Family Sentinel
Guide · Impersonation & invoice fraud

Executive impersonation
and invoice fraud.

Two of the most costly email scams share a method: they impersonate someone you trust to redirect a payment. One wears the CEO's authority; the other wears a familiar vendor's invoice. Here is how each works, how attackers now use AI to make them more convincing, the specific red flags to train your people on, and a verification playbook that stops the money before it moves.

In brief

Executive-impersonation ("CEO fraud") and invoice-redirect fraud both trick an employee into sending money to a criminal by posing as a trusted party. CEO fraud uses authority and urgency to push a wire or gift-card purchase; invoice fraud quietly changes a vendor's bank details so real payments go astray. Neither usually carries a link or malware, so email filters miss them. The defense is not better filtering but a mandatory verification step: confirm every new or changed payment instruction by phone, using a number you already had on file. This guide pairs with our BEC prevention checklist.

Published 8 August 2026 · updated 11 August 2026 by Family Sentinel.

A 7-minute read for finance, accounts-payable, and leadership.

Executive impersonation (CEO fraud)

In this scam, an attacker poses as a senior leader — the CEO, the owner, the CFO — and emails someone who can move money. The message is short, urgent, and confidential: a deal is closing, a supplier must be paid today, buy gift cards for a client, keep it quiet until it's done. The power of it is social, not technical. It borrows the executive's authority and adds time pressure so the employee feels acting is safer than questioning.

Red flags of CEO fraud

Invoice redirect fraud

This one is quieter and often more expensive. The attacker sends a message — frequently from a vendor's real but compromised mailbox — saying the vendor's banking details have changed, so please update the account for future payments. Because it can come from the genuine address, reference a real invoice, and match an expected payment, it looks entirely routine. The next legitimate payment simply lands in the criminal's account, and the fraud may not surface until the real vendor asks where their money is.

Red flags of invoice fraud

The new twist: AI-assisted impersonation

Two developments have made these scams harder to catch by eye. First, attackers now use generative AI to write lures in fluent, on-brand English — the spelling and phrasing "tells" that used to give a scam away are largely gone. Second, and more striking, they have begun faking not just email but voices and faces.

In early 2024, a finance employee at the global engineering firm Arup was tricked into making 15 transfers totaling about $25.6 million after joining a video call in which every apparent participant — including the company's CFO — was a real-time AI deepfake. The employee had been suspicious of the initial email, but the "video call" reassured them. It shouldn't have.

The lesson is not to distrust every call, but to understand what a call now proves: less than it used to. A face and voice on a screen are no longer identity. The only reliable check is one the impersonator cannot control — a call back to a known number, a confirmation through a separate channel, a detail only the real person would know. Build the verification around that, not around "did it sound like them."

The verification playbook

The common thread is that you usually cannot tell the fraud from the message itself, because a compromised account — or a deepfaked call — is convincing. So the defense lives outside the request. Make these steps mandatory, written down, and expected — not optional judgment calls under pressure.

If a payment has already gone out

Speed decides whether the money is recoverable — recovery depends on reaching the receiving bank while the funds are still there, usually within the first day or two. Call your bank immediately to request a wire recall, file with the FBI at IC3.gov so its Recovery Asset Team can act, preserve the original emails and headers, and secure any mailbox that may have been accessed. Our BEC prevention checklist covers the response steps in full.

Sources & further reading: FBI Internet Crime Complaint Center (ic3.gov) · CISA guidance on business email compromise · the Arup deepfake case as reported by CNN and other outlets, 2024. Educational only; not a substitute for advice from your bank, attorney, or a qualified security professional.

Common questions

What is CEO fraud?

CEO fraud is a scam in which an attacker impersonates a senior executive and emails an employee — usually in finance — with an urgent, confidential request to wire money or buy gift cards. It works by combining authority and pressure so the employee acts before verifying. The message often arrives when the real executive is known to be traveling or otherwise hard to reach.

What is invoice redirect fraud?

Invoice redirect fraud is when an attacker, often using a real but compromised vendor mailbox, sends a message updating the bank details on file so future payments go to an account they control. Because it can come from the genuine vendor address and reference a real, expected invoice, it frequently passes every technical check and looks completely routine.

How can I tell a real payment-change request from a fraudulent one?

You often can't tell from the email alone, and that is the point — a compromised account looks genuine. The reliable test is not in the message but outside it: call the requester back on a phone number you already had on file, never one from the email, and confirm the change out loud. Treat any new or changed bank detail as unverified until that call happens.

Can attackers really fake an executive's voice or a video call?

Yes. In one 2024 case, a finance employee at the engineering firm Arup was deceived into making 15 transfers totaling about $25.6 million after a video call in which every apparent colleague, including the CFO, was a real-time AI deepfake. The lesson is that a face and voice on a screen are no longer proof of identity — the verification must happen through a separate, known channel, using a fact or callback the impersonator cannot control.

Who in an organization is targeted by these scams?

Anyone who can move money or change payment records: finance and accounts-payable staff, bookkeepers, office managers, and payroll administrators. Executives are impersonated; the people who process payments are the actual targets. Small businesses and nonprofits are hit hard because they often lack a formal, mandatory verification step.

Who should own the verification process?

Name it explicitly. The written policy should say who performs the call-back, at what dollar threshold a second approver is required, and through which channel verification happens — so it does not depend on one person remembering under pressure. Give staff standing permission to pause any payment to verify, and make clear they will be thanked, never blamed, for doing so.

Catch the request your filter waves through

Family Sentinel's Org Guard watches for exactly these patterns — lookalike domains, new-payee and wire language, and mailbox rules that hide replies — and alerts a person you choose before the payment moves. Read-only, and never able to send or delete a thing.

Book a scoping call More guides