What is CEO Fraud (aka Colleague Impersonation)?

About this video

CEO Fraud is the term used to describe Threat Actors (aka Hackers!) impersonating your boss/CEO to increase the likelihood of your compliance with an unusual or high-value request.

Preying on the natural inclination to be helpful to your boss, CEO Fraud is often used as part of a targeted Spear Phishing campaign, aimed directly at people within the organization who are likely to authorise payments, such as the CFO, Accountant, or Accounts Payable Manager.


The video discusses;

  • Why CEO Fraud is so dangerous (and successful!)
  • Things you need to look for to help identify fraudulent emails from your CEO or other C-Suite / managers in your company
  • Gives an example of domain mimicking, a cheap and highly effective way for hackers to legitimately send email that may well get through your email security WITHOUT HACKING

We’ll then briefly discuss some of the solutions that can assist in protecting a company against CEO Fraud attacks.

SPOILER ALERT: There is a human element too – this isn’t a technical-only solution to this issue!


Take away actions on this topic are

  1. Implement & train your team to pay attention to security warnings
  2. Discuss phishing emails, what they look like, and how to avoid them as part of your larger Security Awareness Training program.
  3. Consider implementing routing phishing testing / training for your team (at least quarterly)
  4. Implement procurement processes and stick to them – ensure you have a no fault or blame culture as long as the procedures are adhered to.

