CEO fraud and fake invoices
Urgent requests from a spoofed or look-alike address to finance staff or suppliers, often timed for travel days and quarter ends.
BEC investigations →Executive impersonation turns a leader's name, face or voice into a payment instruction or an investment pitch. We investigate each incident across the channels it used, preserve the evidence before it disappears, trace the accounts, numbers and domains to the operators and help you close the gaps that made the scam believable.
An executive impersonation investigation looks at a scam that uses a real leader's identity, whether by email, messaging app, cloned voice, fake video call or fake profile, and establishes what happened, which infrastructure the scammers used and what else it connects to. OSINT-S preserves the evidence, traces the operators from open sources and delivers a report your bank, the platforms, police and counsel can act on.
Two audiences, five channels. Inside the company the goal is a payment or data; outside it, the goal is the public's money or trust.
Urgent requests from a spoofed or look-alike address to finance staff or suppliers, often timed for travel days and quarter ends.
BEC investigations →A new number with the CEO's photo asks a manager to keep a deal confidential and buy gift cards or move funds.
A short call or voicemail in a leader's voice, built from interviews, earnings calls or conference videos.
A meeting invite where the executive and colleagues on screen are synthetic or replayed, used to approve a transfer.
Deepfake detection →Ads and posts showing a founder recommending an investment, or profiles of executives used to recruit victims.
Investment scam investigations →Reported losses to business impersonators reached nearly $1 billion in the US in 2025, and the FTC rule explicitly covers posing as a company's officers.
The rule gives the FTC a route to civil penalties and redress; it does not give companies a private claim. What a company can do is put a complete, well-sourced file in front of the platforms, banks, police and regulators that can act.
We work from what the scam left behind: recordings, numbers, meeting links, accounts and the public material the clone was built from.
| Artifact | What we check | Why it matters |
|---|---|---|
| Voicemail or call recording | Phrases and intonation matched to public interviews and videos of the executive | Shows which public material was used, and what to restrict |
| Caller number | Number type, carrier, messaging-app profiles and prior scam reports | Links the call to other incidents and supports a carrier or police request |
| Meeting invite and link | Sender domain, account names, registration dates of linked domains | Separates a compromised account from an outside look-alike |
| Video stills | Background, clothing and framing matched to past public footage | Identifies replayed or synthetic footage and its source |
| Payment instructions | Beneficiary name, bank, crypto addresses and their public history | Gives the bank and police a recall and tracing starting point |
Technical analysis of whether audio or video is synthetic runs as deepfake detection; this page covers who ran the scam and what it connects to.
Stop the money, preserve the evidence, map the infrastructure, warn the right people, then close the gaps.
An incident report, an infrastructure map, evidence packs per recipient and a short list of fixes. A single urgent incident can often be documented within a business day.
A single live incident, such as fake messages from the CEO to the finance team this morning, can often be documented within a business day of agreeing scope. A full investigation across several channels and incidents takes from 10 business days, and a campaign targeting the public in several countries up to about a month. Urgent delivery costs 50% more, a senior analyst reviews every report, the quote is fixed after written scoping and the fee goes down if we miss the agreed date.
We use public and lawfully obtained information only. We do not hack scammers' accounts, call them under false identities or buy leaked data, and we handle the executive's and staff's personal data under the GDPR and similar laws. Attribution to a named person is not always possible with organized groups, and the report states the confidence of each link. To shrink what impersonators can copy, pair this work with an organizational OSINT exposure audit; for leaders who also face threats, see executive protection. It is part of the OSINT services for security and legal teams we provide.
Tell us which executive was impersonated, through which channels, and whether money moved. We confirm scope the same day where we can and give you a fixed quote.
We can establish what the scammers used and what it connects to: the number and its history, the messaging profile, the payment details they gave and the public recordings the voice was likely cloned from. Those links often tie the incident to other scams and sometimes to named people. If money moved, ask your bank for a recall and report to police first; our report then supports both.
Keep the meeting invite with its full email headers, the meeting link and platform account names, any chat messages, recordings or screenshots, the payment instructions and a note of who attended and when. Do not delete the accounts involved. We preserve that material with timestamps and hashes, trace the sender and the linked domains, and identify which public footage the video likely came from.
We document each ad and its landing pages, then trace the domains, apps, wallet addresses and advertiser accounts behind them. That evidence supports impersonation reports to the platforms and, where the public lost money, police and regulators. Identifying the people who pay for ads is sometimes possible from public data and sometimes needs platform records through legal process; the report says which applies.
The rule is enforced by the FTC, which can seek civil penalties and redress in federal court; it does not create a private right for companies to sue. It does make clear that posing as a business or its officers is unlawful. Your counsel may still have claims under trademark, fraud or other laws, and a well-documented OSINT report is useful for either route.
Most protection comes from process: a call-back rule on a known number for any payment change, two approvers for urgent transfers and a verification phrase for sensitive requests. On the exposure side, we list the details scammers rely on, such as travel posts, assistant names and long voice recordings, and suggest proportionate changes, so leaders can stay visible without handing over a script.
If no money moved and the scam stopped, a short documented check is often enough: confirm what was used, whether other staff or suppliers were targeted, and whether the same accounts appear in other scams. A full investigation makes sense when there were losses, repeat attempts, public-facing scams using the executive's name, or a legal or insurance claim that needs evidence.
Sources checked 10 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.