Your finance director receives an email from the CEO. Subject: "Confidential operation -- urgent transfer". The message explains that an acquisition is under way, everything must remain confidential, and a transfer of 87,000 euros must be sent to an account in Hungary before 17:00. The email address is almost identical to the CEO's. The signature is perfect. So is the tone.
48 hours later, the money is gone.
This scenario is not a simulation. It happens to several hundred French SMEs every year, with average amounts now exceeding 70,000 euros per incident.
How it works
The 3 techniques fraudsters use against your SME
€70,000
Average amount stolen
Per BEC incident in France (source: Cybermalveillance.gouv.fr)
$2.9bn
Global BEC losses in 2023
More than all ransomware attacks combined
3 days
Average detection time
Fraudulent transfers are rarely recoverable after 24 hours
1. Impersonating the CEO
The attacker creates an email address that looks like the real one: hakim.djelili@cyber-expert.fr becomes hakim.djeli1i@cyber-expert.fr or hakim.djelili@cyber-experts.fr. They send a message to the CFO or accountant, citing urgency, confidentiality, and serious consequences if the transfer is not made quickly.
The OSINT context is carefully prepared: the attacker has reviewed LinkedIn, the website, and press releases. They know who is who, understand the internal jargon, and sometimes even know about current projects.
2. Compromising an email account (true BEC)
A more sophisticated approach: the attacker takes control of a real email account -- belonging to a supplier, customer, or the CEO. They monitor conversations for several weeks, wait for a genuine transaction, then intervene at the right time to change the bank details.
3. Social engineering by phone (vishing)
Sometimes the fraudster calls after sending the email to "confirm" the transaction. The voice is reassuring. It removes any doubts the employee may have had. With today's voice-cloning tools, some fraudsters even use a synthetic version of the CEO's voice built from LinkedIn or YouTube videos.
Why SMEs are targeted
What makes your organisation vulnerable
SMEs combine several risk factors that large groups have partly addressed:
- No formal transfer approval procedure: in many SMEs, the CEO's word is enough. No dual signature and no systematic callback to a known number.
- A highly accessible CEO: a complete LinkedIn profile, interviews in the local press, and conference appearances. The attacker builds an accurate OSINT file with little effort.
- A small accounting team: one person handles transfers without internal secondary approval. Hierarchical pressure works.
- Poorly configured email: no SPF, DKIM, or DMARC. Anyone can send an email using your domain name without mail servers rejecting it.
- No training: employees have never seen a fraud simulation. They do not know it happens, let alone how to respond.
Protect yourself
The 6 controls that block 95% of attempts
Control 1
Mandatory callback procedure for every exceptional transfer
Any transfer request outside the usual procedure (new beneficiary, unusual amount, or claimed urgency) triggers a phone callback to a known number -- not the one provided in the email. This rule applies even if the request comes from the CEO. Especially if it comes from the CEO.
Control 2
Dual approval for transfers above a threshold
Set a threshold (for example, 5,000 euros) above which every transfer requires approval from two different people. This threshold also applies to transfers to existing beneficiaries if their bank details changed recently.
Control 3
Configure SPF, DKIM, and DMARC on your domain
These three DNS records prevent attackers from sending emails that impersonate your domain name. DMARC in reject mode blocks delivery if SPF and DKIM fail. It is technical but critical: without it, anyone can send an email in your company's name.
Control 4
Systematically verify changes to supplier bank details
Any change to a supplier's bank details triggers verification: call back on the old known number, never the number provided in the change email. This process must be documented and systematic, with no exceptions.
Control 5
Targeted awareness training for the accounting team
Run at least one CEO fraud simulation exercise each year. People who process transfers must have seen at least one convincing fake email and practised saying no despite simulated pressure. Theoretical training is not enough.
Control 6
MFA on every work email account
Compromising an email account requires obtaining its credentials. MFA blocks access even if the password is stolen. Without MFA on executive and accounting mailboxes, you remain exposed to true BEC (email account compromise).
When an incident occurs
What to do within 2 hours of detection
- Contact your bank immediately and request a transfer recall (effective only if the money has not yet been removed from the recipient account).
- File a report with the police or gendarmerie and provide all evidence: emails, amounts, and recipient account details.
- Report the incident on Cybermalveillance.gouv.fr -- the data is passed to specialist criminal police units.
- Notify your cyber insurer if you have a policy. Some policies cover losses related to transfer fraud.
- Preserve the evidence: do not delete fraudulent emails, record timestamps, and retain login logs if the email account was compromised.
Would you like to test your team's resilience to this type of attack? Cyber Expert provides tailored CEO fraud simulations. Contact us for an initial discussion.
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call