CEO Fraud Email Scam UK: Spot a Fake Boss Request
Verify every unusual payment or sensitive-data request through a separate trusted channel, even when it comes from a genuine-looking internal address.
What CEO fraud looks like
CEO fraud is a form of business email compromise. A criminal sends an email tailored to the organisation, impersonates a senior executive or another regular contact, and asks an employee to make an urgent payment, buy gift cards or disclose valuable information. The message may include an invoice or changed bank details that look genuine.
Why it can be convincing
The request combines authority, urgency and sometimes secrecy. Normal email filters may struggle with a low-volume, tailored message. A familiar display name or an address that looks correct is therefore not proof that the request is genuine.
Warning signs
- The request is urgent and confidential.
- It bypasses the normal payment or data-release process.
- The supposed executive is said to be unavailable for a call.
- The payment method, payee or type of information requested is unusual.
- You are told to ignore a Confirmation of Payee warning or not involve another approver.
These are indicators, not a test: a tailored impersonation message may contain no obvious spelling or address error.
How to verify the request
Contact the named person through another method, such as a known phone number or in person. Do not rely on contact details in the message. Follow the organisation's approval process regardless of seniority. The NCSC advises robust verification for changed payment instructions, new suppliers and unusually high transactions, and suggests requiring two or more people where losses could be significant.
Organisational controls
Use multi-factor authentication on email and financial systems, limit payment authority to those who need it, maintain a separate verification process for important requests, and configure email-domain anti-spoofing protections. Train staff to report an unusual request without fear of delaying a genuine transaction.
If money or data has already been sent
Contact the sending bank immediately through an official channel and ask whether the payment can be stopped or recalled. Tell the organisation's IT or security contact so they can check the relevant accounts, mailbox rules and sign-ins. Preserve the original message and audit trail.
Reporting in the UK
Forward a suspicious email to report@phishing.gov.uk. If money was sent, data was disclosed or an account was compromised, report the crime to Report Fraud at reportfraud.police.uk or 0300 123 2040 in England, Wales or Northern Ireland; in Scotland, call Police Scotland on 101. Supplier impersonation and changed bank details are covered separately at Invoice Fraud UK: How to Verify a Payment Safely.
Frequently asked questions
Can a convincing internal-looking email still be fraudulent?
Yes. A tailored impersonation can look familiar, which is why independent verification matters more than the displayed sender.
What is the strongest practical control?
A consistently enforced out-of-band verification and approval process for unusual payments and sensitive-data requests.