Fraud Alert - CEO Phishing Alert


The Take Five to Stop Fraud campaign defines a CEO scam as “when a criminal impersonates a CEO or senior manager to trick employees into making payments to the criminal.” A CEO fraud can also be known as business email compromise.

The criminal can gain access to a real organisation’s email account or use ‘spoofing’ software to email a member of the finance team (normally) with what appears to be a genuine request or just impersonate a senior leader from a personal email address. (Note: Spoofing software is any tool or program used to falsify data and disguise a person’s digital identity, making communications or network traffic look like they come from a trusted source).

The aim of all these methods is to fool an employee into unauthorised actions. They often request that payment details are changed or ask for an urgent payment (which is a ‘social engineering’ tactic, to apply pressure to the recipient), but sometimes the scams involve purchasing Amazon or other gift cards.

Criminals may target businesses over several months, building a picture of the structure of your organisation and the employees responsible for authorising payments. NHS websites (and Freedom of Information requests) can reveal information about genuine suppliers that can then be used by criminals.

What is whale or spear phishing?

CEO fraud (often also called whale or spear phishing) is a focussed form of phishing. (Note: Phishing is a type of cyberattack where attackers masquerade as trusted sources to steal sensitive information.) The cyber-criminal will have studied the NHS organisation or has gleaned data from social media sites to “con” the recipient. The email (or MS Teams or WhatsApp message), spoofing the Chief Executive or other senior leader, generally goes to one person or a small group of people, and some form of personalisation is included – perhaps the person’s name, or the name of a colleague or supplier, to make the attempt seem more legitimate.

Social engineering techniques will always be used, essentially tricking someone into divulging information, or carrying out some action they know is not ‘per the policy / procedure’ because it is the Chief Executive or other senior leader that is supposedly contacting them. Imposing a time pressure to further confuse the recipient is another tactic often used. 

If you don’t work in finance, you may feel this alert is irrelevant to you as you won’t be targeted by such CEO emails, but that is not always the case. Fraudsters often send out these emails / messages to hundreds (and maybe thousands) of people at the same time and may not be as targeted as we assume. Conversely, they may target non-finance personnel who won’t know the prescribed organisation policy or process to follow.

Stop and think

Anyone should stop and take five seconds to think rationally about why the organisation’s CEO (or other senior leader) would be contacting you and asking you to do something unusual (purchase Amazon gift cards and scrape off the foil section to see the numbers) or payment related, something that sits in the purview of someone else.

Similar tactics may be applied in your personal lives, like the broken phone WhatsApp (and text) scam - or messages purporting to be from the Police, HMRC or some other such body or authority figure.

Actions

The generic advice contained in the Take Five to Stop Fraud CEO Scam campaign, cannot be bettered!

 


Latest News & Insights

LOCATIONS

MIAA, Regatta Place
Brunswick Business Park
Summers Road
Liverpool
L3 4BL

Email: miaa.admin@miaa.nhs.uk

Tel: 0151 285 4500 (9am - 5pm Mon-Fri)

FOLLOW

STAY CONNECTED

Get in touch at miaa.admin@miaa.nhs.uk

© Copyright - MIAA