goes out without out-of-band confirmation, a perfect impersonation of the CEO still fails, because the fraudster does not control the verification channel. Hope is not a control; the process is.

What to watch

  • Urgent executive payment requests. A wire or gift-card ask that claims to come from the CEO or CFO and cannot wait.
  • Secrecy demands. Instructions to keep a payment confidential are designed to block the verification that would expose it.
  • Timing around travel. Requests that land exactly when the impersonated executive is away or unreachable.
  • First-time payee from the top. A new beneficiary introduced by senior staff, outside the normal vendor process.
  • Off-process framing. Any ask to skip approvals or bypass the usual payment controls as a one-time exception.

Quick questions

How is CEO fraud different from general BEC?

CEO fraud is a specific BEC variant where the impersonated party is a senior executive. Other BEC variants impersonate vendors or employees; CEO fraud specifically weaponizes top-down authority.

Why gift cards so often?

Gift cards are fast, hard to reverse, and easy to liquidate. A fraudster who cannot arrange a wire quickly will often ask an employee to buy gift cards and share the codes instead.

Does training employees fix it?

Training helps but is not enough on its own, because the attack is built to overwhelm judgment with pressure. An enforced verification process that does not depend on the employee resisting is the durable defense.

What is the single most effective control?

A mandatory callback to a known, pre-established number to verify any urgent or off-process payment request, combined with two approvers on wires. The fraudster does not control that channel, so the impersonation collapses.

Why time attacks around travel?

When the real executive is unreachable, verifying feels harder and the employee is more likely to defer to the apparent instruction rather than track the boss down.

Is the CEO's account always hacked?

Not always. Many attacks simply spoof a lookalike address rather than breaching a mailbox, which is why verification cannot rely on the email looking authentic.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

Qué saber junto con CEO fraud