What is executive impersonation?
Executive impersonation is a social engineering attack in which a criminal poses as a CEO, CFO, or other senior leader to get money, access, or confidential information. It includes CEO fraud, help desk calls from a fake executive who needs a password or MFA reset, and deepfake voice or video calls that push employees to approve a request.
How is executive impersonation different from CEO fraud and BEC?
CEO fraud is executive impersonation aimed at payments. Business email compromise (BEC) is the FBI's broader category: its 2025 annual report describes fraudsters compromising email accounts and other forms of communication, such as phone numbers and virtual meeting applications, to move money. Executive impersonation also covers attacks that go after access, such as a fake executive asking the help desk for an MFA reset.
Isn't executive impersonation just account takeover?
An account takeover (ATO) can begin with executive impersonation. When an attacker talks your help desk into resetting an executive's MFA, the attacker takes over one of the most privileged accounts in the company. ATO Protect stops the takeover at that first request.
Why do attackers target the IT help desk with executive impersonation?
Help desk agents want to solve a senior leader's problem fast, and executive accounts carry broad access. CISA's advisory on Scattered Spider (AA23-320A) describes the group using voice calls to convince IT help desk personnel to reset passwords or MFA tokens.
Can deepfakes impersonate an executive on a video call?
Yes. In January 2024, a finance employee at Arup's Hong Kong office joined a video call where the CFO and every other participant were deepfakes, then approved 15 transfers worth about $25 million. Seeing and hearing an executive on a call no longer proves you are talking to that executive.
Are we at risk if our executives aren't public figures?
Yes. McAfee researchers produced a clone with an 85% voice match from three seconds of audio in one test (McAfee Labs, 2023). A webinar, a podcast, a voicemail greeting, or a LinkedIn video gives an attacker audio to work with.
How does Trusona stop executive impersonation?
ATO Protect sends an identity verification to the person's mobile device when someone asks for a reset, a wire, or an approval, and checks their government ID with the authority that issued it. The verification happens on the device, off the call, so a cloned voice or spoofed number does not change the result. Exec Verify confirms executive-to-executive calls with a single-use code, and Agent Verify lets employees confirm that a call from IT is real.
Does ATO Protect use selfies, liveness checks, or voice matching?
No. ATO Protect runs no selfie or liveness check, because generative AI can now defeat those methods. It also ignores how the caller sounds: the verification happens on the mobile device, not on the call. It needs no app download or pre-registration, and Trusona stores no PII.
What should we do if a payment already went out?
Call your bank right away to request a SWIFT recall or ACH reversal, file a complaint with the FBI's Internet Crime Complaint Center (IC3) the same day, and contact the receiving bank. Then treat the impersonated account as compromised and revoke its sessions. Trusona's
CEO fraud guide walks through the full response.