CEO Fraud Simulation - Breacher.ai

CEO Fraud Simulation

The question is not whether someone would fall for it. It is whether your approval chain would stop it if they did.

An authorized simulation that impersonates a named executive across voice, video, email, and SMS, and runs a payment request through your real approval process. It tests the callback rule, the verified number policy, the wire threshold, and the second approver. No funds move at any point, and no individual is named in the report. What you get back is whether the chain held.

Cloned Voice Deepfake Video Callback Rule Wire Threshold Dual Approval No Money Moves

Written to be forwarded to your CFO.

Executive impersonation stopped being a writing exercise

78%
Of assessed organizations rated highly vulnerable, measured as the approval process failing rather than one person slipping
Source: Social Engineering Risk Index
63%
Of targets could not tell synthetic voice or video from the real thing while it was happening
Source: Breacher.ai engagement data
$450K
Average business loss per deepfake incident
Source: Regula Deepfake Trends 2024

You cannot prevent CEO fraud you have never tested

The control exists, it is written down, and it has never once been run against something that was trying to get past it.

Recognition beats procedure

A verification step is designed for a stranger. It performs very differently against a voice the person has heard in every quarterly meeting for four years. Familiarity does not disable the rule, it just makes following the rule feel rude.

Urgency is the whole technique

An adversary does not need to defeat your controls. They need the request to arrive at 4:50pm on a Friday, tied to a deal that closes tonight, from someone who does not usually ask twice. The control is skipped, not broken.

Awareness training does not measure

A completed module tells you someone watched a video about wire fraud. It tells you nothing about what the payments team does when the request is in front of them and the callback number is the one printed in the email.

Five links, each one a control that is supposed to catch it

The simulation walks the sequence a real campaign walks, and reports which link held.

1
Control: source verification

The instruction arrives

An email from a familiar name, or a Teams message, or a call. The request is plausible: an acquisition deposit, a supplier held on credit, a legal settlement. Your control here is whether the sender or caller identity is verified independently of the message itself.

2
Control: escalation policy

Urgency and confidentiality are established

The deal is sensitive, the deadline is today, and the request is not to be discussed with the wider team. Your control is whether confidentiality framing is itself treated as a red flag, or whether it successfully removes the second pair of eyes.

3
Control: verified number policy

A callback is offered, on the wrong number

The strongest link in most policies and the easiest to sidestep, because a callback offered by the requester feels like verification while being the opposite. Your control is whether the callback goes to the number in your directory or the number in the message.

4
Control: threshold and dual approval

The amount is set just where it needs to be

Sometimes above your threshold to see whether the second approver actually reviews or simply signs. Sometimes just below it, to establish whether your threshold is set where the risk is or where the paperwork is convenient.

5
Control: none, this is the finding

Approval is granted, and we stop

The moment approval is given, the simulation ends and records it. No payment instruction is issued, no banking system is touched, no vendor record is altered. You get evidence that the chain would have paid, without anything having been paid.

Where the same pretext runs against the IT service desk for access instead of money, that is AI vishing simulation.

Coordinated, not parallel

Real executive impersonation does not pick a channel. It uses one to make the next one believable.

Cloned Voice Call

An approved executive voice holding a live conversation, handling a question and a moment of doubt in real time. This is usually the link that converts, because hearing the person is treated as proof of the person.

Live ConversationApproved Likeness
Deepfake Video Meeting

A synthetic executive appearing in a Teams or Zoom call, on camera, responding to what is said. The scenario finance teams are told to be alert to and have never seen, which is why being told about it does not help much.

TeamsZoom
Email And SMS

The written trail a real campaign leaves: the initial instruction, the confirmation, the nudge when the payment has not appeared. Individually unremarkable, which is the point, because they are there to corroborate the call.

BEC PretextFollow-Up Pressure
OSINT Groundwork

Public sources establish who signs, who pays, who is travelling, and which supplier relationship is real enough to invoke. The pretext is built from what an adversary could find, because that is exactly what an adversary would use.

Public SourcesOrg Mapping
Vendor Payment Change

The quieter variant, and the more expensive one. A supplier updating bank details through your normal channel, testing whether a change of account gets the scrutiny a new payment would have received.

Supplier RecordsChange Control
Orchestrated Sequencing

Channels fire in an order chosen for effect, each one raising the credibility of the next, with timing tuned to your close calendar. Running them separately measures four things. Running them in sequence measures the one thing that happens in reality.

OSES OrchestrationTimed To Close

How the engagement runs

The executive impersonation scenario of OSES™, our orchestrated simulation framework. Same discipline on scoping, consent, and evidence as every other engagement, pointed at the approval chain rather than the inbox.

01
Scope & Consent
Executives approved in writing, approval chain and payment paths in scope agreed, abort conditions documented and signed
02
Research
Public sources map authority, reporting lines, supplier relationships, and the calendar pressure that makes a pretext land
03
Asset Generation
Voice and video assets built from consented material, with written pretexts matched to your finance vocabulary
04
Orchestrated Run
Channels sequenced through the approval chain, with the simulation stopping at the moment approval is granted
05
Findings
Which link held, which was skipped, and what to change in the procedure rather than in the people

Every engagement runs under signed authorization, with written consent from each executive whose voice or likeness is used, assets destroyed at close, and client names absent from all public material. For the video channel on its own, see deepfake simulation, and for how the channels are orchestrated, see the OSES simulation platform.

If you are the CFO reading this

This is a controls test, not a security exercise, and it is closer to what your internal audit function already does than to anything in the security budget. It answers one question: if a payment instruction arrived from you, today, with everything an adversary could learn about your company behind it, would the chain that sits between the request and the money have stopped it? No funds move at any point. Nothing touches a banking system, no supplier record changes, and no member of your team is named, ranked, or singled out in anything we hand back. The finding is about the procedure, and the remediation is a change to the procedure. It typically takes one thirty minute scoping conversation from your side, and it produces a document your auditor and your board will both accept without translation.

CEO fraud prevention, measured as a process

Reported at the organizational and process level. No named individuals, no departmental leaderboards.

Process hold rate

The headline. How often the documented approval procedure was followed end to end when a request arrived under pressure from a recognized voice. This is the number that goes in front of the board, and it is a number about the process rather than about anyone's judgement.

The chain, link by link

Which control caught the request, which was skipped, and at which point. If verification failed because the callback used the number in the email, that is a policy fix with a date on it, not a training topic.

Evidence that travels

Written once for the security team, the audit committee, and the external auditor, with methodology, authorization record, and scope included. Nobody has to rewrite it before it leaves the building.

For how your result compares against the wider dataset, see the Social Engineering Risk Index.

Organizations where an instruction can become a payment

Anywhere authority is recognized by voice and money moves on request.

Financial Services
Treasury and payment operations
Professional Services
Client funds and settlements
Manufacturing
Supplier payments at volume
Construction
Subcontractor and progress payments
Technology
Fast approval, distributed leadership

Common questions

Is this the same as BEC testing?

Business email compromise testing usually means a spoofed email and a click metric. This includes that email, but the email is rarely what carries the request over the line. The voice call that follows it, or the video call that confirms it, is what makes the request feel verified. If the engagement only tested the inbox, it would miss the part your people would actually believe.

Do you actually move money?

No. Never, under any scope. The simulation stops at the moment of approval and records that the approval was granted. No payment instruction reaches a banking system, no vendor record is altered, and no account details are changed. The finding is that the chain would have paid, evidenced without paying.

Who needs to authorize this?

Signed authorization from an executive sponsor, plus written consent from every executive whose voice or likeness is used. In practice the sponsor is usually the CISO with the CFO informed, or the CFO directly. Finance staff are not told in advance, because a warned approval chain is not the approval chain you run on.

How do you scope which executives are impersonated?

We start from what a real campaign would find: who is publicly visible, who has recorded audio available, and who holds enough authority that a request from them would not be questioned. That shortlist goes to you, you approve or remove names, and only approved individuals are used.

How is consent and likeness handled?

Voice and face assets are generated only from material the individual has consented to in writing, used only inside the agreed engagement window, and destroyed at close. Nothing is retained for reuse, nothing is used for another client, and no client name or executive identity appears in our public material.

Find out whether the chain would hold

Thirty minutes. We will walk your approval path from instruction to payment and mark the links worth testing first.

No funds ever move Nothing installed No individual named
Book a Demo

If the exposure you are worried about is the help desk rather than the payment run, start with AI vishing simulation.