Back to blog

CEO fraud: how can you protect yourself?

B
BlueSecure
Équipe BlueSecure
March 7, 20234 min read
CEO fraud: how can you protect yourself?

Gilbert Chikli is famous for popularizing CEO fraud, a sophisticated scam technique in which he impersonated a company executive and persuaded employees to transfer money to a fraudulent account. The Chikli case, featured in the Netflix documentary “The Mask,” highlighted the risks of this scam and emphasized the need for companies to strengthen their security and raise employee awareness.

Even today, CEO fraud remains a significant threat to businesses, with around 6,000 companies affected each month and more than 2,300 complaints filed over five years. This attack generally targets a few key employees within an organization, but it can affect all types of structures, and the number of attacks is steadily increasing. With the widespread adoption of remote work since the COVID health crisis, employees communicate more with their colleagues by phone and email, making it easier to impersonate managers. Scammers therefore target isolated workers who cannot easily share their doubts or questions with their direct colleagues.

What is the modus operandi?

CEO fraud is a highly sophisticated and well-developed social engineering technique.

Indeed, this attack requires advance research to gather information in order to manipulate the target more easily afterwards. In past attacks, malicious individuals have, for example, managed to obtain personal information about a finance director who had recently lost his wife. They also researched the acquisition or merger plans of a targeted company. All personal and professional information collected is used to make the scenario more credible.

This type of scam is generally carried out via email, SMS, and telephone. The scammer often uses “spoofing” techniques to make the victim believe they are using a legitimate company email address or phone number. They may also provide privileged information about the company or use other manipulation tactics to persuade the victim to make the bank transfer.

The malicious individual will attempt to convince an internal employee to issue transfer orders as part of exceptional and confidential transactions (external growth, a subsidiary's cash-flow needs, etc.) to their bank account located abroad. They will then confirm their request to the victim by sending an email, an official letter, or an SMS from the compromised mailbox or phone number of the executive, thereby stealing money from the organization. In this type of attack, the urgency, confidentiality, or unusual nature of the request should raise suspicions.

A French e-commerce company fell victim to this scam in 2015. The scammers created a fake email account that looked almost exactly like that of the company's CEO and sent an email to a finance manager at the company. In this email, they requested an urgent transfer of more than €18 million to finalize a confidential acquisition. The finance manager was deceived by the authenticity of the email and made the transfer. It took the company several weeks to realize that the money had been sent to a foreign bank and that it had been the victim of fraud.

In 2016, Snapchat also fell victim to CEO fraud. The fraudsters impersonated the company's CEO and sent an email to a payroll employee, asking them to provide the company's tax information. The employee provided the information, which was used to impersonate the company and request fraudulent tax refunds.

CEO fraud scam

How can you protect yourself against CEO fraud?

To protect against CEO fraud, non-bypassable verification workflows should be established for international, manual, or high-value payments, with multiple approval levels or dual signatures. Payment requests should always be confirmed through a callback, ensuring that the usual contact is reached using the company's already known contact details. Information about how the company operates should also not be disclosed to external individuals. Above all, it is essential to regularly raise awareness among all employees in accounting, treasury, secretarial, and switchboard departments about this type of scam, so that they can recognize warning signs and make a habit of systematically informing their replacements in their positions.

The BlueSecure solution

BlueSecure offers a comprehensive CEO fraud awareness package: dedicated e-learning training, a knowledge assessment test, and phishing campaigns featuring CEO fraud templates via email, SMS, and telephone calls. By combining theory and practice, our offering enables you to raise awareness among all your employees of every risk they may encounter within your organization.

Contact us for further information:

CONTACT US

By

B

BlueSecure

Équipe BlueSecure

The BlueSecure team specializes in cybersecurity awareness training and employee security education. With over 10 years of experience, we help organizations protect their most valuable asset: their people.

Share this article