New: Account Recovery+ for Entra ID Read Now

Executive impersonation

Catch executive impersonation before it moves money or access

Attackers can clone an executive's voice and face, then call your help desk, your finance team, or an executive assistant with an urgent request. Trusona ATO Protect verifies the person behind the request on their mobile device before anyone resets a password, releases a wire, or signs off.

  • No selfie
  • No app download
  • No pre-registration
  • SOC 2 audited
Definition

What is executive impersonation?

Executive impersonation is a social engineering attack in which a criminal poses as a CEO, CFO, or other senior leader to get money, access, or confidential information. Attackers use spoofed email and caller ID, cloned voices, and deepfake video, and they aim the request at whoever can act on it fast, such as the IT help desk or the finance team.

Read: CEO fraud and executive impersonation

CEO fraud

Executive impersonation aimed at payments. The attacker poses as a senior leader and pushes finance to wire money or change a vendor's bank details.

Business email compromise (BEC)

The FBI's category for scams that compromise email accounts, phone numbers, or virtual meeting apps to push an unauthorized transfer. CEO fraud is one version of it.

Help desk impersonation

The attacker calls IT as an employee, often a senior one, to get a password or MFA reset. A successful call can end in account takeover (ATO).

Where it hits

Three ways attackers go after your executives

Attackers look for someone who will act on an executive's word without a second check, or they call the executive directly. That puts your help desk, your finance team, and your leaders themselves in range.

MFA reset · "CFO"Flagged

IT help desk

The locked-out executive

The caller says she's the CFO, traveling, locked out, and late for a board meeting. Your agent is measured on speed, and this is the most senior caller of the week. One reset hands the attacker one of the most privileged accounts in the company.

CISA's Scattered Spider advisory (AA23-320A) describes the group using voice calls to convince IT help desk personnel to reset passwords or MFA tokens.

MFA resetPassword resetPrivileged access
How Trusona stops it ATO Protect sends an identity verification to the caller's mobile device before your agent touches the account. A high-risk result escalates to security.
Wire · $1,450,000On hold

Finance and approvals

The urgent wire

A text from the CEO asks for a confidential wire before end of day. A call in the CEO's voice confirms it. Dual approval fails when the attacker fools both approvers, and a callback fails when it rings the attacker's number.

Wire transfersVendor bank changesPayroll changes
How Trusona stops it Exec Verify confirms executive-to-executive calls with a single-use Exec Verify Code. ATO Protect for Finance verifies the requester on their mobile device before the money moves.
Call from "IT"Code check

Your executives

The fake IT call

The attack also runs in reverse. A caller posing as IT phones your CEO, reports a problem with the account, and asks for a code or an approval push. The call sounds routine, which is the point.

VishingMFA push approvalCredential theft
How Trusona stops it Agent Verify gives your real help desk a single-use, time-limited Verify Code to share on the calls it places, so an executive can confirm the call before sharing anything.
Why it works

Why executive impersonation gets past your controls

Most checks confirm something an attacker can prepare before the call.

Caller ID

Spoofable

Attackers can spoof the number on the screen. A match says nothing about who holds the phone.

Voice and video

Cloneable

McAfee researchers produced a clone with an 85% voice match from three seconds of audio in one test (2023). In a 2025 iProov study, 0.1% of 2,000 US and UK consumers, told to look for fakes, identified every real and fake sample.

Knowledge questions

Researchable

The answers are often public. An executive's work history is on LinkedIn, and a conference agenda can show where they will be next week. Attackers look them up before they dial.

Callbacks and dual approval

Bypassable

A callback to the number in the request reaches the attacker, and a SIM swap hijacks the number on file. Two approvers can fall for the same deepfake.

$3.05B

reported lost to business email compromise in 2025, across 24,768 complaints

Source: FBI IC3 2025 report

86%

Wire transfer or ACH was the most frequently reported way BEC money moved

Source: FBI IC3 2025 report

11%

of 2025 intrusions with an identified entry point began with voice phishing, second only to exploits

Source: Mandiant M-Trends 2026

1,300%+

rise in deepfake fraud attempts during 2024, from about one a month to seven a day, across the 1.2 billion calls Pindrop analyzed

Source: Pindrop, 2025
On the record

What impersonation has already cost

January 2024$25M lost

Arup

A finance employee at Arup's Hong Kong office joined a video call with people who looked and sounded like the company's chief financial officer and colleagues. Every one of them was a deepfake. The employee approved 15 transfers worth about $25 million.

Source: CNN, May 16, 2024
September 2023About $100M

MGM Resorts

MGM's chief executive, Bill Hornbuckle, said the tech call center was "the layer that got engineered" in an attack he described as "partially socially engineered." MGM put the impact at roughly $100 million on its third-quarter 2023 results.

Sources: Las Vegas Review-Journal, October 10, 2023; MGM Resorts, Form 8-K, October 2023

Both attacks worked on people doing their jobs: a finance employee following what looked like the CFO's instructions, and a call center trying to help. ATO Protect gives those people a check that does not depend on a hunch.

How ATO Protect stops it

Verify the person before anyone acts

The check runs on the mobile device, off the call, so it does not depend on how the caller looks or sounds.

  1. 1

    Service request initiated

    An executive, or someone claiming to be one, asks for a reset, a wire, or an approval.

  2. 2

    Verification sent

    Your agent or approver sends an identity verification to the person's mobile device. It runs in the mobile browser, with no app to download.

  3. 3

    Trusona checks the person

    ATO Protect checks the government ID with the authority that issued it and runs SIM swap and man-in-the-middle detection.

  4. 4

    Your agent gets a precise response

    A verified result lets the request move ahead. A high-risk result escalates to security.

    VerifiedHigh risk
No selfie or liveness checkGenerative AI can now defeat those methods.
No app, no pre-registrationIt works the first time someone needs it.
No PII storedTrusona stores no PII and is SOC 2 audited.
No integration requiredStart in the web portal, or connect through ServiceNow or the ATOP API.
"We utilize ATO Protect identity verification alongside our verbal wire confirmation protocol to ensure secure transfers of significant funds to our investors and our portfolio companies. It provides an exceptional level of security and confidence by confirming the identity of the recipient before we initiate any transactions."
Agnes SoCFO, Ballistic Ventures
The category

Executive impersonation is an identity problem

Workforce Identity Impersonation Detection (IID) asks whether the human behind a request is who they claim to be, at the moment they ask for something that matters. Trusona is the company that created Identity Impersonation Detection.

FAQ

Executive impersonation questions

What is executive impersonation?
Executive impersonation is a social engineering attack in which a criminal poses as a CEO, CFO, or other senior leader to get money, access, or confidential information. It includes CEO fraud, help desk calls from a fake executive who needs a password or MFA reset, and deepfake voice or video calls that push employees to approve a request.
How is executive impersonation different from CEO fraud and BEC?
CEO fraud is executive impersonation aimed at payments. Business email compromise (BEC) is the FBI's broader category: its 2025 annual report describes fraudsters compromising email accounts and other forms of communication, such as phone numbers and virtual meeting applications, to move money. Executive impersonation also covers attacks that go after access, such as a fake executive asking the help desk for an MFA reset.
Isn't executive impersonation just account takeover?
An account takeover (ATO) can begin with executive impersonation. When an attacker talks your help desk into resetting an executive's MFA, the attacker takes over one of the most privileged accounts in the company. ATO Protect stops the takeover at that first request.
Why do attackers target the IT help desk with executive impersonation?
Help desk agents want to solve a senior leader's problem fast, and executive accounts carry broad access. CISA's advisory on Scattered Spider (AA23-320A) describes the group using voice calls to convince IT help desk personnel to reset passwords or MFA tokens.
Can deepfakes impersonate an executive on a video call?
Yes. In January 2024, a finance employee at Arup's Hong Kong office joined a video call where the CFO and every other participant were deepfakes, then approved 15 transfers worth about $25 million. Seeing and hearing an executive on a call no longer proves you are talking to that executive.
Are we at risk if our executives aren't public figures?
Yes. McAfee researchers produced a clone with an 85% voice match from three seconds of audio in one test (McAfee Labs, 2023). A webinar, a podcast, a voicemail greeting, or a LinkedIn video gives an attacker audio to work with.
How does Trusona stop executive impersonation?
ATO Protect sends an identity verification to the person's mobile device when someone asks for a reset, a wire, or an approval, and checks their government ID with the authority that issued it. The verification happens on the device, off the call, so a cloned voice or spoofed number does not change the result. Exec Verify confirms executive-to-executive calls with a single-use code, and Agent Verify lets employees confirm that a call from IT is real.
Does ATO Protect use selfies, liveness checks, or voice matching?
No. ATO Protect runs no selfie or liveness check, because generative AI can now defeat those methods. It also ignores how the caller sounds: the verification happens on the mobile device, not on the call. It needs no app download or pre-registration, and Trusona stores no PII.
What should we do if a payment already went out?
Call your bank right away to request a SWIFT recall or ACH reversal, file a complaint with the FBI's Internet Crime Complaint Center (IC3) the same day, and contact the receiving bank. Then treat the impersonated account as compromised and revoke its sessions. Trusona's CEO fraud guide walks through the full response.
Stop executive impersonation

Know who is on the other end

See how ATO Protect, Exec Verify, and Agent Verify confirm the person behind a reset, a wire, or a call to one of your executives.

Verified. Audited. SOC 2.

trusona icon
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.