Cybercriminals are becoming increasingly skilled at impersonating people you know and trust. A message from your boss, a call from the financial director, or a WhatsApp from the mayor – it can sound seemingly familiar. However, a hacked mailbox or WhatsApp channel provides hackers with crucial insights into someone's communication style and an organization's internal work processes. With the help of AI, voice impersonation is also becoming increasingly convincing.
In CEO fraud, an attacker poses as a manager or other trusted individual. This can be done via a spoofed sender, but increasingly, a genuinely hacked email account is used. A credible message, phone call, or voice is no longer proof that the request genuinely comes from that person.
Local governments and other public organizations process a range of financial transactions daily, such as invoices, subsidies, purchases, salaries, and reimbursements. An attacker doesn't always need direct access to the financial system; access to the right mailbox or communication channels is sometimes sufficient. By first monitoring communications, an attacker can quickly discover who makes payments, which suppliers exist, how internal approval procedures work, and which names frequently appear in communications. They can then formulate a credible request via email, message, or phone at the opportune moment.
The attack thus targets not only cracking the technology itself but also cracking your employees by cleverly exploiting trust and work agreements. Preventing CEO fraud is therefore not just a matter of 'paying better attention,' but also of organizing your company so that one convincing email, WhatsApp, or phone call is not enough to initiate a money transfer.
To make organizations resilient, several tips are provided. A request from a manager remains a request that may be verified. Good fraud prevention makes it easy for employees to verify without feeling they are distrusting their manager. A healthy dose of professional doubt is often the best security measure.
Always verify payment requests through a different channel, such as a known phone number. Urgency should never override the control procedure. Make employees aware of these new forms of fraud, as attackers use information from previous communications. Critically examine internal processes: how many people can execute payments, who can change account numbers, and where are controls and double approvals located? A second check is mandatory for financial changes, such as a modified account number.
Where possible, limit publicly available information about employees, roles, and internal procedures, as this makes it easier for attackers to craft credible messages. If an account is compromised, limit the damage with strong multi-factor authentication (MFA) and a rapid reporting procedure.
The month of October marks the 'European Cybersecurity Month,' aiming to raise awareness among citizens, businesses, and governments about online safety. Haviland, as an expertise partner, can assist in considering processes, risks, and measures to enhance organizational cyber resilience.




