CEO Fraud: How to Verify Before You Send the Money
Business email compromise costs organisations billions a year and defeats email filtering entirely. The defence is process, not vigilance. Here is the process.
ClickSafe Team
Security awareness · ClickSafe ·
Business email compromise is the most expensive category of email attack, and it is also the least technically sophisticated. There is usually no malware, no exploit, and often no link. There is a person who is asked to move money and does.
That is exactly why filtering does not stop it. There is nothing in the message for a filter to object to.
How the attack actually runs
Reconnaissance. The attacker maps the organisation from public sources: leadership names from the website, reporting structure from LinkedIn, finance staff from conference attendee lists, supplier relationships from press releases and job adverts.
Access or impersonation. Either a real mailbox is compromised through earlier credential phishing, or a lookalike domain is registered, a transposed character, a different top-level domain, or a hyphen inserted somewhere plausible.
Timing. The request arrives when verification is hardest: during a quarter close, while the executive is visibly travelling, late on a Friday, or in the week of an announced acquisition.
The request. Plausible in size, urgent but not hysterical, and framed as routine. Sophisticated versions ask a question first and only introduce the payment after a reply establishes rapport.
The three variants worth training
Executive impersonation
A senior figure asks for an urgent transfer, usually citing confidentiality. Authority plus time pressure plus isolation, in one message.
Supplier payment diversion
A genuine supplier thread is hijacked, and revised bank details arrive as a reply within it. The conversation history is real, which is what makes this the hardest variant to catch by inspection.
Payroll redirection
An employee appears to request a change to their salary deposit account. Lower value than the other two, higher frequency, and often unnoticed until payday.
Why "be more careful" is not a defence
Every well-intentioned instruction to scrutinise sender addresses has the same weakness: it requires the target to be alert at the exact moment the attack is engineered to remove alertness. It also fails outright against a compromised mailbox, where the sender address is genuinely correct.
Voice cloning has removed the remaining fallback. A callback to a number supplied in the email is now worse than useless.
The defence that works
Controls, not attention. Each of these holds even when the attacker has full access to a real mailbox.
Out-of-band verification, using contact details you already hold. Any payment request or bank-detail change is confirmed by phoning a number from your own records, never a number in the message, and never by replying to the thread.
Dual authorisation above a threshold. Two named people approve, independently. Set the threshold low enough to matter and high enough not to paralyse operations.
A mandatory delay on new payment destinations. First payments to a new account wait twenty-four hours. Fraud depends on speed; legitimate business almost never does.
A challenge phrase for high-value requests. A shared word confirmed verbally, agreed in advance and never sent by email. Trivial to implement and it survives a convincing voice clone.
Explicit permission to challenge seniority. Write it down and have an executive say it out loud: no one will face consequences for verifying a payment request, regardless of who appears to have sent it. Without this, the entire control set fails on the first genuinely intimidating email.
Training this specifically
Generic phishing training does not cover BEC well, because BEC often contains no link and no attachment, the two things people are taught to check.
Train finance and executive assistants separately, with scenarios drawn from your own payment workflows. Run the simulation against the real approval process and observe where it bends: whether anyone phoned, whether the second approver actually looked, whether the delay was waived because the request seemed urgent.
The result you want from the exercise is not a low click rate. It is watching someone pick up the phone.
The template gallery includes executive impersonation, supplier bank-detail change, and payroll redirection scenarios, and CEO Fraud: How to Verify Legitimacy covers the verification process in eighteen minutes.


