CEO Fraud
Pronunciation: C-E-O FRAWD
Definition
CEO Fraud is a form of business email compromise or impersonation in which an attacker poses as a senior executive to pressure staff or partners into sending money, changing payment details, disclosing data, or bypassing controls. It relies on authority, urgency, secrecy, and organizational knowledge rather than necessarily compromising the executive’s actual account. Controls require independent verification of unusual requests, dual approval, protected supplier changes, payment limits, executive communication rules, domain monitoring, and a culture that permits employees to challenge urgent instructions.
Overview
CEO Fraud is a form of business email compromise or impersonation in which an attacker poses as a senior executive to pressure staff or partners into sending money, changing payment details, disclosing data, or bypassing controls. The control exists to prevent deceptive or unauthorized transactions, reduce customer and merchant loss, and preserve evidence for recovery, dispute handling, and investigation. It relies on authority, urgency, secrecy, and organizational knowledge rather than necessarily compromising the executive’s actual account. It should be interpreted alongside Invoice Fraud because the concepts can affect the same decision without representing the same control, event, or risk.
The workflow combines identity, device, behavior, communication, beneficiary, transaction, and historical signals before and after payment. High-risk changes or instructions should be verified through a trusted independent channel, and controls should not rely on information supplied inside the potentially compromised message or session. In this context, controls require independent verification of unusual requests, dual approval, protected supplier changes, payment limits, executive communication rules, domain monitoring, and a culture that permits employees to challenge urgent instructions.
It should connect the term to Business Email Compromise (BEC) where that relationship changes access, transaction treatment, investigation, communication, or recovery.
Records should preserve the original request, account and device events, approvals, beneficiary changes, transaction identifiers, communications, authentication results, review notes, and recovery actions. Teams should connect related attempts without exposing unnecessary personal or credential data.
Useful measures include attempted and confirmed loss, prevented value, false-positive rate, review time, recovery rate, beneficiary-change exceptions, customer complaints, repeat attacks, and control-bypass findings.
The relationship with Beneficiary Name Check should be documented where it affects residual risk or control ownership.
Key Takeaway
Controls require independent verification of unusual requests, dual approval, protected supplier changes, payment limits, executive communication rules, domain monitoring, and a culture that permits employees to challenge urgent instructions.
Sources
- Business Email Compromise — FBI Internet Crime Complaint Center (2026-08-03)
- Recognize and Report Phishing — Cybersecurity and Infrastructure Security Agency (2026-08-03)
- Digital Identity Guidelines: Authentication and Authenticator Management, SP 800-63B-4 — NIST (2026-08-03)