All insights

Wire fraud

The boss made the wire feel late before it was due

Published
October 1, 2026
Read
4 min
Desk
Coffr Content Desk

Executive impersonation fraud works by making a normal approval path feel too slow, too public, or too risky to question.

A finance employee reviewing an urgent executive payment request beside a wire approval checklist.

The message arrives near close. The sender name is familiar. The tone is clipped. A wire needs to go today, the invoice will follow, and the reason for secrecy sounds plausible enough to keep the thread small.

This is executive impersonation fraud in the form finance teams feel first. Not as a technical breach. As pressure. The attacker is trying to make delay look more dangerous than release.

The fraud starts as a management problem

The attacker does not need finance to misunderstand the payment. They need finance to obey a false deadline.

That is why the message often sounds like work. A deal is closing. Counsel is waiting. A supplier is upset. A confidential matter cannot be discussed widely. The senior person is traveling and cannot take a call.

None of those claims has to be unusual on its own. Finance teams live with exceptions. AP managers handle incomplete documents. Treasury leads move money under time pressure. CFOs ask for speed when the business needs it.

The fraud sits inside that habit.

The visible loss is the money. The quieter damage lands on people. A rushed fraudulent payment can pull an AP analyst, controller, or treasury manager into interviews, remediation calls, insurance files, and a long internal second-guessing of a decision made under authority. Even when the employee followed the culture, the employee may carry the blame.

A company that treats every pause as friction gives the attacker part of the script.

The pressure pattern to stop

The control has to recognize pressure before it reviews payment details. Treat certain words and conditions as release risks, not as normal color around the request.

For executive impersonation fraud, the warning signs are usually plain once the team has permission to name them.

  • Same-day release. The request says the payment must move now, before the usual review can finish.
  • Confidentiality. The sender tells AP or treasury to keep the thread small, avoid normal contacts, or not mention the payment to others.
  • Executive rank. The request appears to come from a CEO, CFO, founder, board member, or person claiming to act for one.
  • New money path. The beneficiary, bank account, routing details, payment country, or payment purpose is new or changed.
  • Channel shift. The instruction moves from email to text, from a company account to a personal account, or from a normal system to an informal message.
  • Verification avoidance. The sender gives a reason a callback, ticket, vendor record, or second contact cannot be used.
  • Emotional force. The request makes the employee feel disloyal, slow, or incompetent for asking a routine control question.

A checklist helps because it moves the employee out of a personal confrontation. The analyst is no longer saying, I do not trust you. The analyst is saying, this condition triggers the executive exception rule.

That difference matters.

Why the approval can look clean

Dual approval fails when both people approve the same fiction. The second signature is only strong if it tests the payment instruction, not the executive tone around it.

A controller may see the name, the amount, the coding, and the apparent business reason. A second approver may confirm that the payment is within authority. Neither may verify the beneficiary and bank account through a known channel.

The file then looks complete. The money still leaves under a false premise.

Callbacks have the same weakness when the team calls the number in the message, accepts a forwarded approval, or verifies with the person who brought the request instead of an independent record. Email banners have limits too. They help when the clue is visible. Executive impersonation often works because the context feels believable.

The stronger control separates two decisions. One decision is whether the business reason is approved. The other is whether the payment instruction is real.

Those should not collapse into one act because a senior person sounds impatient.

What changes before release

The useful change is small and uncomfortable: slow the executive request because it is executive. Put that rule in writing before the next message arrives.

For a CFO, this is a governance question. Staff need to know that a missed deadline caused by verification will be defended. If leaders punish control behavior when the request is real, staff will abandon the control when the request is fake.

For an AP manager, this is an operating question. The team needs a known channel list, a step-up rule for new or changed accounts, and a record of who verified what before release. A screen capture of an email is not the same as proof that the beneficiary was checked.

The approval checklist should ask where the instruction came from, whether the beneficiary or account changed, whether secrecy or time pressure was used, which known channel was used to verify the instruction, who performed the verification, and what evidence was retained.

Download the approval checklist and put it beside the next urgent executive payment. If urgency can change the route, urgency is part of the attack surface.

Questions practitioners ask

How does executive impersonation fraud usually reach AP?

It often arrives as an email, text, collaboration message, or call that appears to come from a senior leader or someone acting for that leader. The request pushes urgency, secrecy, or both.

Why can dual approval miss executive impersonation fraud?

Dual approval can miss the fraud when both approvers accept the same false premise. A second signature helps only if someone independently verifies the payment instruction through a known channel.

What should AP verify before releasing an urgent executive payment?

AP should verify the source of the instruction, the beneficiary, the bank account, any account change, the reason for the deadline, and the approval trail using records that are independent of the request.

What should CFOs tell staff about urgent executive requests?

CFOs should state plainly that staff are expected to pause and verify executive payment requests that trigger risk conditions. A delayed legitimate payment is easier to defend than a rushed fraudulent one.

Share and cite

XLinkedInRedditEmail

Community newsletter

The Trust Layer Briefing

CFOs, controllers, and AP leaders subscribe for weekly research on BEC vectors, ERP gaps, and payment instruction security.

One email each Thursday. No spam, one-click unsubscribe.

Practitioners can also request a seat on The Coffr Research Panel.