CEO fraud and invoice fraud: how scammers try to play your bookkeeping
An urgent payment on behalf of the director, or a supplier with 'new' bank details. Here is how to recognise CEO and invoice fraud and build a simple defence.
By Limburg Cyber Group
Not every attack is about hacking. Some of the most expensive incidents use no malware, but deception: convincing someone to send money to the wrong account. Two classics are CEO fraud and invoice fraud. They are surprisingly effective, and surprisingly simple to block.
What is CEO fraud?
An employee with payment authority receives an urgent message that appears to come from the director: “Can you quickly make this payment, I’m in a meeting, keep it between us.” The pressure, the authority, and the haste sideline common sense. Before you know it, the money is with the scammer.
What is invoice fraud?
Here the attacker poses as an existing supplier and reports “changed bank details”. You dutifully pay the next invoice, but to the wrong account number. Sometimes they intercept a real invoice and only alter the IBAN.
The red flags
- Unexpected haste and secrecy (“it has to be now and quiet”).
- A payment that bypasses the normal procedure.
- Changed bank details by email, without verification.
- Subtly different email addresses, see also spotting phishing.
- Authority as leverage (“the director is asking for it”).
The defence is procedural, not technical
The beauty: you stop this mainly with a good agreement, not with expensive software.
- Four-eyes principle for payments above a certain amount: always a second person who approves.
- Verify changes through a second channel. New bank details? Call the supplier on a number you look up, not from the email.
- Make “no, I’ll verify first” normal. No employee should feel pressured to skip that step, not even by “the director”.
- Confirm unusual instructions verbally.
Discuss it with your team
The weakest spot is an employee who does not know this exists. A short explanation with a few examples makes your team resilient. This belongs in your broader security awareness approach.
Need help?
We help you draw up simple payment and verification agreements that stop fraud without slowing down your administration. See our cybersecurity service or book a conversation.
Read more
Passkeys for your business: logging in without a password, and hard to phish
Passkeys replace the password with a key on your device that will not work on a fake site. What they are, what to watch for and how to start sensibly.
Securing your company website: the maintenance nobody gets round to
Many small business websites run for years without maintenance. What to sort out: updates, admin accounts, tested backups, HTTPS and access to your domain.
QR code phishing: how quishing works and how your team can spot it
Scammers hide links in QR codes: in emails, PDFs, letters and on stickers. Why it works, how to recognise it, and what to tell your employees about it.