CEO fraud in Switzerland: how it works and how finance can stop it
CEO fraud in Switzerland: what finance teams need to know
CEO fraud in Switzerland is a social-engineering scam in which someone pretends to be your chief executive or another senior manager and pushes the accounts payable team to make an urgent bank transfer or change payment details. The message often arrives by email or messaging app, stresses secrecy and claims the boss is in a meeting or travelling. Swiss reporting files this pattern under business email compromise and fraud. It is not a malware problem on its own but a process and verification problem, and it hits companies with 20 to 250 staff as often as larger firms, because one person in finance can still release a payment.
BACS reports that offenders research their targets on LinkedIn, company websites and the commercial register, and increasingly use AI-written text and, in some cases, synthetic voice. Fraud made up 52 percent of reports in the second half of 2025 (BACS half-year report). Deloitte’s 2026 study of firms under 250 employees puts CEO fraud at 8 percent among the most frequent attack types.
CEO-fraud reports to BACS in 2025, up from 719 in 2024. Source: BACS weekly review “Dringende Überweisung”, not our survey.
Whether training is legally mandatory for your company is a separate question. Many teams start after a near-miss, as described in our article on whether security awareness training is mandatory in Switzerland.
Who attackers contact first
Offenders pick roles that prepare or release payments, and people close to leadership. In Swiss SMEs that is often accounts payable, the finance clerk, an executive assistant or whoever approves supplier invoices. Sometimes the target is new and does not yet know how the chief executive normally behaves. Public sources supply the material: who posted about a conference on LinkedIn, who signs in the commercial register, which email addresses appear on the website.
You handle supplier payments
A message demands a confidential transfer to a “new adviser” or an emergency supplier.
You assist the executive team
The tone feels personal, and you are asked to bypass the usual approver.
You alone handle small amounts
The sum looks “small enough” for nobody to check, until several payments follow.
How CEO fraud usually unfolds
CEO fraud typically runs in four stages. First, the attacker collects names, roles and travel patterns from public sources. Second, they send a message that seems to come from the executive, sometimes from a look-alike domain or a compromised mailbox. Third, they ask for a confidential transfer, a payment to a new supplier or an exception to the normal approval rules. Fourth, if nobody checks through a second channel, the payment goes out and the money is hard to recover.
Some cases add pressure: “only you can do this today”, “do not call me, I am in negotiations”, or a follow-up from a supposed lawyer or auditor. BACS also describes cases where offenders pose as a Swiss law firm. In others, a real account inside the firm has been taken over, so the email passes technical checks and looks genuine. That overlaps with invoice fraud, where the IBAN changes. This article is about the fake urgency from “the boss”.
Stop rules before money leaves the firm
Train finance and assistants to pause when several of these appear together: a payment request only by email or chat, no purchase order or contract reference, a new beneficiary or changed bank details, an instruction to skip the usual approver, or a chief executive who normally never orders payments directly. The language may be fluent but slightly off, or flawless because a machine wrote it.
BACS recommendations for business email compromise include a call-back, raising awareness in the finance department, two-factor authentication on email accounts and clear payment workflows. In the end, someone has to refuse to pay until the request is verified.
- Call back on a number from your own records, not from the suspicious message
- Do not pay when the usual approver would have to be skipped
- Handle new bank details only through your normal master-data process, never by mail
- Keep the message and tell IT before you reply
What CEO fraud is not
CEO fraud is not ordinary phishing that steals a login, and it is not ransomware locking files. For most SMEs it is also not a statutory cyberattack report to BACS: the federal reporting duty from 1 April 2025 applies to operators of critical infrastructure, which excludes a typical trading or services company with a few dozen staff. You may still report voluntarily to BACS, and if money moved you should involve your bank and the police.
Another antivirus licence will not solve it on its own. Technical measures help, but they do not replace clear approvals and a quick word with a colleague when something “does not fit”.
Typical of CEO fraud
- Urgency from “leadership”
- Secrecy and a process exception
- New beneficiary or unusual amount
Other fraud patterns
- Invoice with changed IBAN from a compromised supplier mailbox
- Gift-card purchases instead of a bank transfer
- Password theft without a payment order
What to do first if a payment looks wrong
If someone in finance has received a message like this and has not paid yet, keep the message, tell IT or your external IT partner, and verify with the supposed sender through your usual phone directory or in person. If the payment has already left, contact the bank immediately to attempt a recall, document times and amounts, and report it to the police. BACS publishes guidance on business email compromise for Swiss companies.
Inside the firm, treat it as a security incident. Hold a short debrief with leadership, tighten the approval rules if they were too thin, and consider whether staff need a focused session on payment fraud. A live security awareness session can walk through CEO fraud, invoice manipulation and how to report odd messages without blaming the person who almost paid.
Can small Swiss companies be targeted for CEO fraud?
Yes. Attackers use public information and run their campaigns at scale. Size does not protect you if one person can release payments without a second check.
Must the chief executive confirm every urgent email?
No. Define which payment types need a call-back or a second approval. Real emergencies happen, but they rarely arrive only by email with no number you already hold on file.
When a short awareness session helps
If your team handles supplier payments or executive assistants see urgent requests, a one-off live session on fraud patterns can align finance, HR and the management assistant on the same stop rules. Details of the Aurum format are on the security awareness training page.
Written by
Aurum Avis Labs
Builds and ships at Aurum Avis Labs. Writes here about what we learn working with founders and SMEs in the DACH region.