CEO Fraud and Fake Invoices Fuel BEC Losses

Proton Blog · Medium sophistication
Last updated August 24, 2026

This article explains how business email compromise (BEC) scams work when attackers impersonate executives or suppliers to request urgent wire transfers, bank-detail changes, or credentials, often without malware or links. It cites real, high-loss cases (including Google/Facebook and aerospace supplier FACC) and provides common BEC pretexts your team can practice spotting and verifying.

How the attack works

Business email compromise (BEC) does not rely on malware or malicious links. Instead, it relies on a plausible, well-researched email that asks a specific person to do something that fits inside a normal working day. Attackers typically impersonate a senior executive, a supplier, or an internal colleague, and the request is almost always a wire transfer, a change to payment details, or sensitive credentials.

Identity spoofing techniques behind these emails include lookalike domains, display-name spoofing, header spoofing, Reply-To manipulation, and in some cases a genuinely compromised mailbox. When attackers use a real compromised account, they don't need to fake anything, which makes detection harder.

Why these scams succeed

Three scenarios illustrate the pattern: a fake CEO requesting an urgent, confidential acquisition payment; a supplier notifying a bank detail change timed just before a real invoice is due; and a fake IT helpdesk asking an employee to confirm a password or approve a login prompt.

Each scenario exploits the same weaknesses:

  • Urgency and confidentiality that discourage verification
  • Trust in an existing relationship, such as a supplier that a business already works with
  • Employees who fear looking obstructive or distrustful toward a senior figure

Real-world examples cited include a $121 million fake-invoice scheme that billed Facebook and Google using invoices impersonating a hardware supplier both companies genuinely used, and a roughly €50 million CEO-impersonation request against aerospace supplier FACC tied to a supposed acquisition project. In the invoice case, the fraudulent payments continued for two years because they fit an existing business relationship.

What to watch for

Red flags across these scenarios include:

  • Urgency tied to closing a deal or completing a transfer

Key findings

  • BEC relies on a plausible, well-researched email request rather than malware or links: “the entire attack is a well-researched email asking a specific person to do something that fits plausibly inside a normal working day.”
  • Attackers commonly impersonate “a senior executive, a supplier, or an internal colleague” to request “a wire transfer, a change to payment details, or sensitive credentials.”
  • Identity spoofing methods described include lookalike domains, display-name spoofing, header spoofing, Reply-To manipulation, and using a compromised mailbox.
  • Real examples cited include: a $121M fake-invoice scheme targeting Facebook and Google, and a ~€50M CEO-impersonation request against FACC tied to a supposed acquisition project.
  • Recommended defenses emphasize process controls (dual authorization, callback verification) and technical email authentication (DMARC/SPF/DKIM), plus an “always acceptable to pause and verify” culture.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounts Payable, Payroll, HR, Executives, All Employees.
  • Affected industries: Technology (internet services), Manufacturing (aerospace supplier), Any organization with finance/accounts payable/payroll functions.
  • Attack channels: email.
  • Impersonated: CEO / senior leader, Existing supplier / vendor, Internal IT / helpdesk.

Red flags to watch for

  • Urgency tied to closing “today” and pressure to act fast
  • Confidentiality request discouraging verification
  • Unusual payment request coming directly from senior leadership
  • Bank detail change timed “just before a real invoice is due”
  • Request relies on existing relationship to avoid scrutiny
  • Payment instructions arrive via email without independent verification
  • Asks for passwords or login approvals via email
  • Uses “system update” urgency to justify unusual requests
  • Tries to normalize bypassing standard IT verification channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is business email compromise (BEC)?

BEC is a scam where attackers impersonate a senior executive, supplier, or internal colleague to request a wire transfer, a change to payment details, or sensitive credentials, typically without malware or links.

How do attackers impersonate executives or suppliers in BEC scams?

Common methods include lookalike domains, display-name spoofing, header spoofing, Reply-To manipulation, and sending from an already compromised mailbox.

What real-world losses have resulted from BEC attacks?

Cited cases include a $121 million fake-invoice scheme against Facebook and Google impersonating a hardware supplier, and a roughly €50 million CEO-impersonation request against aerospace supplier FACC.

How can organizations reduce BEC risk?

Recommended controls include verifying unusual payment or bank-change requests by phone using a number already on file, requiring dual authorization above a set threshold, and deploying DMARC alongside SPF and DKIM.

Read the video transcript

Imagine this hits your inbox: “Confidential: need this acquisition transfer processed today.” And it looks like it’s from our CEO. This is classic business email compromise. No malware, no links, just a well‑researched email pressuring one person to move money fast, outside normal approval steps. It’s fooled big names: Facebook and Google lost over $120 million to fake supplier invoices; aerospace firm FACC lost about €50 million to a CEO‑style acquisition email just like this. Your move: if an email asks for a payment or bank‑detail change, pause, and call the person or supplier on a known phone number to confirm, never the number in the email.

Similar attacks

Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Recruitment Emails Hide BitB Google/Facebook Traps

Recruitment Emails Hide BitB Google/Facebook Traps

Researchers found a large recruitment-themed phishing campaign where victims receive unsolicited interview invites and are sent to fake scheduling or recruitment pages. The pages use “Browser-in-the-Browser” fake login popups to steal Google/Facebook passwords and, in some cases, capture MFA codes…

August 17, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Malicious GitHub Issue Can Hijack AI Coding Agents

Malicious GitHub Issue Can Hijack AI Coding Agents

Researchers showed that AI coding agents from Anthropic, Google, and OpenAI could be tricked by untrusted GitHub inputs (like an issue or workflow file) into taking unsafe actions. In the demos, a single malicious issue or writable workflow file could lead to remote code execution, stolen…

August 6, 2026
GitHub Issue Trick Turns AI Coders Against Repos

GitHub Issue Trick Turns AI Coders Against Repos

Researchers showed that a single public GitHub issue (from someone with no repo access) could steer popular AI coding agents into running dangerous commands, exposing tokens, and changing repositories. The risk comes from AI agents reading untrusted issue/PR text while also having access to…

August 6, 2026