← Back to Knowledge Center
KNOWLEDGE CENTER

Executive Impersonation: Verify Unusual Payment Requests

Business & Organizationen-NG
BEFORE YOU BEGIN

Understand the issue before you decide what to do.

This lesson is designed to explain the subject in practical terms so that you can understand not only what the risk is, but why it matters, how it can appear in real situations and what you can do to reduce your exposure.

Read the explanation carefully before acting on a suspicious message, request, transaction, account notification or other security-related situation.

FULL LESSON

Understanding the subject

Take your time with this explanation. The goal is not simply to recognise a warning sign, but to understand what is happening and make a safer decision when you encounter it.

EXECUTIVE IMPERSONATION: VERIFY UNUSUAL PAYMENT REQUESTS

Attackers may pretend to be an owner, director, manager or other senior person and request a payment or sensitive business action.

The request may arrive through email, messaging applications, social media, phone calls or another channel.

The central principle is:

AUTHORITY SHOULD NOT REMOVE THE NEED FOR VERIFICATION.

1. WHY EXECUTIVE IMPERSONATION WORKS

Employees may feel pressure to act quickly when they believe a request comes from senior management.

Attackers exploit that expectation.

They may use:

  • Familiar names
  • Executive job titles
  • Copied signatures
  • Compromised accounts
  • New phone numbers
  • Urgent explanations
  • Requests for secrecy

2. TREAT UNUSUAL REQUESTS DIFFERENTLY

A request that differs from the person's normal behaviour deserves additional verification.

Examples include:

  • A sudden request for a large transfer
  • A request to use a new beneficiary
  • A request to bypass another approver
  • A request to purchase unusual items
  • A request for sensitive credentials
  • A request to keep the action secret

3. VERIFY THROUGH A KNOWN CHANNEL

Do not verify an unusual request only by replying to the same message or calling the number supplied in it.

Use a previously established contact method or the organization's trusted verification procedure.

4. NEVER SHARE AUTHENTICATION SECRETS TO PROVE IDENTITY

A genuine executive or authorized employee should not need another employee's password, OTP, recovery code or similar authentication secret simply to prove that they are who they claim to be.

Authentication secrets should remain protected.

5. BUSINESS EXAMPLE

An employee receives a message appearing to come from a director requesting an urgent payment and instructing the employee not to call because the director is in a meeting.

The employee follows the company's verification process rather than relying on the message.

The request is independently confirmed before any payment is made.

6. PRACTICAL BUSINESS CHECK

Teach employees to pause when a request:

□ Involves unusual urgency. □ Changes normal payment procedures. □ Requests secrecy. □ Uses a new communication channel. □ Requests a new beneficiary. □ Attempts to bypass approval. □ Asks for authentication secrets.

WHY THIS MATTERS

The safest response to a high-impact request is not blind obedience or automatic rejection. It is appropriate verification.

VERIFY BEFORE YOU TRUST.

A person's apparent authority is not independent proof that a payment request is genuine.

APPLY WHAT YOU LEARNED

Turn understanding into a security habit.

Knowing the definition is only the beginning. The real value of cybersecurity education is being able to recognise the situation and make a safer decision when it happens to you.

How should you use what you learned?

Understanding a cybersecurity concept is useful only when it changes how you make decisions. When you encounter a similar situation in real life, slow down and identify what is being requested before you respond.

Ask yourself who is making the request, what they are asking you to do, what information or access is involved, and whether the request can be independently verified.

Do not allow urgency, fear, authority, familiarity or the promise of a reward to replace independent verification.

What if I still do not understand something?

Cybersecurity concepts can sometimes involve technical terms or situations that are difficult to interpret from a single lesson. If something is unclear, do not guess when the decision could affect your money, identity, account access, device or sensitive information.

You can seek further guidance through the consultancy channel. Explain the situation clearly, but never include passwords, OTPs, PINs, recovery phrases, private keys or other authentication secrets.

Use the consultancy form →

THE VERIFY BEFORE YOU TRUST PRINCIPLEVERIFY BEFORE YOU TRUST.

A convincing message, familiar name, professional appearance or urgent request is not proof of legitimacy. Verify the important facts independently before taking an action that could be difficult to reverse.