CEO Fraud: When Your Boss’s Email Isn’t Your Boss
CEO fraud, also called business email compromise (BEC), works because it bypasses your suspicion. You’ve been trained to watch for “Nigerian prince” emails or typos from a fake bank. But when the sender appears to be your own boss, your guard drops. Scammers don’t guess at random. They research. They scan LinkedIn, company websites, and press releases to learn who the CEO is, who handles finance, which vendors are used, and when the boss is traveling. Then they spoof the CEO’s email address or create a look-alike domain—like replacing an “m” with an “rn” so it reads as “rn.” A single letter difference can slip past even eagle-eyed readers.
The hallmark of CEO fraud is urgency and secrecy. The fake boss insists the payment must happen immediately and that you not discuss it with anyone. Why? Because a quick call to the real CEO in the next office would blow the whole scheme. The scammer wants you to act on fear of missing a deadline or disappointing a superior. For middle-class Americans working in small to mid-size businesses, this pressure feels real. You don’t want to be the person who ignored the boss’s “urgent” request.
But CEO fraud isn’t limited to wire transfers. Variants include fake requests for gift cards, payroll changes, or sensitive employee data like W-2 forms. One common trick: an email from “HR” asking all staff to re-verify their direct deposit information. The link leads to a form that captures bank account numbers, which scammers then use to reroute your paycheck. Another variant targets home buyers. A criminal hacks into the email of a real estate agent or title company and sends the buyer instructions to wire closing costs to a fraudulent account. The buyer loses their down payment—often their life savings.
Why does this scam keep working, even after years of warnings? Because the human brain is wired to trust authority. When someone with power and a familiar name makes a direct request, we comply without double-checking. Scammers know this and exploit it. They also exploit the fact that many small businesses and nonprofit organizations lack proper security protocols. A church treasurer might have access to the congregation’s bank account but no training on verifying email requests. A local dentist’s office might use a single Gmail account for all communications. These are soft targets.
You can protect yourself with a few simple but non-negotiable rules. First, never act on a financial request from an email alone. If you receive an email asking for money, a gift card, or sensitive data, pick up the phone and call the person who allegedly sent it—using a number you already know, not one from the email. Second, establish a “two-person rule” for any transfer above a small dollar amount. Require verbal confirmation from a second authorized person before money moves. Third, slow down. Scammers rely on panic and speed. Any message that demands immediate, secret action is almost certainly a scam. Fourth, use email security tools that flag external senders. Many email systems can automatically add a banner like “Caution: This email came from outside your organization” to messages from outside your domain.
If you fall victim, act immediately. Call your bank and ask them to reverse the wire transfer. The sooner you report it, the better the chance of recovery. File a report with the FBI’s Internet Crime Complaint Center (IC3) and contact your local law enforcement. Do not be embarrassed—these scammers are professionals who have tricked employees at Fortune 500 companies. The shame belongs to them, not you.
CEO fraud is not going away. As artificial intelligence improves, scammers will generate even more convincing voice deepfakes, phoning you and sounding exactly like your boss. The core defense remains the same: verify before you trust. The person on the other end of that “urgent” email is counting on you to skip that step. Don’t let them.


