Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

AI Executive Impersonation Email & Voice Phishing: Finance Staff Tricked by Fake Directives into Transferring Funds

Victims are primarily corporate finance, accounting, and cashier personnel, concentrated in small and medium-sized enterprises as well as some large institutions. They handle a high volume of daily transfer approvals, are accustomed to obeying executive directives, hold high trust in internal emails and voices, and lack multi-layered identity verification mechanisms. Psychological vulnerabilities include inertial obedience to authority, fear of delaying business and facing accountability, and the sense of urgency brought by 'the boss calling personally,' causing rational judgment to be suppressed by emotion.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionGlobal
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

Victims are primarily corporate finance, accounting, and cashier personnel, concentrated in small and medium-sized enterprises as well as some large institutions. They handle a high volume of daily transfer approvals, are accustomed to obeying executive directives, hold high trust in internal emails and voices, and lack multi-layered identity verification mechanisms. Psychological vulnerabilities include inertial obedience to authority, fear of delaying business and facing accountability, and the sense of urgency brought by 'the boss calling personally,' causing rational judgment to be suppressed by emotion.

骗局怎么运作

  • Step 1: Gather public information on target enterprises. Attackers lock down the names, positions, email addresses of corporate executives, and contact information of finance personnel through official websites, recruitment platforms, social networks, and other channels, using AI tools to analyze their linguistic style and common phrasing to prepare for subsequent impersonation. The mechanism is to reduce unfamiliarity so that finance staff feel 'it really is the boss's tone' upon receiving an email.
  • Step 2: Clone executive voice and handwriting. Attackers capture a few minutes of public speeches, interviews, or internal meeting recordings of executives, using AI voice cloning tools to generate the same voice tone; simultaneously, they utilize email history or proxy-signed samples to train handwriting models. The mechanism is to bypass traditional verification methods of 'listening to the voice and checking the signature' used by finance staff, making forged content difficult to distinguish at a sensory level.
  • Step 3: Send forged emails and manufacture urgent scenarios. Attackers send emails to finance staff using executive email addresses (or highly similar spoofed domain emails), claiming they are attending an important meeting/business trip, urgently need to pay a certain amount of funds, requesting 'immediate processing with post-signing,' and attaching forged contracts or invoices. The mechanism is to leverage a sense of urgency and authority pressure to compress finance verification time, while using terms like 'confidentiality agreement' to prohibit seeking verification from others.
  • Step 4: Secondary confirmation via phone or voice message. If finance staff hesitate, attackers will make a spoofed voice call or send a voice message on instant messaging software, claiming 'it's me,' and repeat the email directive. The mechanism is to create psychological suggestion of 'the leader urging personally,' further dismantling the defense line of vigilance and making finance staff mistakenly believe voice verification has passed.
  • Step 5: Induce transfer to designated accounts and erase traces. Once finance staff complete the transfer, attackers quickly disperse and transfer funds across multiple accounts, deleting or forging internal communication records. The mechanism is to exploit the psychological window period of 'relief' after the transfer to delay verification with the real executive, creating huge obstacles for fund recovery.

红旗信号(看到这些快跑)

  • 🚩 There are subtle differences between the email domain and the official domain, such as an extra letter or replacing the letter l with the number 1; checking the sender address character by character is necessary rather than just looking at the display name.
  • 🚩 Executives demand finance staff bypass normal approval procedures, using high-frequency words such as 'urgent,' 'confidential,' and 'pay first, supplement later,' while refusing written confirmation or face-to-face communication.
  • 🚩 The receiving account is a personal account or a new third-party account unrelated to the transaction, with the bank or receiving address inconsistent with the transaction counterparty's location.
  • 🚩 In voice calls, the tone is mechanical and the accent is abnormal, or the excuse 'in a meeting, bad signal' is used to refuse video and meetings, remaining vague when finance staff press for details.
  • 🚩 The layout of contracts and invoices in email attachments is rough, PDF metadata or digital signatures are abnormal, or file links direct to non-official domains.

真实案例

  • Case 1: On July 30, 2024, the Ministry of Public Security published 5 typical telecom network fraud cases targeting corporate accounting personnel, multiple of which involved impersonating bosses to direct financial transfers through instant messaging tools, with single-case losses reaching millions of yuan. Official reports explicitly pointed out that such scams have formed a mature model of 'precise profiling + identity impersonation.' (Source: [https://big5.cctv.com/gate/big5/news.cctv.cn/2024/07/30/ARTI4ArWheElCH2llT8rDR5U240730.shtml](https://big5.cctv.com/gate/big5/news.cctv.cn/2024/07/30/ARTI4ArWheElCH2llT8rDR5U240730.shtml))
  • Case 2: Media reports in 2026 indicated that a hedge fund was scammed by AI mimicking an executive's voice. Attackers used AI to clone the CEO's tone to call finance and demand an urgent transfer, resulting in massive financial losses. The report was published by 36Kr in 2026, showing that this tactic has spread from small and medium enterprises to large financial institutions.
  • Case 3: In August 2026, China Economic Net reported an AI synthetic video call fraud case where a victim was defrauded of 1.86 million yuan. Attackers impersonated acquaintances/leaders to execute transfer orders via AI face-swapping and voice cloning. Anti-fraud centers dismantled deepfake tactics, warning that such scams are frequently occurring in multiple locations.
  • April 2023: Mr. Guo, legal representative of a technology company in Fuzhou, received a WeChat video call from a friend who requested a transfer to a corporate account under the pretext of needing a security deposit. Because he saw a familiar face and heard a familiar voice, Mr. Guo let down his guard and was defrauded of 4.30 million yuan within 10 minutes. It was later verified that the scammer used AI face-swapping and vocal imitation technology to forge his friend's voice and appearance. (Source: [https://www.tmtpost.com/6549271.html](https://www.tmtpost.com/6549271.html))

Official Stance

  • On July 30, 2024, the official website of the Ministry of Public Security released 'Ministry of Public Security Announces 5 Typical Cases of Telecom Network Fraud Targeting Corporate Accounting Personnel,' explicitly listing the impersonation of bosses/executives to induce transfers as a key target for crackdown.
  • In 2024, the National Anti-Fraud Center, in conjunction with CCTV, repeatedly issued early warnings, reminding finance personnel to verify true identities via phone or face-to-face confirmation whenever 'leaders' instruct transfers via social software or email.
  • In August 2026, regional anti-fraud centers (such as Hangzhou Public Security) reported the achievements of the 'Netting 2026' operation, emphasizing that telecom fraud tactics targeting AI forged identities have been upgraded and requiring enterprises to establish internal dual-person transfer review systems.

How to Protect Yourself

  • ✅ Establish a 'dual-person review + offline confirmation' transfer system: any transfer exceeding a set amount must be reviewed by two or more finance personnel, and confirmed by calling back the executive's common number (not numbers inside emails/messages) or face-to-face.
  • ✅ Conduct specialized anti-phishing training for executives and finance personnel, regularly simulating 'boss requesting urgent transfer' drills to strengthen sensitivity to spoofed domains, urgent phrasing, and abnormal receiving accounts.
  • ✅ Deploy AI phishing detection tools on email gateways, monitor internal executive email domains, enable DMARC/SPF/DKIM email authentication, and intercept spoofed domain emails.
  • ✅ Implement a 'cooling-off period' rule: all transfer directives involving unapproved contracts, no matter how urgent, must wait at least 30 minutes or trigger written authorization from superior leaders, avoiding hasty operations under emotional pressure.