Bescherming tegen CEO-fraude

CEO-fraude herkennen.Bedrog met betalingen stoppen.Voordat er schade is.

Conbool MailGuard herkent vervalste identiteiten, aangepaste afzenders en de bekende patronen van fraude via e-mail. Vanzelf en op het moment zelf, voordat een valse opdracht uw mensen bereikt.

CEO fraud: spot it, classify it, stop it

CEO fraud causes losses in the billions worldwide, and it does not only hit large corporations. This page explains the scam, shows typical examples and warning signs, sets CEO fraud apart from CEO spoofing and describes why training alone is not enough.

In short

CEO fraud, also known as the fake president scam or business email compromise, is a scam in which attackers pose by email as company management, a board member or a supplier and demand an urgent transfer or the release of confidential data. The messages contain neither malware nor suspicious links, which is why conventional spam filters let them through. In German the scam is called Chef-Masche or CEO-Betrug.

The three biggest CEO fraud threats

CEO Impersonation

Attackers impersonate CEOs or executives and request urgent wire transfers or confidential information via email. The forged sender is often nearly indistinguishable from the real one.

Wire Transfer Fraud

Fraudulent payment instructions, often disguised as urgent and confidential requests. Average damage per BEC attack: over $120,000 according to FBI statistics.

Supplier Invoice Fraud

Attackers forge invoices from known suppliers or alter bank details in existing business relationships. Particularly dangerous because the emails appear in the context of real transactions.

Typical CEO Fraud examples from the field

Four attack patterns that hit European companies repeatedly — and where MailGuard intercepts them.

Foreign subsidiary ploy

An alleged email from the CEO to the German headquarters' finance team: confidential acquisition, urgent down payment to a Hong Kong account. The actual CEO is travelling, the reply-to address differs by a single character. Documented losses range from €1m to €8m.

Supplier vendor swap

A trusted supplier sends a notice that their bank details have changed, just before the next batch payment run. The sender domain is a cousin domain (e.g. supplier-ltd.com instead of supplier.com). Master data is updated — the next payment goes to the attacker.

M&A confidentiality

During an ongoing acquisition, the “board chair” asks finance for a discreet down payment to an external advisor. The confidentiality framing prevents a peer cross-check — exactly what attackers exploit.

Tax advisor / legal counsel scam

An email from a supposed tax advisor or lawyer demands a short-notice payment for an “administrative deadline”. The letterhead PDF looks authentic, the reply-to is silently routed to a free-mail account.

Warning signs: how to spot CEO Fraud

Eight indicators that reveal CEO fraud before a payment goes out. On its own none of them proves an attack, several together are a clear indication. MailGuard checks every email for these patterns automatically.

  • Unusual urgency (“immediately”, “today”, “strictly confidential”)
  • Instructions to bypass colleagues or the four-eyes principle
  • Changed or new bank details inside an existing supplier relationship
  • Reply-to address differs from the displayed sender address
  • Sender domain with a small deviation (cousin or look-alike domain)
  • Email outside business hours, or “sent from mobile”
  • Impersonal greeting or unusual phrasing for that executive
  • Attachment as alleged invoice, contract or agency letter with payment request

What to do after a CEO Fraud incident?

Five immediate steps for the first hours after a suspected or confirmed attack.

1. Contact your bank

Call your bank immediately and request recall of the wire (SWIFT recall). Reversal is most likely within the first 24–48 hours.

2. File a criminal complaint

Notify police (cybercrime liaison office) and, where applicable, the prosecutor. Preserve full email headers and original files for forensics.

3. Check NIS2 / regulator reporting duty

Essential and important entities under NIS2 have reporting obligations to the national CSIRT. Significant incidents: early warning within 24h, full notification within 72h.

4. Engage IT forensics

Inspect mail server logs, authentication events and the recipient's endpoints. Determine whether mailboxes are compromised or this was external spoofing.

5. Brief your staff

Clear internal communication: what attack ran, how it was recognisable, which procedures apply from now on. Without blame — otherwise future incidents go unreported.

CEO Fraud in numbers

Why technical protection is no longer optional.

$50bn+
global BEC losses since 2013 according to FBI IC3 reports
$120,000
average loss per successful BEC attack
Million-euro losses
documented multiple times in Germany (e.g. Leoni €40m, FACC €50m)

How Conbool MailGuard stops CEO Fraud

Multiple layers of protection work together to reliably detect impersonation and fraudulent instructions.

Impersonation Detection

MailGuard detects when someone impersonates an internal executive. Display name spoofing, look-alike domains, and reply-to manipulation are automatically identified and blocked.

Behavioral Analysis

MailGuard analyzes communication patterns and detects deviations from normal email behavior. Unusual sender-recipient combinations and atypical requests are flagged immediately.

Explainable pattern recognition

MailGuard recognises the language of fraud: payment requests, urgency, secrecy, a changed bank account, extortion. Every hit is assembled from named signals and explained in plain words, instead of coming out of a model nobody can inspect.

Domain Similarity Check

MailGuard compares incoming sender domains with your internal and known supplier domains. Cousin domains and typosquatting are reliably detected.

Payment-Based Alerts

Emails containing payment instructions, account changes, or urgent transfer requests are automatically flagged with a warning or moved to quarantine.

Policy Enforcement

Define custom rules for sensitive communications. MailGuard enforces your security policies automatically, preventing fraudulent instructions from getting through.

Why awareness alone is not enough against CEO Fraud

CEO Fraud attacks are highly professional and targeted. Technical protection is indispensable.

Billions in damages worldwide

The FBI estimates global BEC damages at over $50 billion since 2013. A single successful attack can be existentially threatening to a business.

Targeted social engineering attacks

CEO Fraud emails contain no malware and no suspicious links. They rely on psychological pressure. Traditional spam filters and antivirus scanners cannot detect them.

Automated real-time detection

MailGuard checks every email for BEC indicators in milliseconds. No employee needs to decide under time pressure whether a payment instruction is genuine.

Compliance and audit requirements

GDPR and NIS2 require technical safeguards against identity fraud. MailGuard provides comprehensive audit logs and meets regulatory requirements.

FAQ

Was ist CEO Fraud?
CEO Fraud (auch Business Email Compromise oder Geschäftsführer-Betrug) ist eine Betrugsmasche, bei der Angreifer sich per E-Mail als Geschäftsführung, Vorstand oder andere autorisierte Personen ausgeben. Ziel ist es, Mitarbeiter zu Überweisungen oder zur Herausgabe vertraulicher Daten zu bewegen.
Wie unterscheidet sich CEO Fraud von Phishing?
Phishing zielt auf Zugangsdaten oder Malware-Installation ab und verwendet oft gefälschte Links oder Anhänge. CEO Fraud setzt dagegen auf Social Engineering ohne technische Angriffsvektoren. Die E-Mails enthalten oft weder Links noch Anhänge, sondern nur eine überzeugende Nachricht.
Wie erkennt MailGuard CEO Fraud?
MailGuard kombiniert Absender-Authentifizierung (SPF, DKIM, DMARC), Ähnlichkeitsanalyse von Domänen und Anzeigenamen, den bisherigen Schriftverkehr des Mandanten und eine Absichtserkennung im Text. So werden gefälschte Identitäten, der Bruch eines laufenden Gesprächs und die typische Sprache des Zahlungsbetrugs erkannt.
Funktioniert der CEO-Fraud-Schutz mit Microsoft 365?
Ja. MailGuard arbeitet als vorgelagertes E-Mail-Gateway und ergänzt den Schutz von Exchange Online Protection (EOP) und Microsoft Defender for Office 365. Die Integration dauert weniger als 15 Minuten.
Was kostet ein erfolgreicher CEO-Fraud-Angriff?
Laut FBI beträgt der durchschnittliche Schaden pro BEC-Angriff über 120.000 US-Dollar. Im deutschsprachigen Raum wurden Einzelfälle mit Schäden von mehreren Millionen Euro dokumentiert, darunter der Fall FACC. Der Schutz durch MailGuard kostet nur einen Bruchteil davon.
Kann MailGuard auch Lieferanten-Rechnungsbetrug erkennen?
Ja. MailGuard erkennt gefälschte Lieferanten-E-Mails durch Domain-Ähnlichkeitsprüfung, Absender-Verifizierung und Analyse von Zahlungsinformationen. Geänderte Bankverbindungen in E-Mails von bekannten Lieferanten werden automatisch als verdächtig markiert.
Was ist der Unterschied zwischen CEO Fraud und CEO Spoofing?
CEO Spoofing bezeichnet die Technik, CEO Fraud die Masche. Beim Spoofing wird der Absender einer E-Mail gefälscht, sodass sie scheinbar von der Geschäftsführung stammt. CEO Fraud nutzt diese Fälschung, um eine Zahlung auszulösen. Nicht jeder CEO Fraud arbeitet mit Spoofing: viele Angriffe kommen von einer ähnlich aussehenden Nachbardomäne oder aus einem übernommenen echten Postfach, gegen die eine reine Absenderprüfung per SPF und DMARC nichts ausrichtet.
Wie kann ich CEO-Betrug im Unternehmen vorbeugen?
Wirksam ist die Kombination aus drei Dingen: ein festes Vier-Augen-Prinzip für Zahlungen ab einer definierten Grenze, ein Rückrufverfahren über eine bekannte Telefonnummer statt über die Kontaktdaten aus der Mail, und eine technische Prüfung, die gefälschte und ähnlich aussehende Absender erkennt, bevor die Nachricht zugestellt wird. Fällt einer der drei Bausteine weg, bleibt eine Lücke.

Stop CEO Fraud before it's too late.

Try Conbool MailGuard's CEO Fraud protection free for 30 days.