According to the FBI Internet Crime Report 2024, business email compromise was the second most expensive cybercrime by experienced loss, amounting to over $2.7 billion.
Got a message on your WhatsApp messenger or an email from your boss asking you to handle a discreet assignment? Or, asking you to do a favour involving money? Beware of paying heed to such requests. If you do, you will become a victim of cyber fraud. Termed as ‘Executive Phishing’, this hacking method is currently being used by fraudsters to deceive gullible colleagues. It works on the basic psychology – a boss is asking you to do something, and you can’t generally say ‘no’.
A private company employee received a message from his ‘CEO’, asking him to buy a few gift cards to be presented to some clients. “I’m at a conference. We need to provide our clients with some gift cards, and I want you to handle this discreetly for me,” the message said.
Soon after identifying the attack, the organisation that was mentioned early in the report quickly sent an alert asking its employees not to fall prey to such ploys and check the veracity before acting on such messages. At first glance, it sounded genuine as the sender’s account had the photo of his boss. But on the second, he noticed the message came from a new number.
Stan Kaminsky of Kaspersky cautions that the message could come in dozens of flavours. Hackers cite involvement of regulators, police, or major business partners, and then suggest all manner of ways to “solve the problem” with a colleague’s help.
“The person approaching the victim appears to be someone you know to some extent — and a fairly important person at that. Scammers often choose a C-level manager’s profile as bait. First, they have authority; second, chances are the victim knows the person, but not well enough to spot the inevitable differences in speech or writing style,” Kaminsky said.
To prevent interference with the fraud, the fake boss initially warns the victim against discussing the incident, citing disastrous consequences. The fraudster often claims a lack of trust in others or alleges disloyalty among other employees, aiming to isolate the victim until their demands are met.
Business emails
WhatsApp’s not the only medium that hackers prey on. They use business emails too to lure the victims into the trap. Vakaris Noreika, a cybersecurity expert at the Lithuania-based threat management platform NordStellar, said business email compromise is a sophisticated social engineering attack to deceive victims by impersonating trusted individuals — their colleagues.
“Unlike traditional phishing scams, these attacks are highly targeted and personalised, relying on broader research about the company, its employees, and even conversations within the organisation,” he said in a statement.
According to the FBI Internet Crime Report 2024, business email compromise was the second most expensive cybercrime by experienced loss, amounting to over $2.7 billion.
Noreika explains that business email compromise attacks can be financially devastating because they provide a direct entry point to infiltrate a company’s network by targeting employees.
“Even the most cyber-aware user can fall victim to business email compromise attacks because they exploit the added layer of trust that comes with impersonating a person of authority in the organisation,” he said.
How to stay safe
Noreika emphasises that the first step companies should take to safeguard against business email compromise attacks is to build a comprehensive security strategy and raise employee cybersecurity awareness. Noreika advises companies to monitor the dark web for potential employee data leaks to prevent cybercriminals from infiltrating the network using leaked or stolen credentials.
Published on July 3, 2025

