Search

Hongke's latest articles

HongKe

Add your title text here

I. Introduction: Strategic Changes at the Data Layer under the Critical Infrastructure Legislation

[Hongke Insights] Did You Receive an Urgent Email from the CEO Requesting a Wire Transfer? It Might Be a Scam: How Companies Can Protect Themselves Against Business Email Compromise Scams

“I'm in a meeting right now. Please transfer this payment to the new account immediately.”
“This is a confidential acquisition; please do not contact anyone else.”
“Please purchase a batch of gift cards for me and send me the card numbers directly.”
These emails appear to come from a company’s CEO, CFO, or other executives; they are brief, urgent, and sometimes even mention specific clients, suppliers, or ongoing business transactions. However, the person behind these emails may not be an executive, but rather an attacker who has been researching the organization for some time.
This type of attack is commonly referred to as “CEO fraud”; its full name isBusiness Email Compromise (BEC) The

I. What is the relationship between CEO fraud and BEC?

CEO fraud is typically a common form of BEC.
In CEO fraud, attackers impersonate the CEO, CFO, or other executives and exploit the authority of their positions to trick finance, human resources, administrative, or other employees into carrying out unauthorized actions, such as:
  • Transfer funds to an account controlled by the attacker;
  • Update the supplier's payment account;
  • Purchase a gift card and have the card number sent to you;
  • Submit employee payroll or tax information;
  • Disclosing customer information, personal information, or internal documents;
  • Handle “urgent classified matters” by bypassing the normal approval process.
BEC has a broader scope. In addition to impersonating executives, attackers may also pose as suppliers, lawyers, clients, finance personnel, or other trusted business contacts.
Therefore, in Chinese articles, it is recommended to express this as:
Business Email Compromise (BEC), also commonly referred to as business email fraud; when attackers impersonate a CEO or other executive to carry out a scam, it is typically called CEO fraud or executive impersonation fraud.
Strictly speaking, BEC does not necessarily involve an actual “breach” of an email account. Attackers may either hijack a legitimate email account, register an address that closely resembles the company’s domain name, or forge the email display name. Therefore, “Business Email Compromise” is the standard industry translation, while “Business Email Fraud” is easier for non-technical readers to understand.

II. How Destructive Is BEC?

The FBI has identified BEC as one of the types of cybercrime that cause the most financial losses. According to data from the FBI’s Internet Crime Complaint Center:
 
  • 2025, the FBI received a total of24,768 casesComplaints related to BEC report losses as high as$3.046 billion... a significant increase from the 21,442 complaints and $2.77 billion in losses reported in 2024.
  • In 2025, BEC ranked second among all cybercrime losses, second only to investment fraud.
  • Of the BEC losses reported in 2025, more than$30 millionDirectly related to AI technology.
Even more alarming is the fact that, according to an FBI report, BEC/CEO fraud resulted in more than 23,000 complaints in 2019, causing losses exceeding $1.7 billion;Between June 2016 and July 2019, total global losses attributable to BEC exceeded $26 billion.. Stu Sjouwerman, founder of KnowBe4, pointed out that,BEC is harder to detect than simple phishing attacks...because these emails do not contain malware and can bypass traditional antivirus software.

III. Why Is CEO Fraud So Effective?

BEC does not rely solely on malicious attachments or obvious phishing links. Many attack emails consist of only a few lines of text, asking recipients to transfer funds, reply to the message, or modify their account settings, and may therefore bypass traditional detection mechanisms that focus on malicious files and links.
It primarily leverages the relationships of trust that already exist in a company's day-to-day operations.
 

1. Leveraging the authority of one's position

When an email appears to be from the CEO or another executive, employees may be reluctant to question or refuse a request for fear of delaying important matters.
 

2. Create a Sense of Urgency

“Phrases such as ”Must be completed immediately,“ ”The client is waiting,“ and ”Take care of this before the end of the workday today” can limit the time employees have to think things through and verify details.
 

3. Emphasize confidentiality

Attackers often claim that the matter involves an acquisition, litigation, an audit, or other confidential business matters, and instruct recipients not to discuss it with colleagues, thereby cutting off internal verification channels.
 

4. Simulate Real-World Business Scenarios

Attackers may use corporate websites, social media, public news reports, and compromised email accounts to gain insight into an organization’s structure, travel arrangements, supplier relationships, payment cycles, and even the writing styles of executives. Once they gain access to corporate email accounts, attackers can monitor financial transactions and internal communications, study key personnel and payment processes, and ultimately launch highly convincing attacks.
Generative AI has further reduced the cost of impersonation. Attackers can quickly generate emails that sound natural and are tailored to specific industries and individuals, and they can also combineDeepfake Audio—Make phone calls using an AI-generated voice of an executive to further deceive subordinates into making the transfer.

IV. BEC Is More Than Just “Scams to Trick Finance Departments into Making Transfers”

KnowBe4 has categorized common CEO fraud and BEC scenarios into several categories.
 

Changes to Supplier Accounts

The attacker impersonates a long-standing supplier and notifies the company that “the bank account has changed,” requesting that future payments be transferred to the new account.
 

Emergency Transfer by an Executive

Attackers spoof or take control of executives' email accounts and instruct finance staff to urgently process wire transfers, make payments, or purchase gift cards.
 

Fake Invoices

Attackers gain access to employees’ or suppliers’ email accounts, learn the details of legitimate transactions, and then substitute invoices or payment accounts at the payment stage.
 

Impersonation by Executives or Lawyers

The attackers claimed they were handling acquisitions, litigation, or other confidential matters, and bypassed normal approval procedures on the grounds of confidentiality and urgency.
 

Theft of Sensitive Data

Attackers impersonate managers and request that the human resources, finance, or audit departments submit payroll records, tax documents, employee personal information, or customer data.
 
Therefore, the losses resulting from BEC extend beyond the funds that are fraudulently obtained and may also include data breaches, identity theft, legal liability, business disruption, and reputational damage.

V. How Does BEC Differ from Traditional Phishing?

BEC is actuallyOne of the most complex and sophisticated forms of phishing. Traditional phishing typically involves malicious links or attachments and relies on technical methods to trick users into clicking on them; BEC attacks, however, are entirely different:
 
  • Does not contain malicious payloads: BEC emails are typically plain text with no links or attachments, so they can easily bypass security gateways and traditional antivirus software.
  • Highly Targeted: BEC is not a broad-based spam campaign, but rather a carefully crafted attack targeting specific individuals and specific roles.
  • Leveraging Real Relationships: Attackers pose as people the recipient already trusts—such as a boss, supplier, or coworker—rather than strangers.
  • Relying on Social Engineering: The core of BEC lies in exploiting human weaknesses—obedience to authority, reactions to emergencies, and compliance with confidentiality requirements.
As KnowBe4 points out,The 98% cyberattacks all involved social engineering....and BEC is the hardest phishing threat to detect.

VI. Which Employees Are Most Likely to Be Targeted?

The CEO himself or herself is not necessarily the ultimate victim. Attackers typically impersonate executives to launch attacks against individuals who have access to funds, data, or systems. High-risk individuals primarily include:
 
  • Finance and Accounting Staff: You can make transfers, pay invoices, or edit supplier accounts;
  • Human Resources Staff: Maintain records of employee identification, payroll, tax, and banking information;
  • Executives and Assistants: Stay informed about important events, transactions, and internal decisions;
  • IT Manager: Allows you to reset passwords, create accounts, and adjust access permissions;
  • Procurement and Supply Chain Professionals: Frequently handles supplier data, contracts, and payment information;
  • Administrative Staff: May be responsible for gift cards, meetings, travel, and ad hoc purchases.
When establishing a security system, companies should not only provide standardized training for all employees but also arrange specialized tests and training tailored to the actual work of these high-risk roles.

VII. Why Are Technical Safeguards Still Insufficient?

Email filtering, multi-factor authentication, domain protection, and anomalous login detection are all very important, but they cannot eliminate all BEC risks on their own.
 
A BEC email may come from:
  • A real email address controlled by the attacker;
  • Counterfeit domain names that differ from the company’s domain name by only one character (homoglyph attacks);
  • A supplier's email account that was compromised;
  • Plain-text emails with no links or attachments;
  • Text messages, chat, or voice channels other than executive email addresses.
If an email comes from a legitimate account that has been compromised, and the content aligns with normal business practices, it is difficult to determine whether the request is genuine based solely on technical tools. Companies also need to establish reliable business processes and empower employees to identify anomalies, proactively verify information, and report issues promptly.

VIII. How Can KnowBe4 Help Reduce CEO Fraud Risks?

KnowBe4 can help companies transform their BEC prevention efforts from one-time reminders into a continuous “train—test—report—improve” closed-loop process.
 

1. Conduct targeted safety awareness training

KnowBe4 Security Awareness Training (SAT) can help employees identify common psychological tactics and red flags in CEO fraud, including:
  • A sudden request to change the payment account;
  • Request to bypass the normal approval process;
  • Using unusual, urgent, or confidential language;
  • There is a slight discrepancy in the sender's address;
  • An executive’s manner of address, tone, or signature differs from usual;
  • Requests to purchase gift cards or send card numbers;
  • Requests for salary, tax, or personal identification information;
  • Prevent employees from confirming this over the phone or in person.
The focus of training should not be limited to simply telling employees “don’t click”; it should also teach them to identify identity theft, unusual payments, and circumvention of procedures in emails that do not contain links or attachments.
KnowBe4 offers specialized “Overview of BEC and CEO Fraud” Mobile-First Training Module, demonstrating how these attacks work through real-world examples and providing preventive measures. In addition, the training coversAI-Driven Social Engineering and Deepfake Technology, to help employees deal with emerging threats.

 

2. Simulate a real-life CEO fraud scenario

The KnowBe4 platform supports the creation of CEO fraud or BEC simulation templates. Organizations can test how finance, human resources, and other high-risk personnel respond to requests from individuals impersonating executives in a controlled environment.
These types of tests do not necessarily include links or attachments; they can also determine whether employees might continue communicating or disclose information as requested by the attacker by tracking whether users reply to the emails.
KnowBe4'sPhishing Reply Tracking This feature is specifically designed to test whether users will interact with “bad actors on the other end of the email,” tracking whether users reply to phishing emails and even detecting the disclosure of sensitive information in automated replies.
Companies can design test scenarios based on real-world business operations, for example:
  • The CEO asked the finance staff to make an urgent wire transfer;
  • The CFO has requested changes to the supplier accounts;
  • An executive asked an assistant to purchase gift cards;
  • Management has asked Human Resources to send employee information;
  • The lawyer demanded payment on the grounds that the transaction was confidential;
  • The supplier notified us of a change in its bank account.
The purpose of the simulation is not to “catch employees making mistakes,” but to identify weaknesses in processes and awareness so that they can be corrected before a real attack occurs.

3. Enable employees to report suspicious emails with a single click

When employees detect a suspicious request, they need a simple, clear channel for reporting it. KnowBe4’sPhish Alert Button (Phishing Report Button) This allows users to report suspicious emails directly from their inbox with a single click, and deletes the email from their inbox to prevent further exposure.
The more complex the reporting mechanism, the more likely employees are to ignore emails or delete them on their own. With one-click reporting, security teams can obtain leads more quickly, determine whether the same attack has been sent to other individuals, and take prompt action.
 

4. Implement personalized interventions based on risk

The risks faced by different employees vary. Companies can identify individuals and groups that require priority protection by considering their job roles, permissions, performance on simulation tests, and historical behavior.
KnowBe4'sAIDA (Artificial Intelligence Defense Agent) It can automatically select the most relevant and challenging simulation templates for each user based on their training history, phishing incidents, and performance metrics.
Finance, human resources, executive assistants, and IT administrators can receive more frequent, business-oriented training; employees who demonstrate higher risk in the assessments can receive targeted remedial training.
This prevents everyone from having to go through the same training repeatedly and allows security resources to be prioritized for the areas with the highest risk.
 

5. Enhancing Detection Using Technological Tools

In addition to employee training, KnowBe4 also provides a technical layer of protection specifically designed to combat BEC.KnowBe4 DefendPlatform UtilizationNatural Language Processing (NLP) Technology capable of detecting key indicators of BEC attacks:
  • Display Name Impersonation Detection: Attackers use display names identical to those of internal employees but from external domains, which makes them particularly difficult to detect on mobile devices.
  • Homophone Attack Detection: Identify instances where similar characters are used (such asc0mpany.comInstead ofcompany.com) counterfeit domain names.
  • Language Analysis: Look for “credibility statements” in emails that are intended to create a sense of urgency, demand confidentiality, or discourage the recipient from verifying the information through other channels.
  • Executive Fakes Test Results: Use NLP to determine whether an attacker is impersonating a trusted and important sender, such as a CEO.
Behavioral AIIt also checks for contextual signals, such as unusual writing styles or domain behavior, to detect zero-day phishing and payload-less BEC attacks—threats that static systems are prone to miss.
 

6. Assessing Whether Behavior Has Truly Changed

Companies should not merely count how many employees have completed the course; they should also focus on:
  • Can users identify emails from executives impersonating others?;
  • Was a secondary verification performed when an unusual payment request was received?;
  • Has the rate of suspicious email reports increased?;
  • Has the response rate to simulated BEC emails decreased?;
  • Has the risk scoring for high-risk groups improved?;
  • Do errors of the same type occur repeatedly?
Security awareness programs only truly take effect when employee behavior and business processes change.

IX. What other process controls do companies need to establish?

Training and simulation tests must be integrated with technical and business controls.
 

Independent Verification of Payment Requests

Any request to add or change a payee account must be verified through channels other than email. When verifying, use the company directory or existing contact information; do not use phone numbers provided in suspicious emails.
 

Implement a two-person approval process for high-risk transactions

Transfers exceeding a specified amount, gift card purchases, and exports of sensitive data must be reviewed by at least two authorized personnel.
 

“Urgency” must not be used as an excuse to bypass procedures

Companies should clearly stipulate that, regardless of who makes the request, urgency, confidentiality, or executive authorization cannot substitute for formal approval.
 

Protecting Your Email Account and Identity

Enable multi-factor authentication for executive, finance, human resources, and IT accounts, and monitor unusual logins, automatic forwarding rules, and changes to email permissions.
 

Enhance Domain and Email Security

Deploy SPF, DKIM, and DMARC; monitor spoofed domain names; and flag external emails, display name spoofing, and similar domain names.
 

Control of Public Information

Minimize the disclosure of executive schedules, organizational relationships, financial responsibilities, supplier information, and employee contact information on the official website and social media to reduce attackers' ability to conduct reconnaissance and tailor their messaging.

X. If a transfer has already been made, time is of the essence.

If an employee has already responded to a BEC request or made a payment, the company should immediately:
 
  1. Contact the paying bank to request that the funds be recalled, frozen, or intercepted;
  2. Notify the receiving bank and relevant payment institutions;
  3. Save emails, email headers, chat logs, phone numbers, account information, and transaction details;
  4. Isolate and protect email accounts that may have been compromised;
  5. Reset the relevant credentials, and check the multi-factor authentication and email forwarding rules;
  6. Investigate whether any other accounts, suppliers, or customers have been affected;
  7. Notify management, the legal department, insurance companies, and the appropriate law enforcement agencies;
  8. Assess data breaches and regulatory reporting obligations in accordance with applicable laws;
  9. Quickly share incident information with employees to prevent the attack from spreading further;
  10. Improve payment processes, technical controls, and staff training based on the survey results.
Once funds are transferred to other accounts or converted into other assets, recovering them becomes significantly more difficult; therefore, companies must establish a BEC incident response process in advance, rather than scrambling to find the appropriate contacts after an incident occurs.

XI. The Key to Preventing CEO Fraud Is Encouraging Employees to Verify Information

CEO fraud is often successful not because the attackers employ particularly sophisticated techniques, but because employees are afraid to question a request that appears to come from senior management.
Companies need to establish a clear security culture: when faced with unusual payments, account changes, or requests for sensitive information, employees should pause their work, confirm by phone, or verify in person—not to delay work, but to protect the company.
 
The value of KnowBe4 lies in its ability to transform “staying vigilant” into a behavior that can be practiced, tested, and continuously improved through ongoing training, real-world simulations, convenient reporting, and risk assessment.
 
As Stu Sjouwerman, founder of KnowBe4, said: “Employees need to understand that they may not be able to identify a well-crafted spear-phishing email, even if it appears to come from their boss or a coworker. New security awareness training can teach employees how to verify potentially fraudulent requests, even if they appear to come from a trusted source. "
 
Technical controls can block some fraudulent emails, and business processes can limit the losses caused by a single error; however, trained employees who are willing to proactively verify transactions are the final line of defense in preventing CEO fraud.

Other Articles

Hongke Dry Goods

[Hongke Insights] The Hong Kong Monetary Authority’s Anti-Fraud Checklist Reveals Corporate Blind Spots: Why the Financial Industry Needs KnowBe4-Style Cybersecurity Awareness Training

The Hong Kong Monetary Authority’s “Beware of Scammers!” anti-fraud checklist is continuously updated, exposing scammers who impersonate banks and create fake websites, emails, and apps. Phishing attacks are becoming increasingly industrialized, and nearly all of Hong Kong’s major banks have been targeted by imposters. Relying solely on firewalls and email gateways makes it difficult to block social engineering attacks that bypass technical checks; what scammers truly exploit is people’s sense of urgency and trust. KnowBe4-style cybersecurity awareness training employs a closed-loop “assessment, training, simulation, feedback” approach. Through simulated phishing attacks, microlearning, real-time coaching, and quantifiable reports, it continuously enhances employee vigilance, transforming employees from the weakest link into the first line of defense.

Read more
Hongke Dry Goods

[Hongke Insights] Behind the $135.6 Billion Overseas Expansion Bonanza, a Single Data Breach Could Undo All Efforts

The global cross-border e-commerce market is valued at a staggering $135.6 billion! However, when it comes to exporting fresh produce, pharmaceuticals, and sensitive, high-value products, gaps in environmental monitoring and data compliance are becoming a critical vulnerability for businesses. A single data interruption or temperature deviation could result in the destruction of an entire shipment and exorbitant fines. This article provides an in-depth analysis of the three major data risks in the cross-border supply chain and introduces Hongke ELPRO’s enterprise-grade data logging and cold chain monitoring solutions.

Read more
AR 遙距會診
Hongke Case

[Hongke Solutions] The New Normal in Telemedicine: How Are AR Smart Glasses Reshaping Remote Consultations and Surgical Collaboration Workflows?

Hongke’s AR Remote Consultation Solution combines Vuzix lightweight smart glasses with the S Med remote platform to enable high-definition, real-time first-person view sharing and hands-free voice control. Remote specialists can instantly freeze the screen to annotate and zoom in on lesions, effectively overcoming geographical barriers and improving the efficiency of emergency care and surgical collaboration. Learn more about AR smart medical guidance and its practical applications today!

Read more

Contact Hongke to help you solve your problems.

Let's have a chat