Business Email Compromise (BEC / CEO Fraud)
Business Email Compromise (BEC / CEO Fraud): A scammer impersonates a CEO, supplier or executive (often by spoofing or hacking the real email account) and instructs the finance team to wire money urgently to a "new account". The wire goes to the scammer.
Details
How the scam works: A scammer impersonates a CEO, supplier or executive (often by spoofing or hacking the real email account) and instructs the finance team to wire money urgently to a "new account". The wire goes to the scammer.
Many of these scams rely on victims trusting a forged MT103 / pacs.008 PDF without verifying. Ohmyfin lets anyone — for free, with no bank login — look up any UETR in seconds. If a "proof of payment" UETR cannot be found by Ohmyfin, the document is almost certainly fraudulent.
If you believe you have been targeted by this scam, report immediately to: (a) your bank's fraud line, (b) the receiving bank's fraud line, (c) your local police / financial regulator (FBI IC3 in the US, Action Fraud in the UK, AFP in Australia, Europol in Europe).
Key facts
- Red flags:
- ⚠ Urgent wire request from CEO / CFO / supplier — often outside normal hours
- ⚠ New beneficiary account "just for this transaction"
- ⚠ Pressure not to call or verify ("I'm in a meeting", "It's confidential")
- ⚠ Slight email-domain misspelling (acmecorp.com vs acmec0rp.com)
- How to protect yourself:
- ✓ ALWAYS verify any new payment instruction by phone (not reply email) using a known number
- ✓ Implement a dual-approval rule for any new beneficiary or any wire above a threshold
- ✓ Train finance staff to recognise BEC pretexts
Frequently asked questions
What is Business Email Compromise (BEC / CEO Fraud)?
A scammer impersonates a CEO, supplier or executive (often by spoofing or hacking the real email account) and instructs the finance team to wire money urgently to a "new account". The wire goes to the scammer.
How can Ohmyfin help me avoid this scam?
Most SWIFT-payment scams rely on victims accepting a forged MT103 or pacs.008 PDF without verifying. Paste the UETR from any "proof of payment" into the Ohmyfin homepage tracker — if the UETR cannot be located in the SWIFT network, the document is almost certainly fake.
Where do I report this scam?
Contact your bank's fraud line immediately, then your local financial regulator and police. For cross-border fraud, file with the FBI IC3 (US), Action Fraud (UK), the AFP (Australia), or Europol (EU).
Can I recover the money if I have already sent it?
Sometimes. Contact your bank within hours and request a SWIFT recall. Success rates are highest when reported within 24h. After several days the funds are usually unrecoverable.
Related — more from swift payment scam alerts and beyond
Get 100 free credits — track unlimited SWIFT payments
No card needed. Free for ordinary users — 10 free trackings per day per IP, no signup required. Track any international wire across 11,000+ banks.
Track a payment now — completely free Or try the tracker now →