A Single Email Cost This Company $37 Million
In 2016, FACC, an Austrian aerospace parts manufacturer, lost €42 million (roughly $47 million at the time) after attackers impersonated the CEO and convinced a finance employee to wire funds to accounts controlled by threat actors. The employee believed they were following direct orders from the top. That's the anatomy of a CEO fraud email scam — and it's still one of the most devastating attack vectors in 2026.
The FBI's Internet Crime Complaint Center (IC3) has tracked Business Email Compromise (BEC) — the broader category that includes CEO fraud — as the single highest-dollar cybercrime category for years running. Their IC3 annual reports consistently show BEC losses dwarfing ransomware, credential theft, and every other category combined. In 2023 alone, BEC accounted for over $2.9 billion in reported losses.
I've worked incident response on these cases. What strikes me every time is how simple the attack is — and how preventable it could have been.
What Exactly Is a CEO Fraud Email Scam?
A CEO fraud email scam is a type of social engineering attack where a threat actor impersonates a company executive — typically the CEO, CFO, or another senior leader — to trick an employee into transferring money, sharing sensitive data, or taking another high-risk action. The attacker doesn't need to hack a single system. They just need to craft a convincing email.
These attacks usually target employees in finance, accounting, or HR. The emails are urgent, authoritative, and designed to bypass your normal decision-making process. "I need you to process this wire transfer before end of business. Don't discuss this with anyone — it's confidential." Sound familiar?
The term "CEO fraud" is sometimes used interchangeably with BEC, but it specifically refers to the executive impersonation variant. Other BEC flavors include vendor email compromise and attorney impersonation, but CEO fraud remains the most common and the most costly.
How Attackers Set the Trap
Reconnaissance: They Know Your Org Chart
Before sending a single email, attackers do their homework. They scrape LinkedIn for employee names, titles, and reporting relationships. They study your company website, press releases, and SEC filings if you're public. They know when your CEO is traveling — sometimes from social media posts your executives share themselves.
I've seen cases where threat actors monitored a CEO's calendar for weeks, timing their fraudulent wire transfer request to coincide with the executive being on an international flight and unreachable by phone.
The Spoofed or Compromised Email
Attackers typically go one of two routes. The first is email spoofing — forging the "From" field so the message appears to come from the CEO's actual email address. The second, and more dangerous, is actual account compromise. If they've stolen the CEO's credentials through a phishing attack or credential stuffing, they're sending from the real account. No spoofing detection will catch that.
This is one reason multi-factor authentication on every executive email account isn't optional — it's survival-critical.
The Ask: Urgent, Confidential, Financial
The fraudulent email almost always shares three traits. It creates urgency ("this must happen today"). It demands secrecy ("don't loop anyone else in yet"). And it involves money or sensitive data. Wire transfers to new accounts, changes to vendor payment details, bulk W-2 requests — these are the classic plays.
The $4.88M Lesson Most Organizations Learn Too Late
According to IBM's Cost of a Data Breach Report, the global average cost of a data breach reached $4.88 million in 2024. But CEO fraud losses can vastly exceed that number in a single incident — because the money leaves your organization voluntarily.
Unlike ransomware, there's no encryption to reverse. Unlike a data breach, there's no system to restore from backup. Once a wire transfer clears to an overseas account, your money is gone. Recovery rates for BEC wire fraud are dismal unless you catch it within 24-48 hours and your bank initiates a recall through the FBI's Recovery Asset Team.
The reputational damage compounds the financial hit. When Ubiquiti Networks lost $46.7 million to a BEC scam in 2015, it wasn't just the money — it was the public disclosure, the shareholder lawsuits, and the C-suite shakeup that followed.
Why Traditional Email Security Fails Against CEO Fraud
Your spam filter won't save you here. Most CEO fraud email scam messages contain no malware, no malicious links, and no attachments. They're plain text. They pass SPF, DKIM, and DMARC checks if sent from a lookalike domain or a compromised legitimate account.
This is a human-targeting attack, not a technology-targeting attack. The vulnerability isn't in your email gateway — it's in the trust relationship between an employee and their boss.
That's why organizations adopting a zero trust mindset extend it beyond network architecture to business processes. Never trust a financial request based solely on an email, regardless of who appears to have sent it.
Seven Defenses That Actually Work
1. Out-of-Band Verification for All Financial Requests
Any email requesting a wire transfer, payment change, or sensitive data export must be verified through a separate communication channel. Call the executive directly using a known phone number — not one provided in the email. This single control stops the majority of CEO fraud attempts.
2. Mandatory Dual Authorization for Wire Transfers
No single employee should have the authority to initiate and approve a wire transfer alone. Require two-person authorization for any transaction above a defined threshold.
3. Multi-Factor Authentication on Every Account
Especially executive accounts. If an attacker can't compromise the CEO's actual mailbox, they're forced to spoof — and spoofing is far easier to detect with proper email authentication protocols.
4. DMARC Enforcement at "Reject"
Implement DMARC, SPF, and DKIM — and set your DMARC policy to "reject," not just "monitor." CISA's Binding Operational Directive 18-01 mandated this for federal agencies years ago. Your organization should follow the same standard.
5. Realistic Phishing Simulations
Run regular phishing simulation campaigns that include BEC scenarios — not just the obvious "click this link" tests. Simulate an executive requesting a wire transfer and measure how employees respond. Our phishing awareness training for organizations includes exactly these kinds of real-world BEC simulations.
6. Security Awareness Training That Covers Social Engineering
Your employees need to understand how social engineering works at a psychological level — authority, urgency, scarcity, secrecy. A well-trained employee who pauses and thinks "this feels off" is your last and often best line of defense. Enroll your team in cybersecurity awareness training that covers BEC, pretexting, and executive impersonation scenarios.
7. Flag External Emails Clearly
Configure your email system to prepend a visible banner on all messages originating from outside your domain. Something like: "CAUTION: This email originated from outside your organization." It's a small friction that triggers a critical pause.
How Do You Spot a CEO Fraud Email?
Here are the red flags your team should know cold:
- Unusual urgency: "Handle this immediately" or "before end of business today."
- Secrecy demands: "Keep this between us" or "don't mention this to anyone yet."
- New payment instructions: Any request to wire funds to an unfamiliar account or change existing vendor banking details.
- Slight email address variations: Look for [email protected] instead of [email protected]. One hyphen can cost millions.
- Unusual tone or grammar: If your CEO never writes "Dear" and the email starts with "Dear John," that's a signal.
- Replies go to a different address: The "From" might look right, but the "Reply-To" routes to an attacker-controlled mailbox.
CEO Fraud Isn't Slowing Down — It's Evolving
Threat actors are now using AI-generated voice deepfakes to supplement CEO fraud email scam campaigns. In a widely reported 2019 case, criminals used AI voice technology to impersonate a CEO's voice on the phone, convincing a UK energy company executive to transfer €220,000. That was 2019. The technology has only gotten more accessible and convincing since.
In 2026, we're seeing attackers combine compromised email accounts with deepfake voice calls and even video. The email lands first to prime the target. Then a phone call "from the CEO" confirms the request. The combination is devastatingly effective against organizations that haven't trained their people.
The NIST Cybersecurity Framework emphasizes that people, processes, and technology must work together. No single control is sufficient. Your defense against CEO fraud needs all three layers working in concert.
Your Move
Every organization is a target for CEO fraud. It doesn't matter if you have 20 employees or 20,000. Attackers target the trust between people — and every company has that.
Start with the basics: implement out-of-band verification for financial requests, enforce multi-factor authentication across your organization, and invest in security awareness training that goes beyond checkbox compliance. Your people are the target — make them the strongest link in your defense.