The fake CEO scam

The fake CEO scam ranks among the most used methods against companies. According to the Allianz Trade 2021 fraud study, a quarter of companies suffer a confirmed fraud and two thirds face at least one attempt.
An old technique, moved online
Fake executive and bank-detail-change scams have claimed many victims among French companies. The amounts run into millions of euros, and the effect on the people involved lasts. The French state documents the pattern under the name fraudulent transfer order.
Criminals kept the impersonation technique and changed their tooling. They spoof email addresses and phone numbers, imitate the voice, and now the video. They research the company, which makes their story credible.
The target is a person, not a system
The attack is prepared long in advance and rests on a plausible scenario. Every psychological lever is used to get an accountant to move funds under time pressure. It almost always comes with a compromised mailbox, which supplies the vocabulary and the context.
This is a different order of magnitude from mass phishing: cybersecurity professionals get caught by it.
What the agencies recommend
The official recommendations come down to a few points:
- limit what the company publishes about how it operates, including on social networks;
- train accounting, treasury, secretarial and switchboard staff regularly;
- brief anyone standing in for those roles;
- put multiple verification and signature steps in place for international payments;
- break the email chain by typing the requester’s usual address yourself;
- keep the information system up to date.
Two thousand three hundred complaints were filed over five years in France, and many companies never reported the attack in order to protect their reputation.
These measures remain necessary. They rest, however, on constant human discipline, which an organisation sustains neither over holidays, nor under pressure, nor after someone changes role.
Let the process carry the verification
Sealfie moves the control point from individual judgement to the process. When a sensitive order is initiated, the real requester is prompted on their own phone: photo, device biometrics, automatic checks. A second authorised person confirms. Verifications available from other systems are collected along the way.
The application tells people what to do, including when they suspect something. The accountant stops being the last line of defence, and no longer has to choose between risking a fraud and looking obstructive.
What the technology does
The approach makes legitimate people’s transactions verifiable, rather than trying to recognise every form of impersonation. Verifications from the various systems are encrypted, sealed and linked together on an open chain. You can then check which systems signed, which produces a bundle too costly to forge as a whole.
Measure your exposure
The BEC risk calculator estimates your company’s annual incident probability and expected loss in six questions. Published methodology, and no data leaves your browser.