CEO fraud (BEC): how to defend against it
By Thomas · virtual CISO · 2026-08-03
CEO fraud — Business Email Compromise (BEC) — doesn't resemble any other cyberattack. No malware, no exploited software flaw, no ransomware. Just an email, well written, that seems to come from the right person at the right moment, asking for urgent, confidential action. It's one of the costliest forms of fraud in the world, precisely because it needs no technical sophistication — only a good grasp of organizational psychology, a bit of public research on the target, and the willingness to write a convincing message.
How the attack works
The classic scenario unfolds in a few recognizable steps. The attacker first identifies their target in the org chart — often an accountant, a financial controller, or an executive assistant with the authority or access to initiate a transfer. They then study the company's structure, executives' names, sometimes their writing style, via public sources (website, professional social networks, press releases).
Next comes the email itself, generally sent from an address that resembles the impersonated executive's — either a directly spoofed email (see what is email spoofing for the technical mechanics), or a lookalike domain registered for the occasion, or, more rarely, a genuinely compromised account. The message leans on three proven psychological levers: urgency ("this needs to happen before end of day"), confidentiality ("don't mention it before the deal closes, it's sensitive"), and authority (the supposed sender's tone and status discourage pushback from someone lower in the hierarchy).
Why it keeps working
CEO fraud exploits a real organizational weakness, not just individual naivety. In many companies, hierarchy creates implicit pressure to quickly comply with a request presumed to come from leadership, especially when framed as urgent and sensitive. Questioning an apparent order from the CEO, even out of legitimate caution, can feel socially risky for an employee — hence the effectiveness of authority combined with urgency, which short-circuits the natural instinct to verify.
The requested confidentiality plays an equally central role: it keeps the victim from consulting a colleague or a supervisor before acting, an ordinary reflex that would often have been enough to reveal the anomaly. It's deliberate psychological isolation, designed to disable the most natural verification mechanism — talking to someone else — which is exactly the mechanism a systematic verification procedure must forcibly restore.
The most common variants
Beyond the classic urgent-transfer scenario, several variants have developed:
- The fake vendor invoice — the attacker poses as a regular vendor and communicates a change of bank details, diverting future legitimate payments.
- The sensitive data request — instead of a transfer, the email requests confidential information (pay stubs, employee tax data), later exploited for identity theft or further fraud against those same employees.
- The HR urgency — an email seemingly from an executive asking HR to quietly change the payroll bank details of an "employee," actually the attacker's own account.
Each variant reuses the same psychological foundation — urgency, confidentiality, authority — applied to a different context, which is why the most effective training teaches recognizing that foundation rather than memorizing a fixed list of scenarios that attackers can simply route around.
One evolution worth noting: the classic warning signs based on clumsy writing are losing their reliability. Generative tools now let attackers produce messages in flawless English, matching the tone of the executive being impersonated from their public statements or LinkedIn posts. Training that mostly teaches people to spot spelling mistakes is training for the previous decade's attacks. The signals that survive this shift are the structural ones — urgency, confidentiality, a request to bypass procedure — because they're inherent to the fraud itself: the attacker can polish the style endlessly, but they can't remove the ask.
Technical defenses
DMARC at an enforcing policy (p=quarantine or p=reject) eliminates the most direct variant: the email using exactly the impersonated company's domain. If the attack relies on a forged From: leadership@example-company.com, DMARC blocks the message before it reaches the victim. It's a structural defense that protects every employee at once, not mere individual vigilance — see preventing email spoofing for the full stack of technical defenses.
But DMARC doesn't cover lookalike domains or compromised accounts — the two other frequent vectors of CEO fraud, both of which sidestep the domain check entirely. That's why technical defenses alone are never fully sufficient against this specific attack; they shrink the surface, without eliminating it entirely, which makes the organizational defenses described below just as essential.
Organizational defenses
This is where most of the protection against the variants DMARC doesn't cover comes from:
- Systematic second-channel verification. Any unusual transfer request or bank-detail change must be confirmed via a channel different from the one used for the request — a phone call to a number known in advance, never the one provided in the suspicious email itself.
- A dual-validation threshold. Beyond a certain amount, no transfer should be executable by a single person, regardless of the pressure applied or the seniority of the person supposedly requesting it.
- Targeted training for finance and admin teams on precise warning signs: artificial urgency, requests for confidentiality, sudden changes to bank details, unusual style mistakes from an otherwise careful sender, or an explicit request to bypass an existing validation procedure.
- A culture that values verification, rather than one where questioning an executive is seen as a lack of trust. This is often the hardest change to make, since it touches the organization's management culture, but also the most decisive one over time, outlasting any single training session.
The real cost of a successful fraud
The amounts at stake fully justify investing in these defenses. A successful CEO fraud commonly runs into tens of thousands of euros for an SMB, and can reach far higher amounts for a large company — some publicized cases have exceeded several million. Beyond the direct financial loss come the cost of the investigation, the impact on internal trust (the employee who executed the transfer often carries a disproportionate psychological burden despite having done nothing unusual by the organization's own standards), and sometimes legal consequences if due-diligence obligations weren't met — insurers in particular often require proof of reasonable control procedures before covering this kind of loss.
A typical case, broken down
To ground these principles, here's how a typical case unfolds at a mid-sized company. On a Friday afternoon, the accounting department receives an email signed with the name of the CFO, currently traveling (information gathered from LinkedIn a few days earlier). The message explains a confidential acquisition is closing and a €45,000 transfer must go out before markets close, to an account provided in the message. The tone is professional, echoes phrasing the real CFO typically uses, and the sending address resembles the real one closely enough to escape notice on a quick read — one substituted character, invisible on most screens.
The accountant, used to processing requests from leadership without question, prepares the transfer. One detail gives her pause: this type of operation normally requires dual-signature approval, a procedure the email explicitly asks to skip "just this once, to move faster." That precise bypass of procedure — framed as an exception justified by urgency — is the most reliable warning sign in this kind of scenario. A clear policy, known across the team, stating that no procedural exception is ever accepted via email, would have stopped this attempt before even checking the sending address.
In this example, a simple call to the CFO on his usual number — not the one given in the email — would have revealed the anomaly in under a minute. That verification step, simple and fast, is what's most often missing in victim organizations — not out of individual negligence, but because no procedure systematically requires it, leaving the decision to an employee under time pressure and social pressure at once.
Responding to a confirmed fraud
If a CEO fraud has just been discovered, speed of action matters enormously:
- Contacting the sending bank immediately to attempt a transfer recall — the odds of success drop drastically with time, often within a matter of hours, before the funds are permanently out of reach, so this call comes before anything else, including internal deliberation.
- Filing a police report promptly, which sometimes triggers international cooperation procedures between banks in cross-border cases.
- Documenting the incident in detail (emails, timestamps, amounts, the exact sequence of internal decisions) for the investigation and any insurance claims.
- Analyzing the gap that allowed the attack — which domain was spoofed, through which channel, which internal procedure was bypassed — to fix it before it recurs, possibly in a slightly different form aimed at the same weak point, since the same gap left open will attract a repeat attempt.
In summary
CEO fraud thrives on hierarchical trust and artificial urgency, not technical sophistication. The most effective defense combines two layers: DMARC enforced to eliminate direct domain spoofing, and rigorous organizational procedures — second-channel verification, dual validation, targeted training — to cover what technology alone can't reach.
Checking that a domain isn't exposed to the most direct form of this fraud takes a single pass through the free DMARC analyzer. It's the first line of defense, free and fast to set up, before the internal procedures even get revisited — the two efforts reinforce each other, but this one costs nothing to start today, right now, before the next email lands and finds a target unprepared.
Enforcing DMARC, in practice
Thomas, the virtual CISO of DMARC.com, identifies every legitimate sending source, writes the exact DNS records, and takes a domain from p=none to p=reject — without breaking its mail.
Get to p=reject — freeRelated guides
- Preventing email spoofing
Email spoofing hits organizations of every size. Here are the concrete defenses — technical and organizational — that actually protect a domain, beyond DMARC alone.
- What is email spoofing, exactly
Spoofing means forging an email's sender to deceive the recipient. How it works technically, why it stayed possible for decades, and how DMARC ends it.
- What is DMARC, and how does it stop email spoofing?
A plain-English guide to DMARC: what it is, how it builds on SPF and DKIM, what the policies mean, and what DMARCbis (RFC 9989) changes in 2026.
About the author
Thomas — Thomas is the virtual CISO of DMARC.com: a copilot specialized in email authentication that walks organizations from p=none to p=reject without breaking their mail. His guides draw on real data from the DMARC Observatory and the RUA reports the platform analyzes.
