United Kingdom flagIndependent UK business banking research
UK Business Banking Research · BanksGB
Business typesCards & expensesCash flowSecurityDigital bankingMerchant servicesFX & tradeInsightsAll topics
BanksGB · Security

Business email compromise and CEO fraud: stop the urgent payment before it reaches the bank

A practical UK guide to business email compromise and CEO-payment fraud covering impersonation, compromised mailboxes, bank-detail changes, verification and incident response.

Business email compromise turns ordinary finance routines into fraud instructions. An attacker can impersonate a director, supplier, solicitor or customer and pressure staff to release an urgent transfer. The strongest control is independent verification before payment, because once a Faster Payment is sent the business may have only a recovery process rather than a cancellation option.

The fraud relies on trusted identity and urgency

Business email compromise often starts with a convincing message from an executive or supplier asking for a confidential or urgent transfer. The attacker can spoof the visible sender address or compromise a real mailbox and reply inside an existing email thread.

That makes grammar and logo checks unreliable. Finance should treat unusual payment behaviour as the stronger signal: new bank details, secrecy, late-afternoon urgency, pressure to bypass approval or a request that does not fit the person's normal role.

Bank-detail changes are a high-risk event even when the invoice is genuine

An attacker can wait inside a supplier mailbox until a real invoice is due, then substitute their own bank account. The amount, purchase order and supplier name can all be genuine while only the payment destination is fraudulent.

Verify any new or changed supplier details using a trusted phone number or secure portal already held by the company. Do not call a telephone number contained only in the same email that changed the bank details. Confirmation of Payee can help but should not replace independent verification.

Senior-name impersonation should never override normal approval

CEO fraud succeeds when staff believe a senior executive's authority is more important than process. Set a policy that no director, owner or chief executive can waive beneficiary verification through an email or messaging app.

If the CEO genuinely needs a £250,000 emergency payment, the normal second approver or verification step should still apply. Senior management must support the rule publicly; otherwise staff will not challenge a message that says "I know this is outside process, but do it now."

Treat mailbox compromise as a cyber incident, not only a payment incident

If a real mailbox was compromised, reset credentials, revoke active sessions, review forwarding rules and involve IT or the security provider immediately. Attackers often create hidden rules that continue copying finance messages after the password is changed.

Review other payment requests from the same period. One fraudulent bank-detail change can be part of a larger compromise involving invoices, payroll or customer refunds. Finance and IT should coordinate evidence rather than working separate cases.

Report the fraudulent payment to the bank immediately

If money has already been sent, contact the sending bank through its official fraud channel immediately and provide beneficiary, amount, time and payment reference. Ask the bank to begin the relevant recovery process and obtain a case number.

Do not wait for the supplier or police before notifying the bank. Faster action gives the receiving institution a better chance of identifying remaining funds. Preserve the fraudulent emails and payment approvals because they can be needed by the bank, insurer, police or Financial Ombudsman.

Design finance workflow so one compromised inbox cannot move money

Separate beneficiary creation from payment approval, use named banking users and require a second channel for bank-detail changes. Limit who can edit supplier master data. Turn on payment alerts and review new-beneficiary activity.

Run short simulations with finance staff so they practise challenging a fake urgent request. The control should be behavioural as well as technical. A well-designed process assumes that a convincing email may eventually reach the right employee and makes the transfer difficult to complete anyway.

Create a payment-call-back rule that is independent of transaction size for first-time beneficiaries and changed supplier accounts. A £4,000 fraudulent payment can be a test before a £400,000 request. Verification should use a contact already stored in the vendor master or contract, not one introduced in the change message. Record who made the call and who answered.

After an incident, review approval culture as well as technology. If staff say they felt unable to challenge a director's urgent message, the control environment failed even if multi-factor authentication worked perfectly. Senior executives should explicitly tell finance that legitimate urgent requests can wait for the required verification and that employees will not be criticised for following the payment policy.

Editorial Verdict

Business email compromise succeeds by borrowing trust from real executives and suppliers. The decisive control is not spotting a fake font or greeting; it is refusing to release unusual payments or changed bank details without independent verification.

If a payment escapes, contact the bank immediately and treat the mailbox as compromised until proven otherwise. Finance, IT and management should respond together. The goal is to make one stolen email account insufficient to redirect company cash.

Sources

Keep the banking structure tied to the business model

Use the provider directory, comparisons and practical guides to narrow the questions before choosing products.

Start comparison