2. Common frauds against organisations
CEO fraud and business email compromise
Business email compromise (BEC) is a family of frauds built on impersonating people through email, either by taking over a genuine mailbox or by spoofing one convincingly. Invoice and mandate fraud, covered in the previous lesson, is one branch. CEO fraud is another.
CEO fraud
In CEO fraud, the fraudster impersonates a senior person in your own organisation, typically the chief executive or finance director, and instructs a member of staff to make an urgent payment or buy something on the company's behalf. The message is engineered to make the recipient act before they think.
Typical features include:
- Urgency: the payment must go today, a deal depends on it
- Secrecy: keep this confidential, don't discuss it with anyone else
- Authority: the request comes from someone you would not normally question
- A reason the sender can't talk: in a meeting, boarding a flight, abroad
- A request to bypass the normal payment process just this once
Variants include requests to buy gift cards and send the codes, or to change the bank account that a senior person's salary is paid into.
Why it works
CEO fraud exploits normal workplace behaviour. Most people want to be helpful, respond quickly to senior colleagues, and feel awkward challenging authority. Fraudsters know this, and they often time their messages for late Friday afternoon or holiday periods, when the impersonated person is genuinely hard to reach and checks are more likely to be skipped.
The defence
No genuine senior manager will object to a payment being verified. Your protection is process, not suspicion of individuals: unusual or urgent payment requests get confirmed with the requester through a different channel, such as a phone call to their known number or a face to face word, before anything is paid. If a message asks you to keep a payment secret from colleagues or to skip a control, treat that instruction itself as the biggest red flag in the message.
› Course contents
What fraud is and the law
Common frauds against organisations
Internal fraud and red flags
Prevention and reporting
Putting it into practice