CEO-fraude herkennen.Bedrog met betalingen stoppen.Voordat er schade is.
Conbool MailGuard herkent vervalste identiteiten, aangepaste afzenders en de bekende patronen van fraude via e-mail. Vanzelf en op het moment zelf, voordat een valse opdracht uw mensen bereikt.
CEO fraud: spot it, classify it, stop it
CEO fraud causes losses in the billions worldwide, and it does not only hit large corporations. This page explains the scam, shows typical examples and warning signs, sets CEO fraud apart from CEO spoofing and describes why training alone is not enough.
In short
CEO fraud, also known as the fake president scam or business email compromise, is a scam in which attackers pose by email as company management, a board member or a supplier and demand an urgent transfer or the release of confidential data. The messages contain neither malware nor suspicious links, which is why conventional spam filters let them through. In German the scam is called Chef-Masche or CEO-Betrug.
The three biggest CEO fraud threats
CEO Impersonation
Attackers impersonate CEOs or executives and request urgent wire transfers or confidential information via email. The forged sender is often nearly indistinguishable from the real one.
Wire Transfer Fraud
Fraudulent payment instructions, often disguised as urgent and confidential requests. Average damage per BEC attack: over $120,000 according to FBI statistics.
Supplier Invoice Fraud
Attackers forge invoices from known suppliers or alter bank details in existing business relationships. Particularly dangerous because the emails appear in the context of real transactions.
Typical CEO Fraud examples from the field
Four attack patterns that hit European companies repeatedly — and where MailGuard intercepts them.
Foreign subsidiary ploy
An alleged email from the CEO to the German headquarters' finance team: confidential acquisition, urgent down payment to a Hong Kong account. The actual CEO is travelling, the reply-to address differs by a single character. Documented losses range from €1m to €8m.
Supplier vendor swap
A trusted supplier sends a notice that their bank details have changed, just before the next batch payment run. The sender domain is a cousin domain (e.g. supplier-ltd.com instead of supplier.com). Master data is updated — the next payment goes to the attacker.
M&A confidentiality
During an ongoing acquisition, the “board chair” asks finance for a discreet down payment to an external advisor. The confidentiality framing prevents a peer cross-check — exactly what attackers exploit.
Tax advisor / legal counsel scam
An email from a supposed tax advisor or lawyer demands a short-notice payment for an “administrative deadline”. The letterhead PDF looks authentic, the reply-to is silently routed to a free-mail account.
Warning signs: how to spot CEO Fraud
Eight indicators that reveal CEO fraud before a payment goes out. On its own none of them proves an attack, several together are a clear indication. MailGuard checks every email for these patterns automatically.
- Unusual urgency (“immediately”, “today”, “strictly confidential”)
- Instructions to bypass colleagues or the four-eyes principle
- Changed or new bank details inside an existing supplier relationship
- Reply-to address differs from the displayed sender address
- Sender domain with a small deviation (cousin or look-alike domain)
- Email outside business hours, or “sent from mobile”
- Impersonal greeting or unusual phrasing for that executive
- Attachment as alleged invoice, contract or agency letter with payment request
What to do after a CEO Fraud incident?
Five immediate steps for the first hours after a suspected or confirmed attack.
1. Contact your bank
Call your bank immediately and request recall of the wire (SWIFT recall). Reversal is most likely within the first 24–48 hours.
2. File a criminal complaint
Notify police (cybercrime liaison office) and, where applicable, the prosecutor. Preserve full email headers and original files for forensics.
3. Check NIS2 / regulator reporting duty
Essential and important entities under NIS2 have reporting obligations to the national CSIRT. Significant incidents: early warning within 24h, full notification within 72h.
4. Engage IT forensics
Inspect mail server logs, authentication events and the recipient's endpoints. Determine whether mailboxes are compromised or this was external spoofing.
5. Brief your staff
Clear internal communication: what attack ran, how it was recognisable, which procedures apply from now on. Without blame — otherwise future incidents go unreported.
CEO Fraud in numbers
Why technical protection is no longer optional.
How Conbool MailGuard stops CEO Fraud
Multiple layers of protection work together to reliably detect impersonation and fraudulent instructions.
Impersonation Detection
MailGuard detects when someone impersonates an internal executive. Display name spoofing, look-alike domains, and reply-to manipulation are automatically identified and blocked.
Behavioral Analysis
MailGuard analyzes communication patterns and detects deviations from normal email behavior. Unusual sender-recipient combinations and atypical requests are flagged immediately.
Explainable pattern recognition
MailGuard recognises the language of fraud: payment requests, urgency, secrecy, a changed bank account, extortion. Every hit is assembled from named signals and explained in plain words, instead of coming out of a model nobody can inspect.
Domain Similarity Check
MailGuard compares incoming sender domains with your internal and known supplier domains. Cousin domains and typosquatting are reliably detected.
Payment-Based Alerts
Emails containing payment instructions, account changes, or urgent transfer requests are automatically flagged with a warning or moved to quarantine.
Policy Enforcement
Define custom rules for sensitive communications. MailGuard enforces your security policies automatically, preventing fraudulent instructions from getting through.
Why awareness alone is not enough against CEO Fraud
CEO Fraud attacks are highly professional and targeted. Technical protection is indispensable.
Billions in damages worldwide
The FBI estimates global BEC damages at over $50 billion since 2013. A single successful attack can be existentially threatening to a business.
Targeted social engineering attacks
CEO Fraud emails contain no malware and no suspicious links. They rely on psychological pressure. Traditional spam filters and antivirus scanners cannot detect them.
Automated real-time detection
MailGuard checks every email for BEC indicators in milliseconds. No employee needs to decide under time pressure whether a payment instruction is genuine.
Compliance and audit requirements
GDPR and NIS2 require technical safeguards against identity fraud. MailGuard provides comprehensive audit logs and meets regulatory requirements.
FAQ
Was ist CEO Fraud?
Wie unterscheidet sich CEO Fraud von Phishing?
Wie erkennt MailGuard CEO Fraud?
Funktioniert der CEO-Fraud-Schutz mit Microsoft 365?
Was kostet ein erfolgreicher CEO-Fraud-Angriff?
Kann MailGuard auch Lieferanten-Rechnungsbetrug erkennen?
Was ist der Unterschied zwischen CEO Fraud und CEO Spoofing?
Wie kann ich CEO-Betrug im Unternehmen vorbeugen?
Stop CEO Fraud before it's too late.
Try Conbool MailGuard's CEO Fraud protection free for 30 days.