CEO fraud and invoice fraud: how scammers try to play your bookkeeping
An urgent payment on behalf of the director, or a supplier with 'new' bank details. Here is how to recognise CEO and invoice fraud and build a simple defence.
By Limburg Cyber Group
Not every attack is about hacking. Some of the most expensive incidents use no malware, but deception: convincing someone to send money to the wrong account. Two classics are CEO fraud and invoice fraud. They are surprisingly effective, and surprisingly simple to block.
What is CEO fraud?
An employee with payment authority receives an urgent message that appears to come from the director: “Can you quickly make this payment, I’m in a meeting, keep it between us.” The pressure, the authority, and the haste sideline common sense. Before you know it, the money is with the scammer.
What is invoice fraud?
Here the attacker poses as an existing supplier and reports “changed bank details”. You dutifully pay the next invoice, but to the wrong account number. Sometimes they intercept a real invoice and only alter the IBAN.
The red flags
- Unexpected haste and secrecy (“it has to be now and quiet”).
- A payment that bypasses the normal procedure.
- Changed bank details by email, without verification.
- Subtly different email addresses, see also spotting phishing.
- Authority as leverage (“the director is asking for it”).
The defence is procedural, not technical
The beauty: you stop this mainly with a good agreement, not with expensive software.
- Four-eyes principle for payments above a certain amount: always a second person who approves.
- Verify changes through a second channel. New bank details? Call the supplier on a number you look up, not from the email.
- Make “no, I’ll verify first” normal. No employee should feel pressured to skip that step, not even by “the director”.
- Confirm unusual instructions verbally.
Discuss it with your team
The weakest spot is an employee who does not know this exists. A short explanation with a few examples makes your team resilient. This belongs in your broader security awareness approach.
Need help?
We help you draw up simple payment and verification agreements that stop fraud without slowing down your administration. See our cybersecurity service or book a conversation.
Read more
Security awareness: from a one-off training to a safe culture
Your employees are your biggest risk and your best defence. Here is how to build genuine security awareness that sticks, beyond a mandatory course.
Updates and patch management: the dullest measure that stops the most attacks
Outdated software is the most common way in for attackers. Why patching promptly matters so much, and how to approach it simply and in a structured way.
Securing your office network and wifi: the basics that are often forgotten
Your network is the front door of your business. Practical steps to secure your wifi, router, and guest network, without becoming a network administrator.