CEO Fraud / Business Email Compromise (BEC)
Learn how CEO fraud and business email compromise (BEC) work, how employees are tricked into wiring money to fraudulent accounts, and how organisations can protect themselves. Includes real-life examples, warning signs, and expert safeguarding tips.
Overview
What is CEO fraud / business email compromise?
Business email compromise (BEC) is a category of fraud in which attackers manipulate an organisation's email communications to deceive employees into transferring money, disclosing sensitive data, or redirecting payroll and supplier payments to accounts controlled by criminals. CEO fraud is its most prevalent form: the attacker impersonates the chief executive — or another senior figure — and instructs a finance team member to process an urgent, confidential wire transfer.
Unlike most cyberattacks, BEC does not rely on malware, ransomware, or technical system breaches. It is a crime of deception, conducted entirely through email — and sometimes a follow-up phone call — using nothing more sophisticated than a convincing identity and a plausible story. There is no virus to detect, no suspicious attachment to flag, and no anomalous network traffic to alert a security team. The weapon is trust, and the target is the employee who holds the authority to move money.
BEC takes several distinct forms beyond CEO fraud. Attackers may impersonate a supplier to redirect an incoming payment, compromise a real employee's email account to submit fraudulent invoices from within the organisation, pose as a law firm or financial institution managing a sensitive transaction, or intercept and modify legitimate payment instructions mid-correspondence. In every variant, the goal is the same: convince someone with financial authority to send real money to a fraudulent account before the deception is discovered.
Who is targeted: Finance directors, accounts payable teams, payroll administrators, executive assistants, and procurement officers — anyone within an organisation who has the authority or access to initiate, approve, or modify financial transactions. Organisations of every size are targeted, from sole traders to multinational corporations.
Why it works: BEC exploits the fundamental trust that organisations place in email as a communication channel, combined with the professional deference employees extend to senior leadership and the time pressure of a business environment where acting quickly is often rewarded and delaying a request from the CEO carries its own professional risk.
Scale & Statistics
How common is this scam?
BEC and CEO fraud are consistently identified by the FBI as the most financially damaging category of cybercrime — not because of volume, but because individual losses are catastrophic and recovery rates are extremely low.
- $2.9 billion in reported losses from BEC in the United States in 2023 — the highest single-category cybercrime loss figure recorded by the FBI IC3 that year
- $55 billion in total global BEC losses were reported to the FBI between 2013 and 2023, across more than 300,000 incidents — making it the costliest decade-long cybercrime trend on record
- 21,489 BEC complaints were filed with the FBI in 2023 alone, representing an average loss of $137,132 per incident
- $4.83 million is the average total cost of a BEC-related data breach per incident in 2024, including financial loss, legal costs, and operational disruption, per IBM
- Only 18% of BEC losses are recovered after the fraud is reported, even when victims contact law enforcement immediately — the majority of funds are moved across international borders within hours
- Payroll diversion BEC — in which attackers redirect employee salary payments — increased by 58% in 2023, according to the Anti-Phishing Working Group
- 43% of BEC attacks in 2024 were carried out without any malware or malicious link — relying entirely on social engineering via email text
Most affected sectors: financial services, real estate, legal, healthcare, and manufacturing — any industry that conducts high-value transactions or manages large supplier payment cycles.
Sources: FBI IC3 2023 Internet Crime Report; IBM Cost of a Data Breach Report 2024; Anti-Phishing Working Group (APWG) BEC Report Q4 2024; Verizon Data Breach Investigations Report 2024; FinCEN Financial Trend Analysis on BEC 2024
How It Works
How does it work?
BEC attacks vary in technical complexity from simple spoofed emails to sophisticated long-running account compromises, but they share a consistent operational logic: establish credibility, manufacture urgency, and extract money before verification can occur.
-
The target organisation is researched — Attackers use open-source intelligence (OSINT) to build a detailed picture of the target: the CEO's name and email address, the CFO's direct reports, the names of regular suppliers, the organisation's payment processes, and the identities of employees with financial authority. LinkedIn, company websites, Companies House or SEC filings, press releases, and social media all contribute to this profile.
-
An email account is compromised or spoofed — In the most damaging variant, the attacker gains actual access to a legitimate email account within the organisation — often a senior executive or a trusted supplier — by exploiting stolen credentials from a prior data breach, a successful phishing attack, or a password-spraying attempt. In simpler variants, the attacker registers a lookalike domain or manipulates the display name to make the email appear to come from a trusted source without needing genuine access.
-
The attacker monitors communications passively — With access to a real inbox, the attacker often spends days or weeks reading email threads before acting. This allows them to identify active transactions, understand payment processes, learn the language and tone used in financial communications, and choose the optimal moment to intervene.
-
A fraudulent instruction is inserted — At a precisely chosen moment, the attacker sends an email that fits naturally into the existing context: an invoice that matches an ongoing supplier relationship, a payment instruction that references a real project, or a CEO request timed to coincide with a board meeting or period of executive travel. The instruction directs a payment to an account the attacker controls.
-
Urgency and secrecy are imposed — The message frames the transaction as time-critical and confidential — a legal matter, a regulatory deadline, a sensitive acquisition. Recipients are often told explicitly not to discuss the payment through normal channels, removing the most effective safeguard against the fraud.
-
Funds are transferred and immediately dispersed — Once the victim initiates the wire transfer, funds are routed through a rapid series of intermediary accounts — often in multiple jurisdictions — before being withdrawn or converted to cryptocurrency. The window for recovery narrows to hours.
Platforms and tools commonly used: Compromised email accounts (Microsoft 365, Google Workspace), lookalike domain registration, email header manipulation, money mule networks for fund dispersal, and cryptocurrency conversion to prevent tracing.
Recent variations in 2024–2025:
- Vendor email compromise (VEC) — rather than impersonating an internal executive, the attacker compromises a supplier's real email account and sends fraudulent invoices or updated banking details from within a trusted ongoing correspondence thread, making detection extremely difficult
- AI-generated BEC emails have been observed matching the precise writing style of the impersonated executive using samples from public speeches, LinkedIn activity, and leaked communications, eliminating the tonal inconsistencies that previously helped recipients identify fraud
- Real estate wire fraud has emerged as a major BEC sub-category, with attackers intercepting conveyancing email chains and substituting solicitor bank account details at the point of property completion — a variant responsible for hundreds of millions of pounds and dollars in annual losses
- MFA-bypass BEC uses adversary-in-the-middle (AiTM) phishing to steal authenticated session tokens, granting the attacker full access to a real Microsoft 365 or Google Workspace inbox without needing the victim's password or second factor
Psychological Tactics
What psychological tactics are used?
BEC is the most financially effective form of social engineering precisely because it operates within the normal psychological framework of a working organisation — exploiting the trust, hierarchy, and time pressure that define professional environments rather than introducing anything that feels foreign or suspicious.
| Tactic | How it is used |
|---|---|
| Hierarchical authority | An email from the CEO or CFO carries an implicit instruction to comply. Employees are conditioned to respond to executive requests quickly and without the scepticism they might apply to an external message. Questioning the instruction feels professionally dangerous. |
| Manufactured urgency | "This must be processed before close of business today." "The acquisition window closes at 5pm." Artificial deadlines compress decision-making time and prevent the target from following verification procedures that would expose the fraud. |
| Confidentiality as a control | Framing the transaction as legally sensitive, commercially privileged, or part of an active investigation gives the target a professional reason to bypass standard controls and avoid consulting colleagues who might raise concerns. |
| Contextual plausibility | BEC emails reference real suppliers, real projects, real executives, and real business relationships — intelligence gathered during the reconnaissance phase. The more specific and accurate the context, the more the message feels like an internal communication rather than an attack. |
| Normalisation through account access | When the attacker operates from within a compromised real email account, every aspect of the message — address, signature, thread history, tone — is genuine. The victim has no visual or technical cue that anything is wrong. |
| Exploitation of process gaps | BEC attacks are frequently designed to exploit known weaknesses in an organisation's approval workflow — targeting moments when a senior approver is travelling, when a transaction falls just below a dual-authorisation threshold, or when a new employee is still learning the processes and less likely to challenge an instruction. |
| Reciprocity | In longer-running attacks, the attacker builds a genuine correspondence history with the target — answering questions helpfully, providing documentation, and establishing a relationship — before making the fraudulent request, which feels like the natural next step in an established dialogue. |
The defining characteristic of BEC's psychological power is that it does not ask victims to do something unusual. It asks them to do something entirely routine — process a payment, update bank details, approve an invoice — in a context that has been engineered to make that routine action feel unambiguously appropriate.
Real-Life Example
A real-life case
Case: Toyota subsidiary loses $37 million in BEC wire transfer fraud (2019, landmark case with enduring relevance)
In 2019, Toyota Boshoku Corporation — a major automotive parts supplier and subsidiary of the Toyota Group — disclosed that it had lost approximately $37 million (¥4 billion) to a business email compromise attack. The fraud was executed through a single email exchange.
Attackers impersonated a trusted business partner of the company and contacted a European finance executive with instructions to urgently change the bank account details for an existing supplier payment. The email was convincingly constructed, referenced the correct supplier relationship, and was framed as a routine administrative update required before an imminent payment deadline. The finance executive, believing the request to be legitimate, updated the account details and processed the transfer.
The fraud was discovered only when the genuine supplier followed up on a payment that had not arrived. By that point, the funds had been transferred to accounts under the attackers' control and dispersed across multiple jurisdictions. Efforts to recover the money through international law enforcement cooperation recovered only a fraction of the total.
The outcome: Toyota Boshoku revised its internal financial controls following the incident, implementing mandatory dual-channel verification for any change to supplier payment details and requiring independent confirmation of all new banking information before processing. The case is cited by financial regulators and cybersecurity practitioners globally as a canonical example of how BEC bypasses technical defences entirely — no malware was involved, no system was hacked, and no technical vulnerability was exploited. The only thing that failed was a human process.
Source: Toyota Boshoku Corporation official disclosure, September 2019; Reuters, "Toyota unit loses $37 million in email scam," September 2019; FBI BEC Public Advisory 2020 — ic3.gov
Red Flags to Watch
Red flags to watch for
- An email from a senior executive or known supplier requests an urgent wire transfer, particularly one that must be processed the same day or before a specific deadline outside normal business hours
- The request asks you to change existing bank account or payment details for a supplier, employee payroll, or business partner — especially if the instruction arrives by email alone without a preceding phone call or formal documentation
- The email explicitly asks you to keep the transaction confidential, not to discuss it with colleagues, or to bypass the organisation's normal approval process due to urgency or sensitivity
- The email sender's address looks almost correct but contains a subtle difference — a missing letter, an extra character, a different domain extension, or a lookalike spelling of the company name
- The instruction references a transaction, project, or supplier relationship that is real — but the specific request (new account details, urgent transfer, changed payment method) does not align with your established process
- A payment is directed to a new bank account, a different country, or an institution not previously used in your organisation's financial relationships, with no documented justification
- The executive making the request is stated to be travelling, in meetings, or otherwise unreachable by phone — making independent verification appear inconvenient or impossible
- A follow-up call to confirm the request comes from a number you do not recognise, or the caller discourages you from calling the executive back through the organisation's switchboard
How to Identify
How to identify a BEC attempt
Ask yourself before acting:
- Does this request follow our organisation's normal payment authorisation process, or is it asking me to bypass standard procedures for reasons I cannot independently verify?
- Has a change to payment or banking details been confirmed through a second, independent channel — not just the email in front of me?
- Can I reach the executive or supplier making this request by phone, using a number from our own records, to confirm the instruction before processing?
Verification steps:
- Never change bank account or payment details based solely on an email instruction — always confirm by calling the supplier or executive directly using a number from your own contact records or the organisation's official directory, not a number provided in the email
- Apply a mandatory callback policy for all payment detail changes and high-value transfers — this single control prevents the majority of BEC attacks from succeeding
- Check the sender's full email address character by character — display names can be set to anything, and the underlying domain is where spoofing is most often detectable
- Examine the email headers if possible — the "Reply-To" field, routing information, and originating IP address can reveal a mismatch with the claimed sender even when the display address appears correct
- Cross-reference any invoice or payment instruction against your organisation's purchase order system, supplier contract register, or accounts payable records before processing
- Report any suspicious payment request to your IT or security team immediately — even if you are uncertain, escalating costs nothing; processing a fraudulent transfer may cost everything
Legitimate vs fraudulent — how to tell:
| Legitimate payment instruction | BEC email |
|---|---|
| Follows the organisation's documented approval and authorisation process | Asks you to act outside normal procedures due to urgency or confidentiality |
| Payment details match established, verified supplier or partner records | Introduces new, changed, or unverified account details |
| The requesting party is reachable by phone for independent confirmation | Executive or supplier is stated to be unavailable, travelling, or in meetings |
| Adequate time is given for proper verification and dual authorisation | A same-day or immediate deadline is imposed with no flexibility |
| Consistent with previous communications in tone, format, and process | May differ subtly in tone, formatting, or the level of process detail provided |
How to Protect
How to protect yourself
Preventive habits:
- Implement a mandatory out-of-band verification policy for all changes to supplier payment details and for any wire transfer above a defined threshold — a phone call to a number from your own records is the single most effective BEC prevention control available
- Establish a dual-authorisation requirement for high-value or unusual transactions, so that no single employee can initiate and approve a large payment independently
- Configure email authentication standards — DMARC, DKIM, and SPF — on your organisation's domain to reduce the effectiveness of display name spoofing and lookalike domain attacks
- Enable external email banners in your email platform (Microsoft 365 or Google Workspace) to visually flag messages originating from outside your organisation — this one setting has prevented many BEC attacks by making the external origin of an apparent internal email visible
- Train finance, accounts payable, HR, and executive support teams on BEC scenarios specifically — these are the roles most frequently targeted and they require dedicated, role-specific awareness
- Conduct periodic BEC simulation exercises to test whether verification procedures are actually followed when an urgent executive payment request is received under realistic conditions
If you have already been targeted:
- If a fraudulent transfer has already been initiated, contact your bank immediately and ask them to issue a SWIFT recall or hold on the transaction — speed is critical; transfers recalled within hours have a significantly higher recovery rate than those reported days later
- Simultaneously file an emergency report with the FBI's IC3 (US) or Action Fraud (UK) — both agencies have rapid-response financial fraud units that can coordinate with receiving banks to freeze funds if notified quickly enough
- Preserve all emails, headers, and correspondence related to the attack without modification — do not delete or forward without first preserving originals for forensic investigation
- Notify your cyber insurance provider immediately if your organisation holds a relevant policy — policy terms often require prompt notification to be valid
- Conduct an internal investigation to identify how the attack succeeded and which controls failed — this is essential for preventing a repeat incident, as attackers who succeed once frequently return
- Issue internal communications to alert other employees — particularly those in finance and procurement — that a BEC attempt is active and that heightened verification is required for all payment instructions
Useful tools:
| Tool | What it does | Cost |
|---|---|---|
| MXToolbox | Verifies DMARC, DKIM, and SPF configuration on your domain to assess spoofing exposure | Free |
| Have I Been Pwned | Checks whether corporate email addresses have been exposed in known data breaches — compromised credentials are a primary route for account takeover BEC | Free |
| VirusTotal | Scans suspicious links and attachments associated with BEC lure emails | Free |
| Abnormal Security | AI-powered email security platform with dedicated BEC and vendor email compromise detection, designed specifically to catch attacks that bypass traditional filters | Paid |
Video Lesson
Watch: BEC explained
A clear, structured walkthrough of how business email compromise attacks are planned and executed, how attackers impersonate executives and suppliers to authorise fraudulent transactions, the different BEC variants including CEO fraud, invoice fraud, and payroll diversion, and the organisational controls — particularly out-of-band verification — that are most effective at preventing losses. Suitable for viewers with no prior cybersecurity knowledge.
Further Reading
Further reading
Official resources
- FBI Internet Crime Complaint Center (IC3) — "Business Email Compromise: The $50 Billion Scam" — the FBI's definitive public advisory on BEC mechanics, global loss data, and victim guidance → ic3.gov
- CISA (Cybersecurity & Infrastructure Security Agency) — Technical and procedural guidance for organisations on defending against BEC and email account compromise → cisa.gov/bec
- NCSC (National Cyber Security Centre, UK) — Practical guidance on business email compromise prevention, including DMARC configuration and payment verification controls → ncsc.gov.uk/bec
- Action Fraud (UK) — Report BEC incidents and access victim support; Action Fraud coordinates with the National Fraud Intelligence Bureau on fund recovery → actionfraud.police.uk
- FinCEN (US Financial Crimes Enforcement Network) — Financial trend analysis and advisories on BEC targeting real estate, healthcare, and supply chain payment processes → fincen.gov
Research & reports
- FBI IC3 — Annual Internet Crime Report — includes a dedicated BEC section with year-on-year loss data, most targeted sectors, and recovery statistics → ic3.gov/annualreport
- Verizon — "Data Breach Investigations Report (DBIR) 2024" — BEC and pretexting account for a significant and growing share of all confirmed data breaches globally → verizon.com/dbir
- APWG — "Business Email Compromise Trends Report Q4 2024" — quarterly analysis of BEC attack volumes, average transfer amounts, and emerging variants including payroll diversion → apwg.org/trendsreports
Investigative coverage
- Reuters — "Toyota unit loses $37 million in email scam" — contemporaneous reporting on the Toyota Boshoku BEC case → reuters.com
- KrebsOnSecurity — Ongoing in-depth coverage of BEC infrastructure, money mule networks, and high-profile corporate fraud cases → krebsonsecurity.com
Related articles on this platform
- Phishing Email — fraudulent emails impersonating trusted organisations to steal credentials
- Whaling Attack — phishing specifically targeting CEOs and senior executives for large financial transfers
- Clone Phishing — legitimate emails duplicated with malicious links or attachments replacing the originals
- Vishing (Voice Phishing) — phone calls used to supplement BEC emails and provide false verbal confirmation of fraudulent payment instructions