criticalLast updated: June 2026

CEO Fraud / BEC Scams

Email compromise and impersonation attacks are targeting payment approvals, invoice changes, and executive requests.

Get the CSM Weekly Threat Brief and updates when this threat profile changes.

What\'s happening

Attackers compromise or convincingly spoof executive and finance accounts to redirect payments or force urgent transfers.

AI-generated language, voice cloning, and real-time OTP interception are making these scams harder to detect by instinct alone.

AP teams are being pressured through urgency, secrecy, and realistic domain spoofing designed to bypass normal review.

Who it targets

AP departments and finance teams

Executive assistants and operations leads

Individuals handling family or business transfers

Real-world examples

Wire change requests submitted minutes before payroll runs.

Voice-cloned approvals delivered during travel or off-hours.

Fake vendor onboarding emails sent from lookalike domains.

What it costs

Losses are immediate and often difficult to reverse.

Incidents undermine trust in financial controls and approval workflows.

Recovery frequently requires legal, banking, and vendor coordination.

How to protect against it

Require out-of-band verification for payment changes.

Deploy anti-impersonation and email authentication controls.

Train finance staff on authority pressure tactics.

Use MFA and session monitoring on executive accounts.

Vendors who specialize in this threat

BrightMail Shield

Email Security & Anti-Phishing

Inbox defense, domain impersonation monitoring, and phishing disruption.

Find More Vendors for This Threat

Signal Fraud Ops

Financial Fraud Prevention

Wire fraud controls, anomaly detection, and finance-team verification workflows.

Find More Vendors for This Threat

AwareLine Training

Security Awareness Training

Behavior-focused training for phishing, social engineering, and policy hygiene.

Find More Vendors for This Threat

Related threats

Financial Attackshigh

Fake Invoice Attacks

Attackers are impersonating vendors and resubmitting believable invoices to reroute payment flows.

Stat: Targeting AP departments at 50–500 employee companies

Read Full Brief
Identity & Accesscritical

AI-Generated Deepfake Auth

Synthetic voice and video are being used to impersonate executives, bypass trust checks, and trigger sensitive actions.

Stat: Voice + video cloning now used in fraud

Read Full Brief
Emerging / AI-Powered Threatscritical

AI-Powered Phishing

LLMs are enabling more targeted, more fluent, and more personalized phishing at industrial scale.

Stat: LLMs used to generate hyper-personalized attacks

Read Full Brief