How business email compromise works, what to do in the first hours, whether the bank answers and what actually prevents it.
An email from the finance director requests an urgent and confidential transfer to close a deal. The employee executes it. The email was fake, the deal did not exist, and the money is already in Hong Kong. It is called CEO fraud, and in medium-sized Spanish companies it is today more frequent than a hold-up.
How it works, exactly
CEO fraud (or business email compromise) is not a sophisticated technical attack. It is an attack on people and procedures, and that is where its effectiveness lies. The attacker studies the company for weeks: who signs, who pays, when the managing director travels, what tone he uses in emails, which suppliers the company works with. Sometimes they already have access to a real mailbox, compromised months earlier, and simply wait. And then they strike at the perfect moment: Friday afternoon, the director on holiday, a confidential deal that “cannot be discussed with anyone”, and time pressure that prevents verification. The employee who executes the order is not incompetent: they are someone who did exactly what they always do.
The variants we see most
Impersonation of the executive: an email from a domain almost identical to the real one, with one changed letter nobody notices. Change of the supplier’s account: an email, apparently from the usual supplier, communicates a new account number for the coming invoices. This is the most devastating modality, because the fraud is not detected until the real supplier claims payment, weeks later. Compromised mailbox: the attacker is inside the real email, reads the conversations and inserts themselves into a legitimate thread at the moment of payment.
The first hours: this is where the money is recovered or lost
This is the critical point and where almost every company wastes the time it does not have. There is a window of hours. Call the bank immediately and request the recall or blocking of the transfer: the sooner, the higher the probability the money is still there. Report immediately: the report activates international banking cooperation and the freeze at the destination bank. Do not switch off or clean the systems: the impulse to “secure” the mailbox by deleting and reinstalling destroys the evidence of the access, which is what later proves what happened and who failed. Preserve forensically the mailbox, the access logs and the original emails with their complete headers. The headers are the evidence, and they are lost when the email is forwarded.
Does the bank answer for it?
It depends, and the honest answer is: less than in consumer fraud. When the payer is a company and the transfer was authorised with its own legitimate credentials, the operation is not “unauthorised” in the sense of payment-services regulation: an employee with authority approved it. That does not close the door. It is examined whether the bank complied with its obligations to detect unusual operations, whether the destination account showed evident warning signs, and whether there was negligence in the execution. But expectations should not be oversold: here recovery comes sooner through speed than through claims.
Internal liability: the uncomfortable conversation
Then comes the second part, where the company hurts itself. The employee who executed the transfer committed no offence: they were deceived, just like the company. Dismissing them precipitously, besides being unjust, usually ends in an unfair-dismissal ruling. The right question is not who pressed the button, but why the procedure allowed it to be pressed. And there the responsibility lies with the organisation: there was no double verification, no alternative channel to confirm account changes, and the internal culture made questioning an order from the director unthinkable.
What actually prevents it
It is surprisingly cheap and almost nobody has it: double verification through a different channel for every transfer above a threshold and for every change of a supplier’s bank account, calling a known number, not the one in the email. Segregation of duties: whoever orders does not execute. Two-person authorisation above a certain amount. A culture where asking is not insubordination: this is the most effective control and the hardest to implant. And all of it documented, because it forms part of the compliance programme and, if the moment comes, proves the company’s diligence.
Criminal lawyer. Managing partner of Société de Conseil Juridique et Expert. Offices in Alicante and Madrid.
Francisco Javier Martín Porras
Abogado penalista, socio de Société de Conseil Juridique et Expert y creador de la metodología LIWARD®. Dirige la defensa en procedimientos penales de alta complejidad, combinando estrategia procesal con análisis pericial y forense. Conozca al equipo →

