CEO fraud rarely starts with a technical security gap. In most cases, it starts with a perfectly ordinary message that sounds exactly like the boss. I experienced this myself in spring 2024, and it happened in my own office.
An Email in My Name That I Never Wrote
It was a Monday morning. I was in a Teams meeting, taking notes on the side, while Mireille, our accountant, kept glancing over at me. As soon as I hung up, she asked: “Nikolai, why am I supposed to transfer 5,000 euros to this account?”
On her screen was an email from “Nikolai Behr, DIKT GmbH”. It asked her to transfer 5,000 euros to a specific IBAN. My greeting, my tone, my signature. However, I had never written it. Only when we clicked on the sender did a Hotmail address appear, beginning with 358.
What Mireille said next has stayed with me ever since. Had the amount not been such a round number, she told me, she would have made the transfer. After all, she assumed I had quickly sent the instruction during my call.
So the attackers had not found a weakness in our systems. Instead, they knew how I write, how I address my colleague and what my signature looks like. Moreover, they were counting on the fact that a short instruction between two appointments would surprise no one. We simply leave too many traces online.
Back then, it was an email. Today, it is a face and a voice.
From Email Trick to Deepfake: How CEO Fraud Has Evolved
Also in early 2024, an employee of the engineering firm Arup in Hong Kong joined a video conference. On screen, he saw the CFO and several colleagues he knew. He heard their voices, and together they discussed a confidential transaction. Afterwards, he initiated 15 transfers to five accounts, totalling around 25 million US dollars. Not a single person on that call was real.
How could anyone miss that? The honest answer is that almost anyone would have.

Graphic: Dall-E by DIKT
Why Our Brains Barely Recognise Fakes
A 2024 meta-analysis evaluated 56 studies with a total of 86,155 participants. On average, people identified deepfakes correctly in 55.54 percent of cases. By comparison, a coin toss lands at 50 percent, and the statistical margin of uncertainty even reaches below that mark.
Voices fare little better. Researchers at the University of California, Berkeley, showed in Scientific Reports that participants matched an AI-cloned voice to the same person as the original in around 80 percent of cases. Yet they recognised the clones as artificial in only about 60 percent of cases. In other words, four out of ten cloned voices passed as genuine.
“I recognise my boss by his voice” is therefore no longer a security strategy. The same applies to: “But I saw the client on the video call.”
Berlin: When People Launch the Attack Themselves
An attack on the Berlin city administration in August showed that this goes far beyond payment fraud. According to Germany’s Federal Office for Information Security (BSI), attackers targeted two Berlin government departments – for building and for transport – using a method called TerminalFix. A manipulated website, such as a fake CAPTCHA, persuades the user to open the Windows terminal and paste a command from the clipboard. The method needs no technical vulnerability, because it exploits human behaviour instead.
The consequences were considerable. According to the State of Berlin, most of the data was extracted between 7 and 12 August, and on 14 August both departments were disconnected from the network. For a time, housing benefit payments could not be made to 50,000 eligible households. The group Rhysida also claims to have stolen 5.79 terabytes of data, including passwords.
If a single click can paralyse two government departments, employee training alone is not enough. It then also becomes a matter of access rights, system architecture, authentication and processes.
The Figure That Concerns Me Most
Bitkom, Germany’s digital industry association, estimates the damage caused by theft, espionage and sabotage in the German economy in 2026 at 211 to 270.8 billion euros. Cyberattacks account for 76 percent of that figure. Overall, the damage has even fallen slightly compared with the previous year.
Where my 5,000 euros would have ended up, however, the picture is very different. Losses through fraud attempts amounted to around 0.9 billion euros in 2025, whereas in 2026 they have already reached 8.4 billion. That is more than a ninefold increase in a single year. In addition, 82 percent of the companies surveyed expect attackers to make increasing use of AI.
The Wrong Question in the Fight Against CEO Fraud
Many organisations ask: will our people recognise the fake? A more useful question, however, is this: does our process still work when nobody recognises the fake?
Mireille did not stop the payment because she had a deepfake detector. She stopped it because the amount seemed odd to her and because she felt free to ask me directly.
When did someone in your organisation last stop a payment because an instruction from above seemed strange, and receive explicit praise for doing so?
Five Rules That Protect Against CEO Fraud
- Image and voice are not proof of identity. A video call creates closeness. Nevertheless, every sensitive decision needs a second confirmation.
- Money needs a second channel. Confirm new bank details, unusual payments and larger sums through a known, independent route. In practice, that means calling back on the number you already have, not the one in the email.
- Urgency does not suspend the rules. Words like “immediately”, “confidential” or “the board is aware” are reasons for more scrutiny, not less.
- Questions must be welcome, and audibly so. Anyone afraid of bothering the CEO with a verification question is the ideal target for attackers.
- Train decisions, not just detection. Who is allowed to stop a payment? Whom do I call? What do I do if the supposed boss demands an exception on a video call? These answers must be settled before the attack arrives.
Trust Needs New Rules
Paranoia helps no one here. The vast majority of video calls are genuine, and most clients really are who they claim to be. However, the old certainty of “I can see him, so it must be him” no longer holds. That is why trust can no longer depend on people alone. It needs processes that everyone can rely on, even when dealing with their own boss.
One test question is particularly helpful in everyday work: who benefits if I believe this right now?
And tell your team this week that they may call you back at any time. Even when you are in a hurry. Especially then.
For Your Leadership Team
In keynote talks, I show leaders how deepfakes and social engineering work today and which decisions must be made before the first fake call comes in. With real cases, live examples and without scaremongering. You can explore the topic in more depth in our book “The Age of Fakes!”.
Sources
- Diel et al.: Human performance in detecting deepfakes: A systematic review and meta-analysis of 56 papers, Computers in Human Behavior Reports, 2024
- Barrington, Cooper & Farid: People are poorly equipped to detect AI-powered voice clones, Scientific Reports, 2025
- Financial Times: “Arup lost $25mn in Hong Kong deepfake video conference scam”
- BSI (German Federal Office for Information Security), BITS-B No. 2026-287419-1032 on the TerminalFix campaign
- State of Berlin, information on the cyberattack on the state network
- Bitkom Research: Wirtschaftsschutz 2026 (Economic Protection 2026), survey of 1,003 companies

Dr. Nikolai A. Behr CSP® ist Keynote Speaker, Kommunikationsexperte und Medientrainer für Führung, Vertrauen und empathische Kommunikation in Zeiten von Wandel und KI.
