CEO Fraud: A Payment Verification Protocol That Holds

It’s Friday, ten to five. Your accounts payable manager is closing out the week when her phone rings. The CEO. He sounds tired, slightly conspiratorial. There’s an acquisition in play, he says, completely confidential, the lawyers will email the payment details within minutes, and the transfer has to leave today or the deal collapses. He can’t talk long; he’s between meetings. “I’m trusting you on this one. Don’t discuss it with anyone.”

Nothing about that call is unusual, and that is precisely the problem. The voice sounds right. The email that follows carries a law firm’s letterhead. The amount is large but plausible for your company. Every signal your finance team has been trained to check comes back green, because every signal has been forged.

I build verification tools for a living, and if the fraud data keeps teaching me one thing, it’s this: payment fraud against companies is rarely a hacking story. It’s a trust story. The FBI’s Internet Crime Complaint Center logged 21,442 business email compromise complaints in 2024, with losses of roughly $2.77 billion, making it the second most expensive crime category in the 2024 IC3 report. Almost none of those cases involved breaking into a bank. They involved persuading one person with payment authority that the instruction in front of them was real.

How CEO fraud and invoice fraud actually arrive

Four doors, in rough order of how often I see them described in case reports.

The hijacked thread. A supplier’s mailbox gets compromised, quietly, weeks in advance. When a genuine invoice discussion is underway, the fraudster replies inside the real thread: “please note our updated bank details for this and future invoices.” The history is authentic, the names are authentic, the project references are authentic. Only the IBAN is new. This is the variant that catches careful people, because everything they check is genuinely real except the one field that matters.

The confidential acquisition. The call described above, or its email twin: a message from the CEO’s address (or one letter off) to someone in finance, invoking a secret deal, a pending audit, a tax settlement. The story varies; the ingredients never do. Authority, urgency, secrecy.

The supplier letter. A formal PDF on convincing letterhead: “we have changed banks, kindly direct all future payments to the account below.” No hacked mailbox needed, just a scrape of your supplier list and some patience.

The deepfake meeting. In January 2024, an employee in the Hong Kong office of the engineering firm Arup received a message about a confidential transaction, supposedly from the company’s UK-based CFO. He was suspicious, and said so afterwards. Then he joined a video call with the CFO and several colleagues he recognised, and his suspicion dissolved. Every other participant on that call was an AI-generated deepfake, built from publicly available footage. He made 15 transfers to five local accounts, around US$25.6 million in total, before a check with head office exposed the fraud (CNN’s report has the details).

The Arup case matters not because of the technology but because of what it retires. “I saw him with my own eyes on the call” has now joined “I heard her voice” and “it came from his address” in the category of evidence that proves nothing.

Why hierarchy and urgency beat written controls

Most companies that lose money this way had a payments policy. It sat in a handbook, and it lost a fight against a phone call, because the script isn’t attacking your policy. It’s attacking the person holding it.

Three levers do the work. Authority: a junior clerk does not ring the chief executive to ask whether he is really himself. In most corporate cultures that call feels insubordinate, even insulting. Urgency: the deal closes today, the tax deadline is tonight, the timing is always Friday afternoon or the day before a holiday, when approvers are scarce and everyone wants to go home. Secrecy: “tell no one” is dressed up as deal hygiene, but its actual function is to sever the informal network of colleagues who would otherwise say “that’s odd” out loud.

None of this is improvised. Fraud groups research the org chart on LinkedIn, learn who approves payments, watch for the CEO’s travel and conference appearances, and time the approach for when he is genuinely unreachable. The victim’s colleagues later say the same thing in every case study: she wasn’t careless, she was cornered.

Here is the asymmetry I keep circling back to as a founder. Your CEO can verify a clerk in ten seconds. The clerk has no way at all to verify the CEO. Every scam in this article lives inside that one-way street.

The payment verification protocol

The counter is not vigilance. Vigilance is a mood, and moods lose to professionals. The counter is a mechanical protocol that runs the same way on a calm Tuesday and a panicked Friday. Write this down, adapt the thresholds to your size, and make it policy:

  • Four eyes on every payment above a defined threshold and on every first payment to a new account. Two people, independently, neither able to release funds alone.
  • Out-of-band callback for every instruction that arrives by email, phone or video. Verify on a different channel than the one the request came in on, using a number you already had on file. Never use a number from the message, the signature block or the letterhead; that just phones the fraudster back.
  • Treat every IBAN change as a new payee. Call your existing contact at the supplier on the number from your master data, not the letter. Until they confirm, pay the old account or pay nothing.
  • No exceptions for executives. Not for the CEO, not for the board, not for the “lawyer handling the deal”. The bigger the name, the stricter the check.
  • Let first payments to new accounts wait 24 hours where the business allows it. Fraud has a shelf life; genuine invoices don’t.

That’s the whole protocol. It costs a few phone calls a month. The median it prevents is a wire you will never see again.

Make refusing safe before the phone rings

The protocol has exactly one failure point: the moment a convincing executive pushes back against it live. “I don’t have time for your callback. Do you understand what’s at stake?” A rule that an angry boss can waive is not a rule, it’s a suggestion.

So the missing piece is political, not technical. The CEO must bless the protocol in advance, in writing and in person, with a sentence like: “If anyone, including me, ever pressures you to skip the callback, that pressure is itself the strongest fraud signal you will ever receive. Refusing is your job, and I will back you publicly every time.” This flips the psychology. Challenging the boss is a career risk; following the boss’s standing order is career safety. The Arup employee had doubts before the video call. Doubts need somewhere safe to land, and only the person at the top of the hierarchy can build that place.

The first hour after a fraudulent transfer

If money has already moved, speed beats deliberation. Call your bank’s fraud desk immediately and ask them to attempt recall and to alert the receiving bank; funds often rest in the first mule account for hours before dispersing. In the US, file at once with IC3, whose Recovery Asset Team can in some cases help freeze domestic transfers reported quickly. In the UK, report to Action Fraud on 0300 123 2040. Then preserve evidence: the full email headers, the invoice PDFs, call logs, the works. And resist the urge to make the employee the story. Companies that punish the person who was defrauded teach the next victim to hide the fraud for a week, which is exactly the time window recovery needed.

Verifying the human, not the channel

Every control above is a workaround for one missing primitive: two colleagues on a call cannot prove to each other who they are. That’s the gap we’re building Hongi for. Two people pair once in person, and from then on each sees a rotating codeword, refreshed every 30 seconds and computed offline on the device; an impersonator, however good the voice or the video, can never know both sides. A CFO and CEO who are paired have a two-second check for exactly the Friday call this article opened with: no codeword, no payment. It doesn’t replace four-eyes or callbacks, and I won’t pretend it does. It closes the specific hole they leave open, the voice on the phone. That same mechanism is where our work with organizations is heading, with the security details laid out on our compliance page.

Until then, hold the line on the boring version: callback to a known number, four eyes, no exceptions. The transfer can wait until Monday. The fraud can’t.