Business payment fraud (BEC) · Also called business email compromise, BEC, CEO scam, executive impersonation, fake boss email, urgent wire transfer scam
CEO fraud (executive impersonation)
CEO fraud is a business email compromise scam in which a criminal poses as the chief executive or another senior leader, using a hacked or look-alike email account, and tells a finance employee to make an urgent, confidential payment. The money goes to an account the criminal controls and may be moved on to other accounts.
How it works
- Criminals research the company to learn who handles payments, how approvals work, and when executives are travelling.
- They hack an executive's email account or send mail from an address made to look like it.
- The fake executive emails the employee who processes payments, asking for an urgent and confidential transfer, often at an unusual time.
- The employee sends the money to the criminal's account, from where it is moved on to other accounts, sometimes abroad or into cryptocurrency.
Red flags
- The request stresses secrecy or pressure to act immediately.
- The sender's address is slightly different from the real one, or the executive suddenly writes from a personal email account.
- The executive says they are in a meeting or cannot talk, so the payment must be arranged by email or chat.
- The payment is unusual in its timing, amount, recipient, or wording, such as an urgent wire transfer to a new account.
If you are targeted
- Stop: do not send the payment or any more money until it has been checked.
- Call your bank at once and ask it to recall the payment; the FBI also suggests asking for a Hold Harmless Letter or Letter of Indemnity.
- Call the executive on a number you already have, and tell your IT or security team so they can secure any compromised email account.
- Report it. Our Report a scam page lists where to report in your country, such as ic3.gov and ReportFraud.ftc.gov in the US.
Prevention
For individuals
- Confirm any payment request by calling the requester on a number you already know, never a number in the email.
- Check the full sender address before acting, especially on a phone where it may be hidden.
- Use Forward and type or pick the known address rather than hitting Reply, so your answer reaches the real person.
For organisations
- Require an out-of-band callback, on a number from your own records, before any significant or unusual payment is released.
- Require a second person to approve new payees and any change to payment details, so no single employee can send money on an email alone.
- Turn on multi-factor authentication for company email and flag incoming mail from domains that look like your own.
- Limit what you publish about finance staff, reporting lines, and executives' travel and out-of-office dates.
Step-by-step controls: the implementation guide
By the numbers
Figures are for the reporting category this scam falls under, not this scam alone.
| Business email compromise losses reported to the FBI IC3 in 2025 | $3.05B | US, 2025, FBI IC3 |
Real cases
2015-06 · US · Disclosed · $46.7M stolen
Ubiquiti Networks loses $46.7 million to employee impersonation fraud, 2015
Delivered through: Spear phishing, Email phishing
How official datasets classify it
- FBI IC3
- Business Email Compromise
- UK Finance
- CEO fraud
- Scamwatch
- Business email compromise scams
- MITRE ATT&CK
- T1684.001, T1657
Questions
- What is CEO fraud?
- It is a type of business email compromise in which a criminal poses as a senior executive, by email or message, to get an employee to send an urgent payment to the criminal's account.
- Can a company get its money back after CEO fraud?
- Sometimes, if it acts fast. Ask your bank to recall the payment straight away and file a complaint at ic3.gov, because the FBI may be able to help banks freeze the funds.
Related scams
- Executive gift card request scam
- Deepfake CFO video call fraud
- Deepfake CEO voice and messaging fraud
- Vendor invoice and payment redirection