Cybersecurity, explained for the rest of us.

Phishing & Scams

CEO Fraud Explained: How Wire Transfer Scams Work and Why They Succeed

Margot 'Magic' Thorne@magicthorneSeptember 9, 202612 min read
Empty executive office with laptop showing urgent email, wire transfer form on desk, phone displaying CEO contact

An email lands in your inbox Tuesday afternoon. It's from the CEO. Subject line: "Urgent , Confidential Acquisition."

The message is short. You're handling a time-sensitive wire transfer for a deal that hasn't been announced yet. Legal needs the payment processed today. The CEO is in meetings all afternoon, can't be reached by phone, but trusts you to handle this. Wire instructions attached. Keep it quiet.

You've never received a request like this before. But the email address looks right. The tone matches. And you've seen the CEO's name in the news lately about expansion plans. The urgency feels real.

You open the wire transfer form. The amount is significant but not outrageous for your company. The receiving bank is overseas, but that's normal for international deals. You have signing authority. The CEO is counting on you.

You click send.

Three hours later, your actual CEO walks past your desk and asks how your day is going. You mention the wire transfer. She has no idea what you're talking about.

The money is gone.

This is CEO fraud. Also called business email compromise (BEC), it's the most financially damaging form of cybercrime targeting organizations in 2026. The FBI's Internet Crime Complaint Center reports losses from BEC exceeded $2.9 billion in 2024, up from $2.7 billion the previous year. Average loss per incident: around $125,000. Some single incidents drain millions.

CEO fraud works because it doesn't rely on technical exploits. There's no malware to detect, no suspicious link to block. The attack is pure social engineering: impersonation, urgency, and authority. The attacker manipulates human decision-making, not software vulnerabilities. And when it works, the money transfers directly from your account to theirs, often crossing international borders within minutes.

Here's how the attack actually works, why it succeeds, and what breaks the mechanism.

The Underlying Mechanism: Research, Impersonation, Urgency

CEO fraud is a multi-stage attack. The technical component is minimal. The psychological component is everything.

Stage 1: Reconnaissance. The attacker researches your organization before sending a single email. They study your company website to learn executive names and titles. They browse LinkedIn to map reporting structures, who reports to whom, who works in finance, who has authority to approve payments. They read press releases to understand current projects, acquisitions, expansions. They may scan leaked credentials from previous breaches to see if any executives reuse passwords, giving the attacker access to real email accounts.

The goal is to build a plausible narrative. The attacker needs to know enough to impersonate an executive convincingly and to identify the right target: someone with payment authority who will recognize the executive's name but may not interact with them daily.

Stage 2: Impersonation. The attacker sends an email that appears to come from an executive. There are three common methods:

  • Spoofed sender address. The attacker forges the "From" field to display the executive's real email address. Email protocols allow this. The message doesn't actually originate from the executive's account, but the recipient sees the familiar address in their inbox. Many email clients display only the name, not the full address, making spoofing easier to miss.

  • Look-alike domain. The attacker registers a domain that's one character off from your company's real domain: company.co instead of company.com, or cornpany.com with an r and n that look like an m in some fonts. The email comes from ceo@cornpany.com. If you don't scrutinize the address, it passes.

  • Compromised account. The attacker gains access to the executive's actual email account through credential stuffing, phishing, or password reuse. Messages sent from the real account bypass all impersonation detection because they are, technically, legitimate. This is the most dangerous variant.

The FTC reports that impersonation scams, including CEO fraud, have increased more than fourfold in recent years, with median losses in the tens of thousands of dollars per incident.

Stage 3: The Request. The email creates urgency, confidentiality, and authority. Common narratives:

  • Confidential acquisition in progress; payment needed today to close the deal.
  • Vendor payment overdue; CEO is traveling and needs you to handle it.
  • Legal settlement requiring immediate wire transfer to avoid litigation.
  • Regulatory penalty that must be paid by end of business.

The request often includes reasons you can't verify it through normal channels: the CEO is in meetings all day, the matter is confidential and can't be discussed with colleagues, the deadline is in hours. The attacker is preempting the verification step that would expose the fraud.

The email may reference real projects, real vendors, or real executives by name, details gathered during reconnaissance. This specificity makes the request feel legitimate.

Stage 4: Wire Transfer. The attacker provides wire instructions: account number, routing number, receiving bank. The destination is often an overseas account, sometimes laundered through multiple intermediaries. Once you initiate the transfer, the money moves quickly. Wire transfers are designed to be fast and irreversible. By the time you realize the fraud, the funds have cleared, been withdrawn, and disappeared into a network of accounts that obscure the trail.

The FBI's Internet Crime Complaint Center categorizes CEO fraud under business email compromise and notes that it remains one of the most financially damaging cybercrimes, with losses consistently in the billions annually.

Why CEO Fraud Succeeds

CEO fraud exploits predictable human responses to authority, urgency, and secrecy.

Authority. When the CEO asks you to do something, you do it. Organizational hierarchies train employees to defer to executives. Questioning a direct request from senior leadership feels insubordinate. The attacker leverages that dynamic. The email doesn't just ask, it instructs. And the instruction comes from someone whose authority you're conditioned not to challenge.

Urgency. The request always includes a tight deadline. "I need this done by end of day." "The deal closes in two hours." Urgency compresses decision-making time. It creates pressure to act before you can think, verify, or consult. The attacker knows that if you pause to check, the fraud collapses. Urgency prevents the pause.

Confidentiality. The email emphasizes secrecy. "Don't discuss this with anyone." "This is highly confidential." Confidentiality isolates you from colleagues who might spot the fraud. It prevents you from asking, "Did anyone else get this?" or "Does this seem right?" The attacker wants you alone with the decision.

Plausibility. The narrative fits your role. If you work in finance, the request involves a payment. If you work in HR, it involves employee data. The attacker tailors the scam to your responsibilities, making the request feel like something you would normally handle, just under unusual circumstances.

Lack of technical red flags. CEO fraud emails often contain no malicious links, no attachments, no executable files. They're plain text requests. Email security systems designed to catch malware, phishing links, or suspicious attachments see nothing wrong. The message passes through filters because, technically, it's just an email.

In Gilmore Girls, Lorelai Gilmore moves through Stars Hollow with an ease born from knowing everyone and trusting that familiarity. When someone she trusts asks for help, she doesn't hesitate, she acts. CEO fraud works the same way. The attacker borrows the trust you've built with your executives and uses it to bypass skepticism. You act because the request comes from someone whose authority you respect, in a context that feels familiar, under conditions that discourage verification.

The FTC's consumer guidance on imposter scams emphasizes that these attacks succeed because they mimic trusted relationships and create urgency that short-circuits normal verification processes.

What Makes CEO Fraud Different From Other Phishing

Standard phishing tries to steal your credentials by tricking you into clicking a malicious link or entering your password on a fake site. CEO fraud doesn't need your credentials. It needs your compliance.

The attacker isn't trying to break into your account. They're trying to get you to authorize a legitimate transaction using your real access. The wire transfer goes through normal banking channels, initiated by you, using your login, your authority, your approval. From the bank's perspective, it's a valid transaction. You requested it. You authorized it. The fraud is invisible to the technical systems designed to detect unauthorized access because the access is authorized, by you, under false pretenses.

This is why CEO fraud bypasses most technical defenses. Antivirus software doesn't help. Email filters struggle. Two-factor authentication protects your account but doesn't stop you from authorizing a fraudulent payment once you're logged in. The attack happens in the decision layer, not the access layer.

The Wire Transfer Problem

Wire transfers are fast, irreversible, and difficult to trace across borders. That's why attackers prefer them.

When you initiate a wire transfer, the funds move through the banking system in hours or less. The receiving bank credits the destination account. The recipient, or an intermediary working for the attacker, withdraws the money, often immediately. By the time you realize the fraud and contact your bank, the funds are gone.

Some victims catch the fraud within hours and manage to contact both their bank and the receiving bank before the money is withdrawn. In rare cases, this results in a clawback. But the window is narrow, and success depends on speed, cooperation between banks, and whether the destination account still holds the funds. Most victims lose the full amount.

The FBI's guidance on BEC recommends immediate contact with your bank and the FBI if you realize you've been defrauded, but recovery remains unlikely in most cases.

International wire transfers complicate recovery further. If the destination account is overseas, you're dealing with foreign banking regulations, different legal systems, and jurisdictions that may not cooperate with U.S. law enforcement. Attackers know this. They route payments through countries with weak fraud enforcement and banking secrecy laws.

Variants: Vendor Fraud and Attorney Impersonation

CEO fraud is one variant of business email compromise. The same mechanism applies to other impersonation targets.

Vendor fraud. The attacker impersonates a vendor your company works with regularly. An email arrives: "We've updated our payment information. Please use the new account details for all future invoices." The email looks like it came from your vendor's accounting department. You update the records. The next payment goes to the attacker's account instead of the real vendor. The real vendor contacts you weeks later asking why they haven't been paid. By then, multiple payments may have gone to the wrong account.

Attorney impersonation. The attacker impersonates outside legal counsel. The email claims a settlement requires immediate payment to avoid court action. The request includes urgency (filing deadline today), confidentiality (settlement terms are under NDA), and authority (your attorney is instructing you). You wire the funds. The real attorney never sent the email.

Both variants use the same playbook: research, impersonation, urgency, and a request that bypasses normal verification because the situation is framed as exceptional.

What Breaks the Attack

CEO fraud collapses when you verify the request through a separate communication channel.

The attacker controls one channel: email. If you respond to the email, you're talking to the attacker. If you call the phone number provided in the email, you're calling the attacker. The fraud depends on keeping you inside that single channel.

Verification breaks the channel. You receive the email. You don't reply. Instead, you call the CEO using the number in your company directory, not the number in the email. You ask, "Did you send me a wire transfer request?" The CEO says no. The fraud is exposed.

This is the single most effective defense, and it's the step attackers work hardest to prevent. That's why the email says the CEO is in meetings all day, traveling overseas, or unavailable. The attacker is preempting your attempt to verify.

Organizations that require verbal confirmation for unusual payment requests, using known contact information, not information provided in the request, stop CEO fraud cold. The policy doesn't need to be complex. It's a single rule: any wire transfer request that deviates from normal procedure requires a phone call to confirm. Use a number from your contacts or the company directory. Not the email.

The CISA guidance on phishing emphasizes verification as a core defense: if a request feels unusual, confirm it through a separate channel before acting.

Why Email Filters Struggle

Email security systems are designed to catch malicious content: links to phishing sites, attachments with malware, executable files disguised as PDFs. CEO fraud emails contain none of that. They're plain text. No links. No attachments. Just a message asking you to initiate a wire transfer.

Some advanced filters attempt to detect impersonation by analyzing sender behavior: does this email come from the CEO's usual IP address? Does the writing style match previous messages? Is the domain spoofed? These heuristics catch some CEO fraud, but they're not foolproof. If the attacker has compromised the CEO's actual account, the email originates from the legitimate address, sent from the CEO's device, using the CEO's credentials. The filter sees a legitimate message from a legitimate account.

Filters also struggle with look-alike domains. A one-character difference in a domain name is easy for humans to miss and difficult for automated systems to flag without generating excessive false positives. If the filter blocks every email from a domain that's similar to a known domain, it will block legitimate messages from partners, vendors, and subsidiaries with similar names.

The technical problem is that CEO fraud doesn't exploit technical vulnerabilities. It exploits trust, authority, and urgency, human factors that email filters can't parse.

What You Can Do

If you handle payments, manage finances, or have authority to approve wire transfers, these steps reduce your exposure to CEO fraud:

Establish a verification policy. Any payment request that deviates from normal procedure, unusual amount, unfamiliar recipient, tight deadline, confidentiality requirement, requires verbal confirmation using a known phone number. This is non-negotiable. Document the policy. Train employees. Enforce it.

Scrutinize email addresses. Don't rely on the display name. Check the actual email address. Look for look-alike domains, extra characters, or domains that don't match your company's domain. Hover over the sender's name to reveal the full address. If anything looks off, stop.

Question urgency. Legitimate business transactions rarely require same-day wire transfers with no opportunity for verification. If the request creates artificial urgency, "I need this done in the next two hours", that's a red flag. Slow down. Verify.

Limit public information. Attackers use LinkedIn, company websites, and press releases to research targets. You can't eliminate your public presence, but you can limit unnecessary detail. Do employees need to list their full job titles and reporting structures on LinkedIn? Does your website need to publish detailed org charts? The less information available, the harder reconnaissance becomes.

Use multi-person approval for large transfers. Require two people to authorize wire transfers above a certain threshold. This creates a second verification point. If one person is fooled, the second may catch it.

Report the fraud immediately. If you realize you've been defrauded, contact your bank within minutes, not hours. Contact the receiving bank if you have that information. File a report with the FBI's Internet Crime Complaint Center at ic3.gov. Speed matters. The faster you act, the higher the chance (though still low) of recovering funds.

The FBI's IC3 reporting platform is the central hub for reporting BEC and other cybercrimes. Reports feed into investigations and help law enforcement track trends.

Educate employees. CEO fraud succeeds because employees don't know what to look for. Regular training, real examples, clear policies, practiced verification steps, reduces susceptibility. Employees need to know that questioning an unusual request from an executive is not only acceptable but required.

The Recovery Problem

Once the money is gone, recovery is unlikely. Wire transfers are designed to be fast and final. That's their purpose. Reversing them requires cooperation from multiple banks, quick action, and luck.

Some victims recover partial amounts through insurance. Cyber insurance policies sometimes cover social engineering fraud, but coverage varies. Policies may exclude losses if the organization didn't follow basic security practices, like requiring verification for wire transfers. Read your policy. Understand what's covered. Don't assume.

The Consumer Financial Protection Bureau handles complaints about financial institutions, but their authority is limited in cases of authorized transactions. You authorized the wire transfer. The bank processed it correctly. The fraud happened before the transaction, not during it.

Legal action against the attacker is theoretically possible but practically difficult. The attacker is often overseas, operating under a pseudonym, using laundered accounts that obscure identity. Prosecution requires international cooperation, and even successful prosecution doesn't guarantee restitution.

Prevention is the only reliable defense. Once the fraud succeeds, the money is effectively gone.

Why This Keeps Working

CEO fraud has been documented for over a decade. The FBI publishes annual reports showing billions in losses. Organizations know about the threat. Security training covers it. And yet it keeps working.

It works because the attack adapts faster than defenses. Attackers refine their research methods. They learn which narratives work best. They study failed attempts and adjust. The attack evolves in real time, driven by direct feedback from victims and near-victims.

It works because humans are predictable. Authority, urgency, and confidentiality trigger reliable responses. You can train people to recognize these triggers, but training competes with years of organizational conditioning that teaches employees to defer to executives and act quickly when asked.

It works because the financial incentive is enormous. A single successful CEO fraud attack can net hundreds of thousands or millions of dollars. The attacker's investment is minimal: time spent on research, a spoofed email, wire instructions. The return on investment is staggering compared to other forms of cybercrime.

And it works because the attack surface is every employee with payment authority. You can't eliminate that surface without eliminating the ability to do business. Someone has to be able to authorize payments. That someone is the target.

What Organizations Miss

Many organizations focus on technical defenses, email filters, endpoint protection, network monitoring, and underinvest in human defenses. CEO fraud doesn't care about your firewall. It doesn't exploit software vulnerabilities. It exploits trust.

The most effective defense is a culture where employees feel empowered to question unusual requests, even from executives. That culture is hard to build. It requires explicit permission to verify, clear policies that protect employees who push back on urgency, and leadership that models verification behavior instead of punishing caution.

Some organizations implement code words: a shared phrase that executives include in legitimate urgent requests. If the email doesn't contain the code word, it's not real. This works if everyone remembers the code word and if it's not compromised. But it's a band-aid. The real fix is verification through a separate channel.

The Broader Pattern

CEO fraud is part of a larger category: impersonation scams. The FTC's data on imposter scams shows that impersonation has become the dominant fraud vector across consumer and business contexts. Attackers impersonate government agencies, tech support, family members, romantic partners, and executives. The mechanism is the same: borrow trust from a known entity, create urgency, request action before verification.

CEO fraud is the business-facing variant. It's more profitable than consumer scams because the amounts are larger and the targets have direct access to corporate funds. But the psychology is identical.

Understanding CEO fraud means understanding how attackers weaponize trust. The email doesn't need to be sophisticated. It needs to be plausible enough to trigger action before skepticism kicks in. That threshold is lower than most people think.


CEO fraud works because it's simple. An email. A request. A wire transfer. No malware, no hacking, no technical exploit. Just impersonation, urgency, and a bet that you'll act before you verify.

The defense is equally simple: verify through a separate channel. Call the person using a known number. Ask if they sent the request. If they didn't, you've stopped the fraud. If they did, you've confirmed a legitimate transaction.

The hard part isn't the defense. The hard part is remembering to use it when the email feels urgent, the request feels plausible, and the CEO is counting on you.

Finance employee reviewing email verification checklist, phone in hand, paused before clicking send on wire transfer
→ Filed under
phishingsocial engineeringwire fraudbusiness email compromiseimpersonation scams
ShareXLinkedInFacebook

Frequently asked questions

CEO fraud is a social engineering attack where scammers impersonate executives to trick employees into wiring money or sharing sensitive data. The attacker uses urgency, authority, and often spoofed email addresses to bypass normal approval processes.
Attackers research companies through LinkedIn, corporate websites, and public records to identify executives, finance staff, and reporting structures. They learn names, titles, communication styles, and who has authority to approve wire transfers.
CEO fraud emails often contain no malicious links or attachments—just text requesting a wire transfer. Filters designed to catch malware miss social engineering that relies entirely on impersonation and psychological manipulation.
Recovery is difficult. Wire transfers are designed to be irreversible. If you catch the fraud within hours and contact your bank immediately, there's a slim chance of clawback, but most victims lose the full amount.
Require verbal confirmation for any unusual payment request, using a known phone number from your contacts—not one provided in the email. This breaks the attacker's ability to maintain the impersonation.

You might also like