Skip to content
isthisaigenerated.appsignals behind the content
Image detectorText detectorDocument detectorCheckersAppsHow it works ▾TeamsFor developersDocsPricingAccuracyTrustBlogContactNLSign in

BEC fraud

How to spot a fake payment request from your boss: verify outside the channel that made the request

An email from the boss instructing a large transfer, often to a foreign account, marked confidential: that is the CEO fraud pattern (Fraudehelpdesk, CEO-fraude). The same page describes the clever verification trick: the employee can call a 'law firm' that confirms the instruction, but that firm is part of the scheme. In business email compromise (BEC), criminals impersonate someone you trust - the director, a colleague, a regular supplier or a client - and use email or phone to push you into a payment or into sharing confidential information (NCSC, BEC guidance for SMEs).

The rule that breaks this fraud is not reading the message more carefully, but moving verification to a channel the requester does not control: verify a payment instruction through a number or agreement you already had, never through the channel that sent it.

Direct answer: five checks before any money moves

  1. Verify outside the message. Call the requester back on a number from your own records or contact list; never use the number in the email or payment request, because that number can belong to the fraudster (Veilig Bankieren, CEO and invoice fraud). Expect the accomplice trick from the Fraud Helpdesk pattern too: a 'law firm' or 'notary' that confirms the request is part of the scheme (Fraudehelpdesk).
  2. Do not deviate from the payment process - the deviation is the signal. In CEO fraud the payment process almost always departs from the normal rules in the business; work with segregation of duties or dual authorisation, and let nobody transfer a large amount on the strength of an email or a phone call alone (Veilig Bankieren). Dual authorisation is precisely what works against the pressure of a 'command' (NCSC).
  3. Check the account number against your own records. Does it match what you already had, and is the name-account combination known? If a supplier or client suddenly changes bank details, call the number you already had; the bank does not check the combination of account number and beneficiary name (Veilig Bankieren).
  4. Treat urgency and secrecy as the mechanism, not a detail. Authority, confidentiality ('share this with nobody'), a compliment that you were chosen, and time pressure are the fixed features used to force the instruction through (Fraudehelpdesk). A request that forbids verification is a request not to verify.
  5. Treat the sender address as a label that can be forged. Fraudsters use addresses that resemble the real domain (a lowercase l swapped for a capital I) and sometimes a mailbox they previously compromised, so tone, timing and project references all fit (Fraudehelpdesk; NCSC). So do not check the logo or the address; check the instruction itself through steps 1 and 2.

Why the classic signals stopped working

Until recently a fraud email stood out through bad language and odd sentences. That filter is gone: with AI, attackers write perfect Dutch or English in seconds, clone a director's voice and simulate video calls. The NCSC guidance describes how criminals generate hundreds of emails that fit live projects - and states that the traditional signs of fraud no longer work, which makes verification through an independent channel essential (NCSC). The average damage per BEC incident is EUR 118,000 according to the same guidance, an existential threat for many small businesses.

What a detector does and does not see

You can run the text of the payment request through the text detector and a screenshot through the image detector. That is triage: it helps you decide which message to check first. It is not a statement about the sender. A hand-written email can draw a signal, while a perfectly written, contextually accurate email matching a higher score is exactly the modern pattern. A low score therefore never proves the instruction is real; the decision belongs to the verification in steps 1 and 2.

What you cannot tell from the email

  • whether the sender really is the director, supplier or client, even when name, logo and layout match;
  • whether the project or transaction the email refers to exists;
  • whether the account number belongs to the organisation named in the email;
  • whether this is fraud; only a bank or law enforcement authority establishes that.

If money has already been sent

  • Call your bank and the receiving bank immediately: speed decides whether a payment can still be frozen or recalled (Interpolis on CEO fraud).
  • Report it to the Fraudehelpdesk (by phone on 088 - 786 73 72 or through the reporting form) and file a police report (MKB-Nederland, CEO fraud fact sheet).
  • Have the fake domain blocked on your mail server and monitor mail traffic for similar domains (Veilig Bankieren).
  • Keep everything: the email with headers, the account number, the amounts, the timestamps and the communication with anyone who confirmed the request.
  • Do not count on reimbursement: the bank does not compensate this type of fraud because you executed the payment yourself, and the loss is usually not insured either (MKB-Nederland; Veilig Bankieren).

More checks are in the guides on checking a suspect invoice, spotting an AI voice-clone scam and spotting a fake bank call. To check a single message or file, use the free checker.

Frequently asked questions

The sender address matches exactly. Does that make the payment request real?

No. A sender name, a logo and even a domain can be faked, and criminals sometimes send from a mailbox they previously compromised. What confirms the instruction is verification through a number or person you already had - not the message itself.

Can a detector score expose a fake payment request?

No. The score describes patterns in text or images and says nothing about the sender or about whether the instruction is real. AI makes the language perfect, which is why wording is no longer a usable filter. Use the result as triage only.

My employee already paid. What now?

Call your bank and the receiving bank immediately for a freeze or recall, preserve all evidence, report it to the Fraudehelpdesk and file a police report. Then discuss the incident openly in the team: shame only makes the next attempt stronger (NCSC).

What do we agree on in advance to prevent this?

A verification policy: every change of bank details or urgent instruction is confirmed by phone through a number from your own records, large payments always pass two pairs of eyes, and there is an agreed code word for urgent requests from the board (NCSC; Veilig Bankieren).

isthisaigenerated.appWhat’s real? What’s fake?

Signals support human judgement. They do not prove origin.

ProductCheck mediaCheckersBlogAppsHow it worksPricing
BuildFor developersDocsDetection APIAccuracyBenchmarks
CompanyTrustTeamsPilotContact
LegalPrivacyTermsProvenanceC2PA

© 2026 isthisaigenerated.app · Open beta · No detector output is standalone proof.