Single Blog Title

This is a single blog caption

CEO Fraud / BEC Fraud and Legal Protection of Companies

Entrance

CEO fraud and BEC (Business Email Compromise) fraud are among the most serious cyberfraud methods companies have faced in recent years. In this type of fraud, perpetrators impersonate company executives, CEOs, CFOs, accounting managers, suppliers, customers, lawyers, bank employees, or business partners to persuade employees to make payments, change IBANs, send invoice amounts to the wrong account, or share confidential information. While the incident often appears as a simple "fake email," it lies behind an organized fraud mechanism with strong technical and psychological components.

In international practice, this type of crime is often Business Email Compromise, or BEC . The FBI defines BEC fraud as one of the most harmful online crimes, exploiting the reliance individuals and companies place on email in their daily business and carried out through fraudulent requests that appear to come from a known source. FBI examples include a supplier appearing to have changed their billing address, a company CEO requesting urgent payment, or payment instructions being altered via fraudulent email.

In Turkey, CEO fraud and BEC fraud should be examined together in terms of Turkish Penal Code Article 158 (aggravated fraud ), Article 243 (unauthorized access to an information system) , Article 244 (obstructing, disrupting, destroying or altering data , unlawful acquisition of personal data) , KVKK (data breach) , banking and payment transactions , labor law , and the duty of care and liability for damages of company directors .

Therefore, for companies, CEO fraud is not just a problem for the accounting department or the IT unit. The company's payment approval system, email security, employee training, GDPR compliance, supplier contracts, bank procedures, and legal crisis management are all central to this risk.

What is CEO Fraud?

CEO fraud occurs when a scammer impersonates a senior company executive, giving payment instructions to employees or arranging money transfers in the company's name. The perpetrator typically uses the name of the company's CEO, chairman of the board, general manager, finance director, or owner. Messages often contain pressure tactics such as "urgent," "confidential," "only you," "I'm in a meeting, don't call," or "payment must be made immediately.".

In this method, the scammer sometimes gains control of the real manager's email account. Sometimes they use a fake domain name that closely resembles the company's domain name. For example, if the real address ferhatkule.com , the fake address might have letter changes, a dot added, or similar character usage. The employee, in their busy work schedule, might not notice this subtle difference.

The most dangerous aspect of CEO Fraud is that it involves not only technical but also psychological manipulation. The perpetrator exploits hierarchical pressure, a sense of urgency, a perception of secrecy, and the employee's tendency not to question their manager. Accounting, finance, purchasing, and human resources departments are particularly targeted by these attacks.

For example, a company accountant might receive an email saying, "Send $85,000 to this account today, confidential, needed for contract closing." The email bears the CEO's name, the signature is genuine, and even uses a similar tone to previous correspondence. If the employee makes the payment without confirming it by phone, the money is often quickly transferred to different accounts, making it difficult to recover.

What is BEC Fraud?

Business Email Compromise (BEC) fraud isn't limited to CEO impersonation. It's a broader fraud model where company emails, supplier correspondence, billing processes, payment confirmations, and customer relationships are manipulated. The FBI explains that in BEC attacks, perpetrators can impersonate email accounts or websites, gain access to company accounts through spear phishing, and infiltrate payment correspondence with malware.

Typical examples of BEC (Business Email Compromise) fraud include: A supplier's genuine email account is compromised and a message is sent stating "our bank details have changed." A fake invoice is sent to a company customer, and the payment is redirected to the fraudster's account. An urgent payment order is sent to the finance department, appearing to be from a manager. A fake message is sent to the human resources department claiming that an employee's payroll account has changed. A deposit, legal fees, project costs, or advance payments are requested by impersonating a lawyer, consultant, or business partner.

BEC attacks are often the result of prolonged monitoring. The perpetrator doesn't act immediately after gaining access to the company's email inbox. They first examine the payment patterns, suppliers, invoices, authorized personnel, and internal communication language. Then, they intercept the correspondence precisely when payment is expected. This is why the victim often becomes suspicious days or weeks after the incident.

What crimes do CEO fraud and BEC fraud constitute under Turkish law?

In CEO fraud and BEC (Business Email Compromise) cases, the most fundamental type of crime is often aggravated fraud. The General Directorate of Security's information on fraud also states that the crime of fraud is regulated in Articles 157 and 158 of the Turkish Penal Code; and that using information systems, banks, or credit institutions as tools is considered aggravated fraud.

In CEO fraud cases, the perpetrator deceives the victim through fraudulent behavior, thereby gaining an unfair advantage for themselves or a third party at the expense of the victim or the company. Since this type of fraud is often committed using email, fake domain names, bank transfers, EFT, SWIFT, payment institutions, or digital communication tools, it falls under the category of aggravated offenses within the scope of Article 158 of the Turkish Penal Code.

If the perpetrator has gained unauthorized access to the actual email account or company system, Article 243 of the Turkish Penal Code (TCK) concerning unauthorized access to an information system will be considered separately. Article 243 of the TCK punishes the act of unlawfully accessing or remaining in all or part of an information system.

If the perpetrator has deleted emails, created forwarding rules, altered invoice files, manipulated bank information, exported data, or rendered data inaccessible/altered in the system, Article 244 of the Turkish Penal Code may come into play. Article 244 of the Turkish Penal Code regulates acts of obstructing or disrupting the operation of an information system, as well as corrupting, destroying, altering, rendering inaccessible, inserting data into the system, or sending existing data elsewhere.

Furthermore, if personal data is present in an email inbox and this data has been obtained by unauthorized individuals, the crimes of unlawful acquisition or dissemination of personal data may also be discussed. If trade secrets, customer lists, contracts, or financial information have been obtained, unfair competition and trade secret infringement may also arise.

Fake IBAN Scams and the Risks for Companies

The most common scenario in BEC (Business Email Compromise) incidents is fake IBAN fraud. The perpetrator gains access to the email account of the company's real supplier or customer, or uses a fake domain name that closely resembles it. They then send messages such as "our bank account has changed," "payment will be made to the new IBAN," or "the previous account has been closed.".

In this type of fraud, the victim company appears to have sent the money voluntarily. However, this volition is compromised by fraudulent behavior. The fraudster deceives the company by exploiting the trust relationship, previous business correspondence, and the expectation of payment. Therefore, this is not a simple mistake like "we sent money to the wrong account"; in most cases, it should be considered organized fraud.

In cases of fake IBANs, if action isn't taken quickly, the money can be transferred to other accounts, withdrawn as cash, or converted into cryptocurrencies within minutes. Therefore, the company must immediately submit a written application to the bank, request a block on the recipient account, ask for urgent notification to the other bank, and simultaneously prepare a complaint with the prosecutor's office.

What should be done in the first hour when fraud is detected?

When CEO fraud or BEC fraud is detected, time is of the essence. The first step is to immediately contact the bank that made the transfer. Informing the bank by phone is not sufficient; the incident must be documented in writing, via email, branch request, or through a registered electronic mail system (KEP). The application should state that the transaction was fraudulent, request that the recipient's account be blocked, that the money be refunded, that the other bank be urgently notified, and that a review of the suspicious transaction be requested.

The second step is to secure the relevant email accounts. Passwords should be changed, all active sessions should be closed, multi-factor authentication should be activated, automatic forwarding rules should be checked, and it should be investigated whether the attacker has created any hidden folder or mail rules.

The third step is evidence preservation. Emails should not be deleted; raw header information should be retrieved, payment receipts should be saved, and any fraudulent IBAN notifications, domain name information, IP log records, server logs, and security alerts should be preserved. Screenshots can be taken; however, screenshots alone may not be sufficient. The original email format, header information, and system logs are far more valuable.

The fourth step is to prepare the technical and legal file for the prosecutor's complaint. The faster and more evidence-based the petition is prepared, the greater the likelihood of the bank account being blocked and the money being traced.

Applying to the Bank and Getting Your Money Back

In CEO Fraud/BEC (Business Email Compromise) cases, the bank process becomes critical after the money transfer. The company must request immediate notification from the sending bank to the receiving bank. In EFT/wire transfers, if the recipient account is within the same country, the possibility of a blockage is a race against time. In SWIFT transactions, a "recall" or refund request must be initiated quickly with both the correspondent bank and the receiving bank.

The application to the bank must include the following information: transaction date and time, amount sent, recipient's IBAN, recipient's name, payment description, the fraudulent email, correspondence with the legitimate supplier, the fake email address, the time the company became aware of the fraud, and information that a complaint will be filed with the public prosecutor's office.

The bank's liability is assessed on a case-by-case basis. The bank may have followed the customer's instructions; however, if there are indicators of suspicious transactions, unusually rapid cash movements, deficiencies in account opening, money laundering risks, or inadequate reaction after notification, the bank's duty of care may be questioned separately. Therefore, bank correspondence must be kept on record.

How should a criminal complaint be prepared for the prosecutor's office?

Complaints regarding CEO fraud and BEC (Business Email Complaint) fraud must include detailed technical information when submitted to the prosecutor's office. Simply stating "we were defrauded" is insufficient. The complaint must clearly describe the chronology of events, the genuine business relationship, the forged email, the payment instructions, the money sent, the recipient's account, the application made to the bank, and any technical evidence.

The following requests must be evaluated in the petition: blocking the recipient bank account, requesting the account holder's identity and account opening documents, determining subsequent money transfer movements, obtaining ATM/camera recordings, requesting IP-log records from the relevant email service providers, investigating domain records if a fake domain name was used, determining IP and device records if there was unauthorized access to the real email account, and conducting an investigation against the suspects under Articles 158, 243, 244 of the Turkish Penal Code and other related crimes.

If the transaction involves an international payment, the possibility of international legal assistance may arise during the prosecution process. Therefore, SWIFT messages, correspondent bank information, recipient bank country, payment reference number, and all bank correspondence should be attached to the petition.

GDPR Aspect: If an Email Account Has Been Compromised, Is There a Data Breach?

In CEO fraud and BEC (Business Email Compromise) incidents, if a company email account has been compromised, the possibility of a personal data breach should be seriously considered. This is because corporate mailboxes can contain customer names, phone numbers, email addresses, billing information, contracts, employee information, bank details, identification documents, proposal files, and sometimes sensitive personal data.

According to the KVKK (Law on Protection of Personal Data), the data controller is obliged to take technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing of personal data, unlawful access to personal data, and to ensure the preservation of data. The KVKK also states that if data is processed by other persons on behalf of the data controller, the data controller may be jointly liable with those persons for the necessary measures.

If an attacker has gained access to an email account and personal data, the company cannot simply ignore the GDPR implications by saying "it was just fraud." A technical report must be prepared to examine which mailbox was compromised, the date range of access, which data categories are at risk, and whether any data was exported.

If personal data is obtained by others through unlawful means, the data controller is obligated to notify the data subject and the Board as soon as possible. This obligation is explicitly stated in the KVKK's data security information.

72-Hour GDPR Notification

If a personal data breach occurs, or if there is a serious finding that personal data has been obtained by unauthorized persons, notification to the Personal Data Protection Board becomes necessary. According to current public announcements by the Personal Data Protection Law (KVKK), data controllers are obligated to notify the Board without delay and within a maximum of 72 hours from the date they become aware of the breach, in accordance with the Board's decision dated January 24, 2019, and numbered 2019/10.

The 72-hour period is important in BEC (Business Email Compromise) incidents because companies often focus only on financial losses in the initial stages. However, if there has been unauthorized access to the email account, personal data is also at risk. In this case, even if the technical investigation continues, an initial notification may be made with the available information, and additional information may need to be provided later.

Notifications to relevant individuals should also be clear, concise, and informative. For example, customers could be informed that emails regarding IBAN changes or payment instructions received on behalf of the company should not be considered without telephone confirmation. If customer data has been compromised, the specific data categories at risk should also be clearly explained.

The Company's Responsibility Towards its Customers and Suppliers

In BEC (Business Email Compromise) incidents, the damage sometimes occurs to the company itself, sometimes to the customer, and sometimes to the supplier. For example, if a company's email account is compromised and a scammer sends a fake payment instruction to a customer from that account, the customer sends the money to the scammer. In this case, the customer might say, "I made the payment trusting the email from the company.".

In such disputes, the following questions are important: Was the email sent from the actual company account? Was the company account compromised due to a security vulnerability? Was multi-factor authentication in place? Did the customer confirm the unusual IBAN change by phone? Was there a payment account change procedure between the parties? Did the company warn customers as soon as it became aware of the fraud? Did the customer also fulfill their duty of care?

If the company's security vulnerability is evident, if customers were notified late, or if the payment instruction was sent from the actual company account, the company's liability for damages may be questioned. Conversely, if the customer made a payment for a high amount and an unusual IBAN change without any confirmation, contributory negligence may arise.

Employee Responsibility and Internal Control

Employee error is common in CEO fraud cases. Accounting staff might execute an urgent payment order without question. A finance employee might fail to confirm an IBAN change over the phone. An employee might click on a phishing link and give away their email password. However, employee error does not automatically absolve the company of corporate responsibility.

The company must have established the following internal control mechanisms: double signature for high-value payments, confirmation via registered phone number for IBAN changes, second manager approval for urgent payment requests, non-email verification channels, multi-factor authentication, regular cybersecurity training for employees, payment instruction procedures, and an email security policy.

If the company has not established these procedures at all, the incident cannot be considered solely due to employee negligence. However, if the employee acted maliciously or violated clear instructions, disciplinary actions, termination, and compensation/recourse proceedings may arise under labor law.

Duty of Care of Company Directors

CEO Fraud risk management should also be considered within the scope of the duty of care of company executives. Email security and payment procedures are particularly important for companies that handle high-volume money transfers, international payments, regular supplier payments, or process customer data, making them integral parts of corporate risk management.

The governing body must ensure that the company's payment systems include an authorization matrix, signature circulars, bank approval limits, technical security measures, and employee training. The defense of "the accountant should have been careful" may not be sufficient if basic control mechanisms are lacking.

Therefore, measures taken against CEO fraud in companies should be documented by management decision; payment approval procedures, information security policy, and incident response plan should be put in writing.

Measures Companies Should Take for Legal Protection

The most effective protection for companies against CEO Fraud and BEC fraud is a system established before the incident, not after. The first measure is multi-factor authentication for all critical email accounts. MFA should be mandatory for management, finance, accounting, purchasing, human resources, and sales departments. The FBI also recommends establishing two-factor or multi-factor authentication and independently verifying payment changes to protect against BEC fraud.

The second precaution concerns the payment procedure. IBAN changes should never be accepted solely via email. Confirmation must be obtained via the supplier's or customer's registered phone number; the new number in the email should not be used. For high-value payments, approval from at least two administrators should be required.

The third measure is email security configuration. SPF, DKIM, and DMARC records must be correctly set up; fake domain names should be monitored; emails from external sources should be indicated with a warning label; suspicious forwarding rules should be reviewed; and Microsoft 365 or Google Workspace audit logs should be activated.

The fourth measure is employee training. Employees should learn about CEO Fraud scenarios, fake IBAN notifications, urgency pressure, domain similarities, phishing pages, and the risk of sharing MFA codes. Training shouldn't be a one-time event; it needs to be supported by regular drills and tests.

The fifth measure is to add secure payment clauses to supplier and customer agreements. The parties may agree that changes to bank accounts will only be valid with a written confirmation signed by an authorized representative, via registered electronic mail (KEP), a secure electronic signature, or a registered telephone confirmation.

File the Company Needs to Prepare After the Incident

Following a CEO fraud or BEC (Business Email Compromise) incident, the company must prepare a comprehensive incident report. This report should include bank applications, payment receipts, forged emails, genuine correspondence, email header information, IP log records, technical reports, criminal complaints to the prosecutor's office, GDPR assessment notes, customer notifications, management decisions, and corrective actions taken.

This file is important not only for the prosecutor's office, but also for potential compensation claims, bank disputes, insurance applications, GDPR reviews, and internal audits. The company must be able to document what measures it took after the incident.

Conclusion

CEO fraud and BEC (Business Email Compromise) fraud are types of fraud with strong technical and psychological components that target companies' business processes based on email trust. The perpetrator often impersonates a company executive, supplier, customer, or finance officer, issuing fraudulent payment instructions, changing IBANs, or manipulating legitimate business correspondence. Therefore, the incident is not simply "sending money to the wrong account," but in most cases constitutes aggravated fraud and cybercrime.

In Turkish law, these events can be evaluated under Article 158 of the Turkish Penal Code (TCK) concerning aggravated fraud using information systems and banks/credit institutions as tools; Article 243 concerning unauthorized access to an information system; and Article 244 concerning altering, rendering inaccessible, or transferring data.

The company's initial actions include promptly notifying the bank, requesting a block on the recipient's account, preserving evidence, obtaining email logs, preparing a technical report, filing a criminal complaint with the prosecutor's office, and initiating the GDPR process if there is a possibility of a personal data breach. Under the GDPR, the company is obligated to take the necessary technical and administrative measures to prevent unlawful access to personal data and ensure data security.

In conclusion, the strongest defense companies have against CEO Fraud and BEC fraud is a payment security and email security system established before the incident. Companies with multi-factor authentication, double-checked payment procedures, phone verification for IBAN changes, SPF-DKIM-DMARC configuration, employee training, secure payment terms in supplier contracts, and an incident response plan both reduce the risk of fraud and manage their legal responsibilities more effectively when an incident occurs.

Leave a Reply

Call Now Button