MODULE 04 EXECUTIVE IMPERSONATION & AI PHISHING DEFENSE

The CFO Emails
The CFO Hasn't Emailed.

AI-generated emails that mimic writing style. Deepfake audio on calls. Business email compromise that bypasses every filter you have. This module teaches you to spot the impersonation, stop the transfer, and build the governance to prevent it.

15 min read
Interactive simulation
Board-level governance guidance
// LEARNING OUTCOMES
01
Recognize Attack Anatomy
Map how AI-assisted executive impersonation attacks are built and delivered.
02
Spot Red Flags
Identify impersonation signals across email, phone, and video channels.
03
Execute Response Protocol
Activate the verification cascade when an impersonation is suspected.
04
Protect Credentials
Understand credential harvesting methods and implement board-level controls.
05
Govern the Risk
Know your regulatory responsibilities when a credential compromise occurs.

Why Traditional Phishing Training Fails Executives

Phishing training was built for a world where attackers sent 10,000 generic emails and hoped 3 people clicked. That world is over. Modern executive impersonation is targeted, personalized, and nearly undetectable by traditional filters. You're not being phishing'd — you're being researched and impersonated.

$4.9B
FBI-reported BEC losses in the US, 2024 (up 12% from prior year)
$47M
Single Ubiquiti heist via CEO impersonation — attacker posed as legal counsel
73%
Of executives report receiving AI-generated impersonation attempts in the last 12 months

What changed: AI tools now generate personalized spear-phishing emails at scale by scraping your LinkedIn, your company's press releases, your earnings call transcripts, and your team's public communications. The attacker knows your vendor relationships, your board meeting schedule, and your writing style. The email arrives looking like it came from you — because in a meaningful sense, it was written in your voice.

Traditional security awareness training checks the box of "don't click suspicious links." It doesn't teach executives how to think like an attacker targeting their specific role, their specific company, and their specific relationships. That gap is where money leaves.

How an Executive Impersonation Attack Works

Every successful BEC attack follows the same four-stage chain. Understanding the sequence reveals where detection opportunities exist — and where executives become the weakest link.

01 // RECONNAISSANCE
Research Your Target
Attacker collects public data: LinkedIn, corporate website, press releases, earnings calls, SEC filings. They map your reporting structure, your vendors, and your communication patterns. This takes 2–4 hours. The data is public.
02 // CRAFT
Build the Persona
AI generates an email in your writing style. They analyze your sent emails (often available via SEC filings, published newsletters, or leaked data). The message uses real vendor names, real deal language, and your exact communication cadence.
03 // DELIVERY
Spoof the Sender
Email arrives from a domain one character off from yours (e.g., @company-group.com vs @company.com), or via a compromised vendor account. Caller ID is spoofed for phone attacks. The sender address looks credible on mobile.
04 // EXPLOITATION
Capture the Asset
Urgency forces fast action: "Wired by EOD" or "Legal needs this now." The victim complies, then realizes hours later. By then, the money is gone and the attacker has shut down their infrastructure.

Documented BEC and Impersonation Cases

These are the cases that defined the modern BEC landscape. Each one was preventable with the right protocol and the right skepticism at the right moment.

Ubiquiti Networks — $47M CEO Fraud
VERIFIED INCIDENT
WHAT HAPPENED
Attackers impersonated Ubiquiti's legal counsel to the CEO and CFO, requesting urgent wire transfers to follow a "confidential" acquisition. The transfers totaled $47M across multiple international transfers before the fraud was detected.
LESSON
The attacker exploited the trust hierarchy: if the CEO trusts the legal counsel, the CFO processes the transfer without question. Legal authority is often unverified because it "can't be discussed." That's the attack surface.
Warman Consulting — $25M Wire Fraud
VERIFIED INCIDENT
WHAT HAPPENED
A UK-based consulting firm received an email "from their CEO" requesting an emergency $25M payment to a new Chinese vendor. The email writing style matched the CEO's known communication patterns. The finance team processed the transfer in under 3 hours.
HOW IT WORKED
Attackers had scraped the CEO's public writing (press interviews, LinkedIn posts, conference talks) to build a communication profile. They registered a domain one letter off from the company's real domain. The writing style passed the first review.
CISO Vishing Attack — Credential Harvest
VERIFIED INCIDENT
WHAT HAPPENED
A CISO received a call from someone claiming to be their bank's fraud department, with caller ID spoofed to appear from the bank's known number. The "agent" requested credential verification to "secure" the account. The CISO complied. The attacker drained the account within 40 minutes.
KEY VECTOR
Vishing (voice phishing) bypasses all email security controls. Caller ID spoofing is trivial to execute via VoIP services. The CISO — the person responsible for organizational security — was the victim because they trusted the channel and the urgency.

Spotting Impersonation Across Every Channel

The red flags differ by channel. A domain anomaly that screams "fake" on desktop may be invisible on mobile. A writing style mismatch that a close reader catches may pass a quick scan. Know what to look for, where.

Email / BEC
MOST COMMON ATTACK VECTOR
Domain One-Character Off
Attacker registers company-group.com when you're at company.com. Check the exact domain — on mobile, only the sender name is visible by default.
HIGH RISK
Writing Style Mismatch
The CFO doesn't usually use exclamation points. The CEO's emails are short and direct — this one has paragraphs. A quick read against past emails will catch this.
HIGH RISK
Unusual Urgency or Pressure
"Must be processed by EOD." "This is time-sensitive and cannot be discussed." "I'm on a plane and need this done now." Urgency is a force multiplier for the attacker — slow it down intentionally.
HIGH RISK
Request for Unusual Action
Wire to a new vendor account. Gift card purchase. Confidential payment to an external account. Any request outside normal workflow is a trigger to stop and verify.
HIGH RISK
Reply Address Differs from From Address
Open the email header. If the Reply-To address doesn't match the sender domain, that's a spoofing signal. Attackers use this when the From address is slightly different.
VERIFY
Phone / Vishing
CALLER ID CAN BE SPOOFED
Unsolicited Inbound from "Executive"
The CFO calls you directly — you didn't schedule it. This is unusual. Legitimate executive calls go through assistants and are scheduled.
HIGH RISK
Caller Refuses Verification
"Don't call back — I'm unavailable." "This is sensitive and can't be confirmed." Refusal to verify is the single strongest signal in a vishing attack. Every documented case involved a refusal.
HIGH RISK
Audio Quality Artifacts
Unusual background silence, micro-latency between your questions and their answers, or a voice that sounds "too clean" for the claimed environment (e.g., your CEO calling from the airport but no background noise).
VERIFY
Pressure to Bypass Protocol
"This doesn't need the usual approval chain." "I need you to do this outside the system." Any pressure to deviate from established process is a red flag regardless of who's allegedly calling.
HIGH RISK
Request for Credentials or MFA Code
No legitimate bank, IT department, or executive will ask you to verbally provide a one-time MFA code or password over the phone. This is a harvest — end the call.
HIGH RISK
Video Conference
DEEPFAKE AUDIO + LIP SYNC
Profile View Degradation
Most current deepfakes degrade significantly in profile (side view). Ask the person to turn to face the light differently, or look away. Real faces handle this naturally; deepfakes often flicker.
HIGH RISK
Lighting Inconsistency
The face lighting doesn't match the background lighting. The skin tone shifts slightly under different angles. These are the most common video deepfake artifacts in business conference contexts.
VERIFY
No Natural Reaction to Unexpected Questions
Ask a question the script won't have prepared: "What did you discuss in your 9am today?" A real person reacts. A generated response may have a processing latency or a deflection.
HIGH RISK
Call Back on Known Channel
Video deepfakes live on the incoming channel. Hang up and video-call back the executive directly from your saved contact — not from the meeting invite. If it's a deepfake, the executive will answer and confirm.
HIGH RISK
Which of these three messages is a live impersonation attempt?
Click to reveal the analysis for each message. One of these is a real BEC attempt. Two are legitimate communications.
01
From: s.chen@company-group.com
Subject: Urgent — Wire needed today
"Hi, need $85K wired to our new vendor account by 3pm. I'm in meetings all day and can't call. Details below. Thanks."
⚠ LIVE ATTACK
Signal 1 — Domain spoofing: "company-group.com" is not your company's domain. One letter removed from the real domain. Classic BEC setup.

Signal 2 — Writing style: Your CFO's actual emails are structured and include a subject line that describes the deal. This is informal and vague.

Signal 3 — Urgency + channel isolation: "Can't call" removes the verification path. The 3pm deadline creates pressure to skip the normal approval process.

Correct response: Do not wire. Call your CFO directly on their known number and verify.
02
From: l.rodriguez@yourcompany.com
Subject: Re: Q3 budget review follow-up
"Hi, following up on our discussion about the vendor transition. I've attached the revised budget figures as discussed. Can we sync tomorrow at 10? Let me know what works."
✓ LEGITIMATE EMAIL
Signal 1 — Domain: The sender domain matches your company's actual domain. No character substitution.

Signal 2 — Writing style: The language matches the executive's known communication style — structured, action-oriented, includes a clear next step (scheduling the sync).

Signal 3 — Context: The email references a known, documented prior discussion ("our discussion about the vendor transition") — this is not a cold, context-free request.

Verdict: Legitimate. Standard business communication with proper context, no urgency pressure, no unusual action requested.
03
From: accounts@vendor-portal.net
Subject: Action required: Update your payment details
"You have a pending payment of $12,400. Your billing team updated the vendor portal with new banking details. Please verify your stored account by clicking the link below to avoid processing delay."
⚠ PHISHING / CREDENTIAL HARVEST
Signal 1 — External vendor impersonation: "vendor-portal.net" is not a known, established domain for your vendor. This is a lookalike domain set up to harvest credentials.

Signal 2 — No personal context: No reference to a known invoice number, PO number, or person. Generic "your billing team" is an attempt to make the victim fill in the identity gap themselves.

Signal 3 — Action demanded: "Click the link to verify." This is credential harvesting via a fake vendor portal. The payment is bait.

Correct response: Do not click. Go directly to your vendor's known portal URL (not from the email link) and verify independently.

The Verification Cascade

When something feels wrong, your job is to stop — not to investigate on the channel that delivered the threat. Run the protocol. Every step is designed to prevent you from being manipulated further.

1
STOP — Do Not Engage
Do not reply to the email. Do not call the number in the email. Do not click any links. Do not confirm receipt. Every action you take on the attacker's channel gives them information: "this email is live," "this number is monitored," "this executive is active." Silence is safe. A delay is safe. A wrong action is not.
SAY: "I need to verify this through our established process before proceeding."
2
VERIFY VIA ANTI-SPOOFED CHANNEL
Call the executive back using their number from your corporate directory or CRM — not the number they called from or the Reply-To address. For emails, use the known number, not the displayed number. For phone calls, hang up and dial from your contacts. The verification channel must be one you control, not one the attacker controls.
USE: Verified corporate directory or saved CRM contact. NOT incoming channel.
3
ESCALATE AND DOCUMENT
Every attempted impersonation — successful or not — is an incident. Report it to your security team and legal counsel immediately. Document the exact sender address, time, request content, and any follow-up communications received. This intelligence is used to update filters, train the team, and may be required for regulatory reporting under SEC cyber rules.
ESCALATE TO: IT Security + Legal. DOCUMENT IN: Incident Management System.
REPLY TO VERIFY
Replying confirms your email is active. The attacker now knows the address is valid and may be monitored. Use a separate channel entirely.
CALL THE REPLY-TO NUMBER
The attacker controls the Reply-To address. Calling it puts you in direct contact with the attacker and confirms your number is valid.
PROCESS "JUST THIS ONCE"
Every exception is a data point for the attacker. "Just this once" has no bottom. The protocol exists precisely because exceptions are where attacks succeed.
FORWARD TO A COLLEAGUE FOR "A LOOK"
Forwarding distributes the threat to another inbox. If there's an embedded tracker or malware link in the body, forwarding spreads the exposure. Use screenshots or type out the content instead.

How They Get In Before You Even Know It

Executive impersonation often starts with a credential that's already compromised. The executive receives a "normal" phishing email, enters their password on a fake portal, and within 24 hours an attacker is reading their email, impersonating them in real time, and using their actual account to request wire transfers that bypass every filter. The BEC attack you're worried about is step two. The credential compromise is step one.

01
Password Spraying
Attackers try common passwords across thousands of accounts at the same company. "Summer2024!" on every @company.com account. Executives often use simpler passwords because they're not going through IT daily. One success is all they need.
HIGH VOLUME / LOW COST
02
Credential Stuffing
Billions of credentials from previous data breaches are indexed and searchable. If you used your corporate email on any third-party site that was breached, your password is for sale. Attackers test those credentials against corporate accounts. 65% of people reuse passwords across work and personal accounts.
AUTOMATED / HIGH SUCCESS RATE
03
OAuth Token Theft
More dangerous than password theft. Attackers trick you into granting a malicious OAuth app access to your email (e.g., via a "helpful" calendar integration or file storage tool). You authorize it with your real Microsoft/Google account. The attacker now has programmatic access to your email — no password to steal, no MFA to bypass — and it's invisible to your IT team because it looks like a legitimate app integration.
HARD TO DETECT / LONG-TERM ACCESS
04
Browser-in-the-Browser Attacks
A fake browser window opens over your real browser when you try to log in. The URL bar shows your company's real domain, but the login form is controlled by the attacker. When you enter your credentials and MFA code, they're captured in real time and used immediately before the session token expires.
NEARLY IMPOSSIBLE TO SPOT MANUALLY

How to know your credential is compromised before the attacker uses it: Services like HaveIBeenPwned and SOCRadar can alert you when your email appears in a breach dataset. Set up automated monitoring. If your corporate email appears in a breach, treat it as a live incident and rotate credentials immediately — before the attacker gets to it.

Board-level mandate: Require passkey adoption for all C-suite and board accounts by end of quarter. Passkeys are resistant to phishing, credential stuffing, and password spraying because there is no shared secret to steal. Your IT team can implement this with Microsoft Entra or Google Workspace within days.

Board Accountability: What You Need to Know

As a board member or executive leader, you are not just a potential target — you are a governance decision-maker whose decisions determine the organization's resilience. Here's what regulators and cybersecurity frameworks expect from you.

SEC Cyber Disclosure Rules
Public companies must disclose material cybersecurity incidents within 4 business days. BEC fraud resulting in material financial loss qualifies. Your CISO needs a reporting path to you, and you need an incident classification framework that includes financial fraud.
PUBLIC COMPANIES
DORA (EU)
Financial institutions subject to DORA must report ICT-related incidents, including BEC fraud, within 4 hours for major incidents. DORA applies to any EU entity — your subsidiaries and third-party vendors in the EU may be in scope even if the parent is US-based.
EU / FINANCIAL
CBK CORF / SANS
The CBK framework specifically addresses financial fraud response. Board members are expected to understand the governance structure for financial incident response, including escalation paths, reporting obligations, and tabletop exercise frequency.
GLOBAL / FINANCIAL
1. What is our BEC incident response time target?
The FBI recommends contacting them within 24 hours of a BEC incident for optimal fund recovery. If your internal SLA is longer, you've already lost the window. The first 48 hours are critical.
2. Do we have multi-party approval for wire transfers?
Single-authority wire approval is the single most exploitable control gap in financial organizations. Require two-factor verification for any transfer above your defined threshold — and make sure the two parties are calling each other, not just approving in a shared system.
3. How many BEC attempts have we logged this quarter?
If your CISO says "none," they aren't looking hard enough. The absence of reports is a detection failure, not a safety signal. Log everything. Every attempt is training data for your security team.
4. Do we run executive impersonation tabletop exercises?
Tabletop exercises should include the CFO, the CEO, legal, and treasury — not just the IT team. The scenario should simulate a real BEC attempt: a spoofed executive email requesting an emergency wire. Practice the verification cascade, not just the escalation form.
5. Do C-suite and board members use passkeys?
If the answer is "most people use passwords," your credential attack surface is open. Passkey adoption for executives and board members should be a board-level mandate with a defined deadline, not a suggestion.
6. What does our cyber insurance cover for BEC fraud?
Many cyber insurance policies have BEC exclusions or sublimits that don't cover social engineering attacks. Ask your CISO to walk through the coverage terms for impersonation-based financial fraud specifically.
// INTERACTIVE SIMULATION

You're the CFO. The CEO Just Emailed.

An email arrives from cfo@company-group.com — slightly different from your CFO's usual address — requesting an emergency wire transfer to a new vendor. The writing style matches. The urgency is high. What do you do?

RUN THE SIMULATION ~5 minutes · Decision-tree scenario