Business, Commercial and Corporate
CEO Fraud and Workstations: When Urgency Becomes a Scammer’s Weapon
Why is this type of fraud so effective?
It relies on common human behaviours: respect for authority, willingness to help, a sense of urgency and confidentiality. Information about an organization—its organizational structure, projects, investments and business practices—is often publicly available online. Cybercriminals routinely research these details before launching an attack. With the help of artificial intelligence, they can now mimic an executive’s writing style, create highly convincing emails or even replicate a person’s voice and appearance in a phone call or video meeting.
The scam typically follows a familiar pattern:
- An email, text message or phone call appears to come from the CEO or another senior leader.
- The sender makes an urgent request to transfer funds, issue a payment to a supplier or update banking details.
- The employee is pressured to act quickly and, in some cases, to keep the request confidential.
- By the time the organization realizes it has been targeted by a scam, the payment has already been made and the funds have been moved out of reach.
Emerging schemes that rely on deepfakes (AI-generated fake voices or videos) make these attempts even more convincing.
How can SMEs protect themselves?
The most effective safeguards are often simple and inexpensive:
- Require dual approval for significant fund transfers as part of your internal processes and policies.
- Ensure those processes and policies prohibit changes to banking information based solely on an email request.
- Verify any unusual requests through a separate communication channel, such as a phone call to a known number or a Teams conversation, to confirm that the request is legitimate.
- Enable multi-factor authentication (MFA) on sensitive accounts.
- Train employees regularly on the risks of phishing, CEO fraud and social engineering. Raise awareness before and during vacation periods. As students and temporary workers supplement the workforce, fewer trained employees may be available to handle these requests, making it a particularly attractive time for cybercriminals. Ensure that everyone receives appropriate training.
Remote work: an added risk
Employees working remotely are often more vulnerable to fraud attempts because they cannot always quickly verify a request with a colleague or manager. Organizations should therefore establish clear verification procedures, secure communication channels and training tailored to the realities of remote work.
Remote workers using personal computers
Some remote workers use their personal laptops, either because they are self-employed or because their employer does not provide a device. In these situations, they should:
- Keep their operating system and software up to date.
- Use a reputable antivirus solution and ensure it remains active at all times.
- Enable MFA on all work-related accounts.
- Use strong, unique passwords.
- Avoid sharing the device with family members.
- Lock their screen whenever they step away from their workstation.
- Connect only to secure Wi-Fi networks protected by a strong password.
- Avoid downloading work documents locally unless absolutely necessary.
- Promptly report any suspicious activity or potential device compromise.
The most common mistakes made by remote workers using personal computers:
- Using the same computer for both work and personal activities, which increases the risk of malware infections. Free games and social media platforms can serve as entry points for malicious software. If children also use the laptop for these purposes, the attack surface increases. Keeping the laptop for work purposes only and limiting its use to a single person helps ensure that no one clicks on a fraudulent link and that security settings remain compliant.
- Postponing updates, which leaves users exposed to attacks that could otherwise have been prevented.
- Reusing the same password across multiple accounts. If that password is exposed in a breach or appears on the dark Web, it becomes easier to identify the employee and try the same password on their personal computer to gain access to sensitive information.
- Disabling or failing to enable MFA. Multi-factor authentication is not intended to inconvenience employees; it serves as a last line of defence, especially if a password has been exposed elsewhere.
- Using a poorly secured Wi-Fi network. Residential routers sometimes still use weak passwords or default settings. An inadequately secured home network can make certain attacks or data interception easier.
- Downloading sensitive documents locally, such as customer lists, contracts and personal information. This practice should not be permitted. Keeping information within the organization’s secure environment, where one exists, rather than on an employee’s hard drive, is much more secure.
- Responding too quickly to an urgent request, particularly when it involves a financial transaction that could be a case of CEO fraud. Similarly, installing an application or artificial intelligence tool without the organization’s authorization is not recommended, even if it is free and may improve productivity. Confidential information could be disclosed without the employee realizing it.
- Ignoring warning signs after a mistake, such as clicking on an unknown link, entering a password on a fake site or sending an email to the wrong recipient. Any incident should be reported to the organization as quickly as possible so that appropriate action can be taken.
Particular caution is required when personal, financial or confidential information can be accessed from a personal device.
The best defence: staying vigilant
In the age of deepfakes and artificial intelligence, a familiar voice, a known email address (sometimes even a personal Gmail account) or a video can no longer be considered sufficient proof of authenticity. The best protection remains a combination of clear procedures, financial and technological controls, ongoing training, and a culture where employees are encouraged to verify before acting. Just a few minutes of verification can prevent thousands of dollars in losses.
