There is a category of attack against which your antivirus can do absolutely nothing. It exploits no software flaw, drops no suspicious file, and triggers no alert. It exploits something far harder to fix: the trust an employee places in a message that appears to come from their boss.
CEO fraud, and its cousin, fake supplier fraud, target the accounts department of SMEs directly. The result is not an encrypted file, it is a transfer sent voluntarily, approved by someone within the company, to an account that will be emptied within the hour.
How does the attack actually unfold?
The scenario is almost always the same, and it begins well before the first message.
The scammer first studies your company. Your public website gives away the name of the director, the head of finance, sometimes the full organisation chart and the format of e-mail addresses. Professional networks fill in the rest. A holiday announcement, a trade fair or a post about a business trip tells them the right moment to strike.
Then comes the message. It arrives from an address very close to the real one, with a letter changed or a slightly different domain, or from a genuinely compromised mailbox. The tone is that of an executive under pressure. The request is clear, the amount credible, the deadline short.
Finally, the pressure builds. If the employee hesitates, the scammer follows up, answers objections, adds a fake lawyer or notary to the conversation. Every exchange serves the same purpose: preventing verification through another channel.
The bookkeeper receives an e-mail signed by the director, who left on a business trip the day before. "Hello Sandra, I'm in meetings all day abroad, it's hard for me to call. We are finalising the acquisition of a competitor and I need to pay a deposit today. This is strictly confidential, the board has not been informed yet, please don't mention it to anyone for now. Our lawyer will send you the details. I'm counting on you." The address looks like the director's, except for one letter. Twenty minutes later, a "lawyer" sends a foreign IBAN and reminds her that the deadline expires at 5 p.m. Everything is in place: an authority you don't question, an urgency that forbids waiting, a secret that forbids asking a colleague to confirm.
The most discreet variant: the fake supplier
Fake supplier fraud is less spectacular and often more effective. Here, the scammer does not pose as the boss, but as a company you have worked with for years.
The message announces a change of bank details: a new bank, an internal restructuring, a change of factoring company. The invoice is sometimes genuine, intercepted from a compromised mailbox and resent with a single element changed: the IBAN.
This variant is formidable for three reasons. It involves no abnormal urgency, since it concerns a payment you were expecting anyway. It often involves usual amounts, which trigger no alert threshold. And it frequently goes unnoticed for weeks, until the real supplier sends its first reminder.
This is the mistake that cancels out the entire verification. The phone number shown in the e-mail or on the altered invoice belongs to the scammer, who will answer confidently and confirm the change. Only use the number you already had: the one in your supplier file, in a signed contract, or in previous correspondence. The same rule applies to the executive's phone number.
Why does it work? Authority, urgency, secrecy
These attacks do not succeed because employees are careless. They succeed because they activate three mechanisms we all carry, which reinforce one another.
Authority. A message from the director is not questioned in the same way as a request from a colleague. Refusing means taking a personal risk. Asking for confirmation implicitly casts doubt on the boss’s word. In a small organisation where the hierarchy is close, this weight is even stronger.
Urgency. A short deadline removes the time to think. Yet it is exactly during that time that doubt appears. A request to be handled before 5 p.m. leaves no room for “I’ll check tomorrow morning.”
Secrecy. This is the most important lever, and the most revealing one. The instruction of confidentiality has a single function: isolating the targeted person. As long as they cannot talk to anyone, they cannot be contradicted. A legitimate request never forbids you from mentioning it to the colleague at the next desk.
These three levers belong to social engineering, the same family of techniques as phishing. The difference is the level of preparation: here, the scammer knows your company by name.
What do the Swiss figures show?
Fraud is not a marginal threat. In the second half of 2025, it accounted for 52% of all reports received by the National Cyber Security Centre, or 15,090 fraud reports. The total number of voluntary cyber-incident reports reached 64,733 for 2025, up from 62,954 in 2024. These figures and how they are collected are covered on our page on cybercrime in Switzerland in figures.
For CEO fraud specifically, Swiss companies reported 605 cases to the NCSC during the first half of 2025, a record number, then 366 cases in the second half. Adding the two published periods together, this represents 971 reported cases over the year. This data appears in the NCSC’s 2025/II semi-annual report, published on 30 March 2026.
What these figures tell an SME director is simple. Fraud has become the leading category of reported incidents in Switzerland, far ahead of the purely technical attacks that get talked about more. In other words, the weakest link under pressure today is not your firewall, it is the person who prepares your payments. And one point deserves to be highlighted: these are only the cases reported voluntarily. Many companies report nothing, out of embarrassment or fear for their reputation. The real scale is therefore higher.
The organisational defences that stop the attack
No technical tool solves this problem alone. A spam filter reduces the volume, two-factor authentication limits mailbox compromises, but the final message remains a technically perfectly legitimate e-mail. The defence is procedural.
| Measure | In practice | What it blocks |
|---|---|---|
| Dual validation | Any transfer above a defined threshold requires two different people, including one who did not receive the initial request | Manipulation of a single isolated person |
| Callback to a known number | Any unusual request is confirmed by phone, using the number in the internal file, never the one in the message | E-mail identity spoofing |
| Written amount threshold | A cap amount beyond which the reinforced procedure applies automatically, without personal judgement | Negotiation and pressure on the employee |
| Control of IBAN changes | Any change of bank details follows a formal procedure with verbal confirmation and validation by a third party | Fake supplier fraud |
| The right to say no | A rule written and communicated by management: no employee will be penalised for verifying | The authority lever |
This last line is the one most often forgotten, and it may be the most effective. As long as verifying an instruction from the boss seems impolite, the procedure will keep being bypassed whenever pressure rises. It is up to management, and management alone, to remove this social cost. The sentence to spread is simple: “if you call me to verify a payment, you are doing exactly your job.”
"Any payment request that is urgent, confidential, or to a new account is confirmed by phone, on a known number, before it is executed." The word "confidential" must become a warning sign, not a reason to stay silent. A short, displayed rule is applied; a twelve-page policy stored in a binder is not.
What should you do if the transfer has already been sent?
The first hours decide everything. Act in this order, without waiting to fully understand what happened.
First call your bank, immediately, and request a recall of the funds. This is the only action that can still recover the money, and its window is measured in hours. Then file a complaint with the cantonal police. Report the case to the NCSC via its online form, which feeds national detection. Finally, check whether an employee’s mailbox or a supplier’s has been compromised, since a mailbox compromise often means other frauds are being prepared.
A word on internal attitude. The person who approved the transfer is a victim, not someone at fault. Questions of individual responsibility depend on internal instructions, the training received and the actual circumstances; they fall under employment law and deserve legal advice before any decision. In practice, a punitive reaction mainly produces one effect: next time, the alert will come too late.
Where to start this week
Three actions are enough to significantly reduce the risk, and none of them require an IT budget.
Write your payment procedure on a single page, with a specific amount threshold and the callback rule. Communicate it personally to the people concerned, stressing their right to verify. Then test it: send an unusual request yourself and see if anyone calls you back.
At the same time, enable two-factor authentication on all of the company’s mailboxes, which cuts off the access route most used for these attacks, and plan for regular awareness training for your teams. Start at the top: management is the primary target of this type of fraud, and it is also management that authorises its employees to verify, as we explain in training management first. Finally, make sure your response plan is ready before the incident, as described in our article on the first hours after an attack.
To gauge your overall exposure, the cyber check-up includes several questions on payment procedures. The other attacks targeting your employees are grouped in the Threats pillar, and protecting your data in the event of an incident also depends on the 3-2-1 backup rule as well as your FADP obligations.