forumNew topic

Got a fake email impersonating the CEO asking for a company wire transfer, what to do against these attacks

TTuba E***Expert
Job title
Data protection consultant
Joined
Oct 2023
Message
158

Doki · Backup setup · 2024

#1

Yesterday our accounting team got a fake email — it was from the 'CEO' and said an urgent transfer was needed. Luckily, the accounting manager called the CEO to check. It was fake.

Such a smart attack scares me. This could happen to other businesses too. How can we fight this kind of fraud?

Is it easy to spoof email headers? How can they send emails under someone else's name?

DDamlaMember
Job title
Clinic manager
Joined
Aug 2024
Message
92
Most Helpful#2

CEO Fraud (Executive Impersonation) is an extremely common and costly attack. Attackers spoof email headers (header spoofing).

Protocol: Always set up a dual-approval mechanism for financial transactions. The accountant must be verified by a second person.

Against email-based attacks: Configure DMARC, SPF, and DKIM settings. These protocols verify the source of fake emails.

SSevimNew member
Job title
Florist
Joined
Nov 2024
Message
26
#3

happened to us too! the ceo email section was simply fake but nobody noticed. now we have a double signature rule no problems anymore

PPınar K***New memberCommunity member
Joined
Aug 2026
Message
410
#4

Protection from CEO Fraud: 1. Dual approval for all transfers 2. Phone verification (not via email links) 3. Set up DMARC/SPF 4. Train employees 5. Check the sender's email address

YYasemin T***New memberCommunity member
Joined
Aug 2026
Message
68
#5

the email header actually fooled us. the address looked legit... edit: it was fake but who's gonna cheeck

HHilal Z***MemberCommunity member
Joined
Dec 2024
Message
136
#6

How email spoofing works: Mail servers without SPF, DMARC, and DKIM configuration can send emails under other names.

RRıdvan A***Veteran
Job title
Software developer
Sector
Leather
Organization type
two-branch business
Joined
Jan 2024
Message
12
#7

How does a dual-approval mechanism work? For example, is approval required from both the accountant and the CFO?

AAslı K***New member
Job title
System support specialist
Sector
Consulting
Organization type
family business
Joined
Aug 2026
Message
193
#8

great reflex! you could have lost a lot of money. cEO fraud costs companies over a trilion dollars

OOrhan T***Member
Job title
Purchasing manager
Sector
Printing
Organization type
medium-sized business
Joined
Mar 2023
Message
348

Doki · E-commerce infrastructure · 2023

#9

I'll argue the opposite, don't get mad. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Correct me if I'm wrong.

DDamla P***MemberCommunity member
Joined
May 2024
Message
191
#10

Ill try it.

SSena Ç***Member
Job title
Software team lead
Sector
Security services
Organization type
120-person company
Joined
Jan 2025
Message
29
#11

Im curious too. Dont hesitate to ask; those who dont ask always pay more.

Good luck with that.

NNazlı T***Member
Job title
Social media manager
Sector
Packaging
Organization type
medium-sized business
Joined
Nov 2023
Message
58
#12

The most overlooked point about executive impersonation email is this: Hasty decisions become decisions you have to fix six months later.

If you have questions, write them; I'll answer as best I can.

KKübra E***Member
Job title
Logistics planning
Sector
Leather
Organization type
20-person company
Joined
Mar 2025
Message
46
#13

You're right. If you scold false alarms, nobody will report again.

If you post the result here, it will help others too.

MMeryem A***Expert
Job title
Store Manager
Sector
Media and publishing
Organization type
boutique agency
Joined
Dec 2025
Message
99

Doki · Brand identity · 2026

#14

Three different views emerged, they all complement each other. The answer varies greatly by industry; there is no one-size-fits-all rule.

I'm also curious if anyone does it differently.

EErcan G***MemberCommunity member
Joined
Dec 2023
Message
282
#15

This approach has a cost, which isn't discussed. When we decide without measuring, we always end up in the same place.

An automated scan report is not the same as a penetration test. I'm also curious if anyone does it differently.

OOkan K***MemberCommunity member
Joined
Mar 2026
Message
66
#16

Let me summarize the topic since several different answers were given. I mean when making a decision first look at what data you have on hand.

Im also curious if anyone does it differently.

MMert U***ExpertCommunity member
Joined
Jan 2024
Message
112
#17

Three different views emerged they all complement each other. Mistakes made on the executive impersonation email side are usually reversible but expensive.

HHakan Y***Member
Job title
Production planning
Sector
Seafood
Organization type
20-person company
Joined
Sep 2022
Message
42
#18

I'm curious too.

MMerve Ö***Expert
Job title
Technical service technician
Sector
Retail
Organization type
workshop
Joined
Oct 2022
Message
142
#19

I went through the same thing two years ago. Most incidents start with a leaked password, not a vulnerability.

Just leaving this note, it might be useful.

FFurkan U***MemberCommunity member
Joined
Apr 2023
Message
163
#20

How did you solve this? Having backups accessible on the same network and with the same identity makes them part of the target.

Reply