How to measure whether your organization would fall for CEO fraud

Una mano con puño de camisa y gemelos desliza un sobre rojo sellado con lacre sobre un escritorio de oficina al anochecer, junto a un teclado y una pila de hojas, con las luces de la ciudad desenfocadas detrás

How to measure whether your organization would fall for CEO fraud

At 5:40 p.m. on a Thursday, the treasury team gets an email from the CFO. A transfer to a new supplier has to go out before the close, the deal is confidential and he is walking into a meeting, so there is no need to call him. The analyst calls him anyway, and the payment never leaves. The next day the audit committee asks the uncomfortable question about that CEO fraud attempt. Would it work again? And on whom?

The click rate from your last phishing campaign does not answer that question. CEO fraud is one of the scams that moves the most money. The FBI’s IC3 2024 report recorded 21,442 complaints and $2.77 billion in losses, the second-largest crime by amount after investment fraud. Measuring whether your organization would fall for it takes a different kind of exercise.

What is CEO fraud?

CEO fraud is a scam in which someone impersonates a person with authority inside the organization, or a trusted supplier, to get someone else to make a payment or change bank details without following the usual control. It is also known as BEC, short for business email compromise.

Email is the classic channel, but not the only one. The IC3 itself includes compromised phone numbers and virtual meeting applications in its definition, which is why the same request can arrive as a voice note or as a meeting with a familiar face. Deepfakes have made the format more convincing, but the mechanism is the same as ever and relies on the same persuasion levers of social engineering, with authority and urgency up front.

The technical side, how a sender is spoofed or an email account is taken over, is a topic of its own. This piece deals with a different question, the committee’s.

What is the goal of CEO fraud?

The goal is to divert money. Sometimes the target is credentials or information, but the typical case ends with a transfer to an account the attacker controls. It can be an urgent payment that appears to come from senior management, or a legitimate invoice from a real supplier with the bank details changed.

That defines who it targets. To work, CEO fraud only needs one person who can move funds or edit the supplier master file, and in most organizations those people are few and have names. They sit in treasury, in accounts payable and in the executive assistant roles that handle calendars and signatures. The board completes the group, because theirs are the identities being impersonated.

Why doesn’t a general phishing simulation measure CEO fraud?

The usual reaction is to add a “CEO” scenario to the next organization-wide phishing campaign. It looks efficient, and it has two costs worth putting on the table before you do it.

The first is that the pretext stops working. A transfer request signed by management and sent to two thousand people is irrelevant to the nearly two thousand who have never approved a payment, and it is exactly the kind of email people talk about in the hallway. By the time it reaches treasury, a screenshot has already gone around the team chat.

The second is that the average hides the group that matters. A 4% click rate across the organization can coexist with two out of six treasury staff entering their details, and in the general report those two people are a rounding error. The average rate describes the organization, and CEO fraud is decided in a group of twelve.

There is one more reason not to settle for the average. An attacker only needs one person in the right place.

What does a targeted exercise need?

A CEO fraud exercise looks more like an internal control test than a security awareness campaign. These are the five elements that set it apart.

  1. A closed, named group. The people who can approve, execute or change a payment, and no one else. It is defined by what each person can do in the process, not by their department on the org chart.
  2. A high-context pretext. Month-end close, a supplier the organization actually works with, a change of bank account or a confidential acquisition. The closer it is to the group’s real week, the more the result tells you.
  3. The timing. These requests tend to arrive near the close, before a public holiday or when the signatory is travelling. Choosing that moment is part of the realism.
  4. A prior agreement. Management and HR know the exercise exists and what will be done with the result. An exercise that ends in a list of culprits teaches the group to hide the next mistake, and a list of repeat clickers says more about the lure than about the person.
  5. An observable behavior. What counts as falling for it and what counts as doing the right thing has to be defined before the first email goes out.

Part of the risk is tested differently. Whether someone calls the number in the email or the one in the supplier master file is measured by a tabletop exercise on the dual verification procedure. The simulation and that exercise complement each other, and neither replaces the other.

How do you run an exercise like this in SMARTFENSE?

A phishing simulation campaign in SMARTFENSE can be assigned to a group built from specific names, so the exercise reaches the twelve people in the group and no one else. Besides the scenario gallery, content can be created from scratch, which lets you write the pretext with your organization’s supplier, tone and vocabulary.

The platform records, per person, who opened the email, who clicked, who entered data and who reported it with the button, along with the time of each event. The report counts in their favor too. It can trigger a Nudge, a message that reaches that person by email, Slack or Microsoft Teams, to thank them in the moment for doing exactly what the exercise was looking for.

What do you present to the committee?

The first thing you present is a number with a denominator: how many people in the group fell for it out of everyone who received the exercise. The stated goal is zero, and it pays to say so from the start, because in this group a single person who approves the payment is the entire incident.

Next to it go two figures that tell the good part, how many people in the group reported it and how long the first report took, which is the time an attacker would have had to push the rest.

If two people in accounts payable clicked, what goes up at the end of the presentation is which control was missing at that point in the process and the proposal that covers it. For example, verifying every change of bank details through a channel different from the one the request came in on, and requiring a second signature when an urgent transfer exceeds a certain amount. The named detail stays with whoever has to adjust the process. What the committee needs is to know where the gap is and what is being done about it.

The following Thursday

The analyst who called that Thursday did something no filter could have done for her. What the committee wants to know is whether that was a reflex of the group or the luck of the email landing on her desk, and a targeted exercise is the way to answer with data before a real fraud answers it.

If you want to see how the exercise is built for your own group, you can request a platform demo.

Nicolás Bruna

Product Manager de SMARTFENSE. Su misión en la empresa es mejorar la plataforma día a día y evangelizar sobre la importancia de la concienciación. Ha escrito dos whitepapers y más de 150 artículos sobre gestión del riesgo de la ingeniería social, creación de culturas seguras y cumplimiento de normativas. También es uno de los autores de la Guía de Ransomware de OWASP y el Calculador de costos de Ransomware, entre otros recursos gratuitos.

Leave a Reply