CEO fraud, payment diversion, fake buyer fraud: how social engineering targets human decisions

Want to know how CEO fraud, payment diversion and fake buyer fraud could impact your business? At the core of these modern fraud schemes lies social engineering - a tactic that exploits the human factor within organisations.

This article outlines what social engineering is, shows how it is used in common fraud scenarios, and highlights patterns to watch for. Understanding these tactics is the first step toward protecting your business from these sophisticated threats.

Summary

  • Social engineering underpins CEO fraud, payment diversion and fake buyer fraud by manipulating people, trust and routine processes rather than hacking systems.
  • Social engineering underpins CEO fraud, payment diversion and fake buyer fraud by manipulating people, trust and routine processes rather than hacking systems. Fraudsters use tactics such as authority, urgency, trust and fear of blocking business, following a similar lifecycle: investigation, entrapment, attack and exit.
  • Once a trusted employee approves a transaction, systems will usually execute it - which is why understanding how these schemes work and spotting their patterns is essential to building effective protection.

Modern fraudsters rarely start with code – they start with people. Instead of trying to break your systems, they try to bend your decisions.

60% of breaches involve a human element¹. CEO fraud, payment diversion, and fake buyer fraud all have one thing in common: they use social engineering to manipulate trusted employees into approving payments, changing bank details, or releasing goods. Even when your IT security is robust, a single human decision can bypass multiple layers of technical control and internal policy.

In the following sections, you’ll see what social engineering is, how it underpins CEO fraud, payment diversion and fake buyer fraud, and why it is so successful at exploiting the human factor in organisations.

Social engineering is the practice of manipulating people into taking actions they would normally avoid. In a business context, the goal is often to:

  • Convince someone to approve a payment,
  • Change bank account details,
  • Release goods on credit,
  • Share confidential information or credentials.

Fraudsters carefully study your organisation, your hierarchy, and your communication style. They then craft messages and scenarios that sound, look and feel familiar and legitimate.

They exploit four main levers of human behaviour:

  • Authority - “This is the CEO / CFO / Director asking.”
  • Urgency - “We must act now or lose the deal.”
  • Trust - “This is your regular supplier / customer / colleague.”
  • Fear of blocking the business - “If you delay, you’ll be responsible for a missed opportunity.”

There are many types of social engineering attacks – such as baiting (offering something attractive to trick users), whaling (targeting top executives via professional and personal communication channels), phishing (mass fraudulent emails), spear phishing (highly targeted, personalised emails), and smishing (phishing via SMS) – but the underlying principle is always the same: using psychology to make people override their usual caution.

Most social engineering attacks follow a simple lifecycle:

  1. Investigation - gathering information about your company, people, and processes.
  2. Entrapment - building contact and trust, often via email, phone, or messaging.
  3. Attack - triggering the key action: a payment, a bank detail change, or the release of goods or data.
  4. Exit - covering tracks, withdrawing funds, disappearing, and preparing the next attack elsewhere.

Once a trusted person approves a transaction, your systems usually do exactly what they are supposed to do even if that means executing a fraudulent payment or shipping goods to a fraudster.

To make these mechanisms more tangible, let’s look at some concrete, common cases where social engineering is used against companies.

CEO fraud: exploiting hierarchy and urgency

CEO fraud is a targeted scam in which criminals impersonate a senior executive or decision‑maker to trick employees into making urgent, unauthorised payments.

The typical goal is to convince someone in finance, treasury, or accounting to transfer funds to a fraudulent account.

How this scheme typically unfolds:

  • An email, message or call appears to come from the CEO’s address, or a very similar one.
  • The request is labelled as confidential, time sensitive, or linked to a strategic deal.
  • The employee is asked to bypass normal procedures: “Don’t involve anyone else”, “Handle this personally”.

The communication often appears to come directly from the CEO, CFO, or high-ranking manager, and plays on hierarchy, urgency, and confidentiality. If the employee complies, funds are transferred to the fraudster’s account, with minimal chances of recovering the money.

Why CEO fraud works

  • Employees are conditioned to respect hierarchy and respond quickly to senior leaders.
  • Urgency and confidentiality make it socially hard to push back or ask questions.
  • The message often arrives at busy times (end of day, month‑end, holidays).
  • Attackers may have gathered details from social media, company news, or previous emails to make the story credible.

Payment diversion: redirecting legitimate payments

Payment diversion (also called “invoice fraud” or “mandate fraud”) aims to divert genuine payments to a fraudulent account by manipulating your trust in suppliers or customers.

The typical goal is to convince someone in accounts payable or finance to:

  • Update bank details for a supplier or creditor.
  • Pay a real invoice to a new, fraudulent account.
  • Accept a “one‑off” bank change for a specific highvalue payment.

How this scheme typically unfolds:

  • A fraudster either compromises a genuine supplier email account or uses a very convincing lookalike email address to request a bank detail change. Some may also use other channels such as phone, letter or even messaging apps to pass on the new, fraudulent bank details.
  • Your accounts team receives a message that appears to come from the supplier’s finance department, announcing new bank details.
  • The request looks professional and familiar, often including the correct supplier name, reference numbers, logos, and signatures copied from real documents, along with plausible reasons like a "bank merger" or "internal reorganisation."
  • The email asks that all future invoices or a specific urgent invoice be paid to the new account.

If the change is accepted without independent verification, your next legitimate payment is sent straight to the fraudster’s account.

Why payment diversion works

  • Bank detail changes are often treated as administrative updates, not high‑risk events.
  • Staff may trust email as a primary channel and skip additional verification.
  • The request is embedded in an otherwise normal process (paying a routine invoice).
  • The fraud may only be detected weeks later, when the real supplier chases unpaid invoices.

Fake buyer fraud: exploiting sales and credit approvals

Fake buyer fraud targets your sales and delivery processes. Criminals pose as genuine customers - either by imitating an existing client or by presenting themselves as a well-known company – to obtain goods on credit and disappear without paying.

The typical goal is to convince your sales and credit teams to:

  • Accept a large order on open terms or extended credit.
  • Deliver goods to a location controlled by the fraudster.
  • Trust a buyer identity based on brand recognition and convincing details.

How this scheme typically unfolds:

  • Fraudsters impersonate regular customers or reputable companies, often registering domain names that closely resemble the real customer’s (e.g., changing one letter or adding a hyphen).
  • They contact your sales team using a real buyer’s name or a plausible contact with a similar email address and place large orders.
  • Delivery addresses appear legitimate, and references or PO numbers look authentic, leading your credit team to approve the order under normal terms.
  • The goods are delivered to the specified location, controlled by the fraudsters, who then vanish with the goods without making any payment.

Everything appears routine. Only when the invoice remains unpaid and your receivables team contacts the real customer the fraud becomes clear: they never placed the order, and the email address is not theirs.

Trade Credit Insurance doesn’t cover payment defaults resulting from buyer fraud, since it stems from a fraudulent action and not a valid business debt.

Why fake buyer fraud works

  • It closely mimics normal, profitable business with a reputable name.
  • It leverages your trust in established customers and recognised brands
  • It uses realworld details (names, past orders, addresses) to overcome suspicion.
  • The loss is often discovered late, when recovery of goods is no longer possible.

Business Email Compromise (BEC) is a broader category that underpins many of the attacks described above. In BEC, criminals gain control over, or convincingly impersonate, a legitimate business email account to influence payments and approvals.

Typical goal:

  • Insert themselves into real email conversations,
  • Misuse trust in known names, brands or roles (e.g. “CEO”, “key account”)
  • Manipulate payment details or instructions,
  • Steer money or information to accounts they control.

Typical pattern:

  • An employee, supplier, or customer falls for a phishing email and enters their credentials on a fake login page, or clicks a malicious link.
  • The attacker logs into the genuine mailbox and silently monitors email traffic over days or weeks.
  • They learn how your teams communicate, which invoices are due, how orders are placed, who approves payments, and which relationships are critical.
  • At the right moment such as before a large invoice is paid or a big order is approved the attacker intervenes within an existing email thread, using the real account or a convincing spoofed address to provide fraudulent payment details, request urgent transfers, amend orders, or send altered invoices.

Because the message is part of a real, ongoing conversation, it appears trustworthy. If your team implements the change without independent verification, the payment or the goods will be diverted to the fraudster. According to the FBI, $2.7 billion² in losses were caused by BEC worldwide in 2024.

Strengthening your defences starts with combining people, processes, and the right tools, because no single measure is enough on its own.

Here are the key steps worth putting in place:

  • Run regular security awareness training: Make sure your team can spot social engineering scams, phishing attempts, and impersonation tactics before they cause harm. Role-specific training works best.
  • Add multi-factor authentication (MFA): MFA gives your online accounts and computer network an extra layer of security, making it significantly harder for attackers to gain access even if credentials are stolen.
  • Enforce strict payment verification workflows: Any request to change bank details or approve an urgent transfer should require independent, out-of-band confirmation, regardless of who appears to be asking.
  • Control access carefully: Apply least-privilege principles so employees only access what they need. This limits the damage if an account is compromised.
  • Stay current on emerging threats: Tactics evolve fast, from scareware to USB drives left in parking lots loaded with a form of malware. Keeping your team informed reduces vulnerability.

Social engineering attacks – such as CEO fraud, payment diversion, fake buyer fraud, and Business Email Compromise (BEC) - all exploit the same vulnerabilities: people, trust, and routine processes. Understanding how these schemes operate and identifying their patterns is a critical first step in order to develop effective protection strategies.

Even with strong processes in place, social engineering attacks can still get through, and when they do, the financial impact can be severe.

Allianz Trade Business Fraud Insurance covers direct financial losses from both internal and external fraud, including social engineering schemes like CEO fraud, payment diversion, and fake buyer fraud.

Beyond the direct losses, the cover also extends to legal fees, contractual penalties, reputational damage support, and business operation continuation costs for up to six months after an incident. If fraud occurred before your policy started but you discover it while insured, you're still covered, and with unlimited retroactive cover available.

You also get access to a dedicated team of fraud specialists who can assess claims and support you through the aftermath, so you're never left to handle it alone.

Get in touch today for your free, no-obligation Business Fraud Insurance consultation. Arrange a call-back.

A social engineering attack is when cybercriminals manipulate people, rather than systems, into handing over sensitive information like passwords, personal data, or credit card numbers. Instead of breaking through technical defences, attackers exploit human error by building false trust or creating a sense of urgency. Common tactics include phishing emails, pretexting, and phone calls impersonating trusted entities. It targets your people, making it one of the hardest cyber threats to defend against.

Phishing is a specific type of social engineering. Social engineering is the broader category, covering any manipulation tactic used to deceive individuals, whether that's impersonation, pretexting, tailgating, or baiting, and it can happen digitally or in person. Phishing sits within that category and focuses specifically on deceptive messages (such as emails, text messages, or fake social media contact) to steal credentials or sensitive data. So while all phishing is social engineering, not all social engineering is phishing.

CEO fraud is one of the most common examples of social engineering targeting businesses. A scammer impersonates your CEO via email, creates a sense of urgency around a confidential payment, and pressures a finance team member into transferring funds to a fraudulent account before anyone can verify the request.

Payment diversion is another frequent case. Here, a hacker poses as a trusted supplier and sends updated bank details, redirecting a legitimate payment away from the real recipient.

Both are targeted forms of phishing that rely on social engineering techniques, but they differ in who they go after.

Spear phishing targets specific individuals or teams, such as finance staff, IT admins, or anyone with system access or approval authority. Attackers do their homework first, using social media profiles or company websites to craft convincing, personalised messages. The goal is usually to steal credentials, trigger fraudulent payments, or gain a foothold in your network.

Whaling takes the same approach but aims exclusively at high-value targets: your CEO, CFO, or board members. Because these individuals can authorise large transfers or access highly sensitive information, attackers invest far more preparation. Messages are often sophisticated enough to reference real projects or ongoing deals.

Phishing uses deceptive messages to trick large numbers of people into clicking malicious links, handing over credentials, or downloading malicious software. It relies on urgency and volume, casting a wide net.

Pretexting takes a more targeted approach. The attacker builds a fabricated story to gain your trust directly, often through phone calls or personalised messages. According to Verizon's 2024 Data Breach Investigations Report, pretexting now accounts for more than 40% of social engineering incidents.

Spear phishing targets a specific individual using a personalised, spoofed email. Attackers research their victim first, often through social networking sites or company websites, to craft a convincing message that can request credential access, fraudulent payments, or infected files downloads.

Vishing extracts sensitive information or authorising a transaction over a live call. Attackers impersonate bank representatives, IT support, or senior executives, using urgency and authority to pressure victims into revealing data like passwords or date of birth, or to approve a transfer.

Receive our latest economic and insolvencies updates from our experts.
Follow us

You might also be interested in…

For a free credit insurance consultation call our UK team, 09:00-17:00 Mon-Fri.
People discussing on a coach

Allianz Trade is the global leader in trade credit insurance and credit management, offering tailored solutions to mitigate the risks associated with bad debt, thereby ensuring the financial stability of businesses. Our products and services help companies with risk management, cash flow management, accounts receivables protection, Surety bonds, Business Fraud Insurance,  debt collection processes and  e-commerce credit insurance ensuring the financial resilience for our client’s businesses. Our expertise in risk mitigation and finance positions us as trusted advisors, enabling businesses aspiring for global success to expand into international markets with confidence.

Our business is built on supporting relationships between people and organisations, relationships that extend across frontiers of all kinds - geographical, financial, industrial, and more. We’re constantly aware that our work has an impact on the communities we serve and that we have a duty to help and support others. At Allianz Trade, we’re strongly committed to fairness for all without discrimination, among our own people and in our many relationships with those outside our business.