Phishing, CEO fraud and deepfakes: the cyber threats targeting your company
Cybercriminals no longer attack systems, they attack business processes and people. What executives, sales teams and HR need to know.
Phishing today: more targeted, more convincing, more dangerous
The era of clumsy scam emails is over. Phishing is now personalised using AI: the attacker studies your social media, your website and your press releases to craft a message that fits your context precisely. This is what is meant by spear-phishing, and by whaling when executives are the target.
Warning signs: artificial urgency, a request for a payment or for sensitive information, and an email address that has been altered very slightly.
CEO fraud: how it actually works
CEO fraud, also known as business email compromise for payment orders, accounts for hundreds of millions of euros of losses in France every year. The classic scenario: an email or phone call impersonating the CEO or CFO requests an urgent and confidential transfer from an accountant or finance officer.
With voice and video deepfakes, it is now possible to clone an executive’s voice in seconds from a single interview. Finance teams have transferred millions after a video call with a convincingly faked executive.
In 2024, a Hong Kong bank lost 200 million dollars following a deepfake video conference with fake executives. Your company is not immune.
The six threats to know
| Threat | Main target | How to protect yourself |
|---|---|---|
| Spear-phishing | All employees | Training, regular simulations, multi-channel verification |
| CEO fraud | Accountants, finance, HR | Mandatory telephone verification procedure |
| Voice or video deepfake | Executives, finance decision-makers | Shared spoken passphrase, callback verification |
| Ransomware | The whole organisation | Backups, multi-factor authentication, phishing training |
| Supply chain attack | Through your providers | Cyber due diligence, contractual clauses |
| Business email compromise | All departments | DMARC, DKIM and SPF configured, training |
What each function should do
Executives and board
- Be wary of urgent and confidential requests, even from your own team
- Agree a verification passphrase with your CFO and your assistant
- Do not post your diary and travel plans on social media
Sales and presales
- Always verify the identity of a prospect requesting confidential documents
- Never share client data or commercial proposals without encryption
- Be wary of tenders that are suspiciously well targeted, they can be industrial espionage
HR and support functions
- Never change bank details by email without telephone verification
- Treat applications with attachments carefully, they can carry malware
- Use secure recruitment tools rather than a personal mailbox
Key figures
- 90 % of cyberattacks begin with phishing
- A 67 % rise in attacks targeting HR functions in 2024
- Average cost of CEO fraud: €300,000 per incident
- Average detection time: 207 days
- 3.4 million unfilled cybersecurity positions worldwide
Train your teams
Our CyberMasterClasses train executives, sales teams and HR to recognise and defeat these threats. 90 minutes, online, led by an expert.
Get the next publications.
One analysis per publication on cyber governance, resilience and compliance.
Take action in 90 minutes
Our CyberMasterClasses train executives, sales teams and HR on cyber issues, without technical jargon.
See the masterclasses