Subscribe to the Non-Human & AI Identity Journal

CEO Fraud

CEO fraud is a social engineering attack in which an adversary impersonates a senior executive or trusted intermediary to convince staff to approve money transfers, disclose information, or change account details. The attack succeeds by exploiting organisational authority and urgency rather than technical compromise.

Expanded Definition

CEO fraud is a form of business email compromise and authority-based social engineering that targets decision-making, not infrastructure. The attacker pretends to be a chief executive, finance lead, lawyer, or trusted supplier and pushes the recipient toward a fast action: approve a wire transfer, alter payment instructions, or share sensitive records. The key distinction is that the victim is being manipulated into authorising a business process, often through email, chat, or voice, rather than being tricked by malware or a direct account takeover.

Definitions vary across vendors on whether CEO fraud is a subset of business email compromise or a broader category of impersonation fraud, but the security issue is the same: an attacker exploits authority, urgency, and secrecy. This aligns with core governance concerns in NIST SP 800-53 Rev 5 Security and Privacy Controls, particularly where organisations need approval workflows, identity verification, and transaction controls for sensitive actions. The most common misapplication is treating CEO fraud as a mailbox problem, which occurs when teams focus on spam filtering while ignoring process weaknesses in payment approval and identity confirmation.

Examples and Use Cases

Implementing defences against CEO fraud rigorously often introduces friction into payment and escalation workflows, requiring organisations to weigh speed against verification depth.

  • A finance employee receives an urgent email that appears to come from the CEO requesting an immediate international transfer before market close.
  • An attacker impersonates a senior executive in a chat platform and asks HR to send payroll data or tax records to a “new auditor”.
  • A compromised supplier account sends revised bank details, and the message is reinforced by a fake executive thread to create legitimacy.
  • A voice call from a spoofed number instructs an assistant to bypass normal approval steps for a confidential acquisition payment.
  • An internal approver receives a forged request that mirrors the style of prior executive correspondence, making policy bypass feel routine rather than suspicious.

These scenarios are especially effective when organisations rely on informal approvals, shared inboxes, or inconsistent callback procedures. The attack surface is often widened by weak segregation of duties and by staff assuming that familiar tone or seniority equals authenticity. Guidance from CISA on business email compromise and MITRE ATT&CK reinforces that social proof, not technical sophistication, often drives success.

Why It Matters for Security Teams

CEO fraud matters because it turns trust relationships into a financial control failure. When security teams treat it only as an awareness issue, they miss the operational impact: fraudulent transfers, delayed procurement, compromised personal data, and reputational harm. Effective mitigation requires identity-aware controls around high-risk approvals, including verified out-of-band callbacks, dual authorisation, transaction thresholds, and clear exception handling. Those controls map directly to OWASP guidance on identity and trust abuse patterns only insofar as automated assistants or email triage systems are being manipulated to route requests, but the core issue remains human and process trust.

For identity and access teams, the lesson is that executive impersonation often succeeds where roles, privileges, and approval paths are loosely governed. PAM, mailbox protections, and MFA help, but they do not replace validated business processes. Organisations typically encounter the true cost only after a fraudulent payment is approved or a confidential change is already in motion, at which point CEO fraud becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-1 Identity verification and access decisions are central to resisting impersonation fraud.
NIST SP 800-53 Rev 5 IA-2 The control family covers authentication for users initiating sensitive actions.
NIST SP 800-63 Digital identity assurance helps validate who is actually requesting a sensitive action.
OWASP Non-Human Identity Top 10 Trusted non-human workflows can be abused to relay or approve fraudulent requests.
NIST AI RMF AI-assisted communication tools can amplify impersonation and trust exploitation.

Bind high-value approvals to strong authentication and independent confirmation.