CEO Fraud vs. Business Email Compromise: What’s the Difference?

CEO fraud is a type of business email compromise—but several related terms overlap. Compare BEC, VEC, account takeover, whaling, and invoice fraud.

A supplier emails your accounts-payable team from a real mailbox. The message continues an existing invoice thread, changes the bank details, and copies an executive to create pressure. The payment goes to a criminal account.

The incident may qualify as business email compromise, vendor email compromise, email account takeover, executive impersonation, and invoice fraud.

These terms describe different layers of an attack. One names a fraud family, another identifies the person being impersonated, another describes how the attacker gained access, and another names the payment tactic. Separating those layers helps security and finance teams investigate the right problem and apply controls that address how the attack actually worked.

CEO Fraud vs. Business Email Compromise: The Short Answer

Business email compromise (BEC) is the broader fraud category. CEO fraud is a type of BEC in which an attacker impersonates a CEO, CFO, or another senior leader to manipulate someone into sending money, sharing sensitive information, or granting access.

Some sources use “CEO fraud” as another name for BEC. Using the terms interchangeably hides other forms of BEC involving suppliers, payroll, attorneys, real-estate transactions, and compromised employee accounts. Treating CEO fraud as a subtype is more useful when you need to classify an incident or choose controls.

The FBI’s BEC guidance illustrates the breadth of the category with both executive gift-card requests and vendor invoice changes. The same BEC family can therefore contain very different impersonated identities, access methods, and payment requests.

TermWhat the term describesWho is impersonated or targeted?Is a real account compromise required?Common objectiveSimple example
Business email compromise (BEC)The broad fraud operationAn executive, employee, vendor, attorney, customer, or other trusted partyNoMoney, data, credentials, or accessA message that appears to come from a trusted business contact requests a fraudulent payment
CEO fraudThe identity used in a BEC scenarioA CEO, CFO, or another senior leader is impersonatedNoWire transfer, gift cards, payroll or data disclosureA fake CFO tells finance to make a confidential transfer
Vendor email compromise (VEC)The supplier identity or relationship being abusedA vendor or supplierUsually in the strict sense, although “vendor impersonation” may use spoofingInvoice or bank-detail diversionA supplier’s compromised mailbox sends replacement payment details
Email account takeover (ATO)The access mechanismA real mailbox ownerYesSurveillance, impersonation, data theft, or further fraudStolen session access lets an attacker reply from a real mailbox
WhalingThe seniority or value of the targetA CEO, CFO, board member, or other high-value person is targetedNoCredentials, access, data, or payment authorizationA tailored phishing message targets a CFO
Invoice fraudThe payment tactic or outcomeA vendor, employee, or fabricated business identity may be usedNoDivert an expected or invented paymentAn invoice contains a criminal bank account

Why These Fraud Terms Overlap

Classify each term by what it tells you:

  • Fraud family: Is the operation BEC?
  • Identity: Is an executive, employee, or vendor being impersonated?
  • Access: Did the attacker take over a real email account, or merely spoof one?
  • Target: Is the message aimed at an executive or another high-value person?
  • Tactic: Is the attacker altering an invoice, redirecting payroll, requesting gift cards, or seeking credentials?
  • Channel: Did the manipulation remain in email, or move to phone, SMS, a messaging app, or video?

An incident can carry a label from every layer. Calling it BEC doesn’t rule out VEC or invoice fraud. Calling it email account takeover says how access was obtained, not what the attacker did with that access.

There is no perfectly consistent industry glossary. The definitions below use operational distinctions that help teams describe evidence, assign response work, and select defenses. Where common usage differs, the difference is noted.

Six Terms, Six Different Parts of the Attack

Business Email Compromise Names the Fraud Family

BEC is targeted fraud that abuses trusted business communication and a legitimate-looking request. The attacker wants a person or organization to take an action that appears routine: pay an invoice, change bank details, release payroll data, buy gift cards, or share credentials.

Despite the name, BEC does not prove that a mailbox was hacked. Attackers can use display-name impersonation, forged sender details, lookalike domains, compromised accounts, or combinations of email, voice, and messaging. The “compromise” can be a compromise of trust and process, not necessarily technical control of an inbox.

BEC is therefore the family name. CEO fraud and VEC describe important branches within it, while email ATO may provide the trusted account used to carry it out.

CEO Fraud Uses the Executive as the Mask

In CEO fraud, an attacker presents themselves as a senior leader and directs a subordinate, partner, or service provider to take action. The executive’s authority supplies the pressure.

A typical request invokes urgency, secrecy, or an exception: “The acquisition is confidential,” “I’m in a meeting,” or “We need this payment before the deadline.” The attacker may use a lookalike email address, a compromised executive mailbox, a cloned voice, or a messaging profile.

No executive account needs to be breached. A convincing impersonation is enough if the recipient treats apparent authority as authorization. This makes CEO fraud a BEC subtype defined by whose identity is being used.

Vendor Email Compromise Exploits Supplier Trust

Vendor email compromise uses a supplier’s identity and an established commercial relationship to deceive the supplier’s customers. A common version begins when an attacker takes over a vendor mailbox, studies real correspondence, waits for an invoice, and changes the remittance details inside the legitimate thread.

If no supplier account was actually compromised, “vendor impersonation” may be the more precise description. The resulting operation can still be BEC, but the access method and incident owner may differ.

VEC can be especially persuasive because mail from a genuine supplier account may pass SPF, DKIM, and DMARC checks. The message can also contain correct names, amounts, purchase context, and prior correspondence. The strongest control is often a financial process: verify bank-detail changes through a known contact method that did not come from the message requesting the change.

Email Account Takeover Describes the Access

Email account takeover means an attacker gained unauthorized control of a real mailbox. They might steal a password, capture a session token through adversary-in-the-middle phishing, abuse an OAuth grant, compromise a device, or manipulate account recovery.

Once inside, an attacker can read historical conversations, learn approval patterns, create forwarding or deletion rules, and send from a trusted address. That access can enable CEO fraud, VEC, payroll diversion, invoice fraud, data theft, and attacks against customers or partners.

But email ATO is not synonymous with BEC. A compromised mailbox may be used only for espionage or credential resets. Conversely, BEC can succeed through spoofing without any account takeover. Always name the account type because “ATO” can also refer to bank, social-media, SaaS, or customer accounts.

Whaling Targets the Executive

Whaling is highly targeted phishing directed at senior executives or other high-value people. The “whale” is the target. An attacker might send a CFO a tailored credential lure, pose as a board member, or use legal pressure to manipulate a CEO into disclosing information.

Security teams can use a directional distinction: whaling targets the executive; CEO fraud impersonates the executive. Industry usage remains inconsistent. Cisco’s current whaling guidance, for example, describes whaling as executive-targeted phishing while also noting that it is often called CEO fraud.

When reporting an incident, describe who received the lure and whose identity was used. Those facts are more reliable than assuming everyone uses “whaling” the same way.

Invoice Fraud Describes the Payment Tactic

Invoice fraud uses a false, altered, duplicated, or misdirected invoice to steal a payment. An attacker might replace the bank details on a real invoice, invent a supplier, submit the same invoice twice, or pose as a legitimate vendor asking for a payment change.

Email is a common delivery channel, but it isn’t required. A fabricated invoice submitted through a portal or by post is still invoice fraud and may not be BEC. Likewise, many BEC attacks request wires, gift cards, payroll changes, data, or credentials without involving an invoice.

When invoice fraud occurs inside a compromised supplier thread, several labels can apply: BEC describes the operation, VEC describes the abused relationship, email ATO describes the access, and invoice fraud describes the payment tactic.

How One Attack Can Change Labels as It Unfolds

Consider two simplified scenarios.

Scenario one: the fake CFO request. An attacker registers a domain that differs from your company’s domain by one letter. They send an accounts-payable analyst a message that appears to come from the CFO and request an urgent wire for a confidential transaction.

The fake-CFO scenario is BEC because trusted business communication is being used to trigger fraud. It is also CEO fraud because a senior executive is being impersonated. Without evidence of access to a real account, email ATO does not apply. Under the target-based convention, the analyst is the target and the CFO is the mask, so this stage is CEO fraud rather than whaling.

Scenario two: the attack that evolves. An attacker sends a tailored credential lure to a senior executive. At this stage, the attack is whaling. The executive enters credentials and the attacker captures an authenticated session, creating an email account takeover.

The attacker watches the mailbox, learns about an upcoming supplier payment, and sends finance new bank details. The operation has now become BEC. If the attacker sends as the executive, it is also CEO fraud. If they instead compromise or impersonate the supplier relationship, it may be VEC. If an invoice or remittance instruction is altered, it is also invoice fraud.

Labels change as the attack progresses because the facts change. Preserve that sequence in the incident record rather than forcing the entire chain into one term.

How to Classify a Suspected Incident

Start with observable facts and work through five questions:

  1. What action was requested or completed? Record the wire, bank-detail change, invoice payment, credential disclosure, data release, gift-card purchase, or access change.
  2. Whose identity was presented? Identify whether the sender appeared to be an executive, employee, supplier, attorney, customer, or another trusted party.
  3. Was a real account confirmed compromised? Separate verified mailbox access from assumptions based on a convincing message. Check sign-in, session, OAuth, forwarding, deletion, delegate, and recovery evidence.
  4. Who received the lure? If the initial target was a senior executive or another high-value person, “whaling” may describe that stage.
  5. Was a genuine invoice or payment relationship altered? This distinguishes invoice diversion and strict VEC from a generic payment request or fabricated bill.

Use multiple labels when the evidence supports them. A useful incident summary might read: “BEC using CEO impersonation through a lookalike domain; no email ATO found.” Another might read: “VEC following supplier email ATO, resulting in invoice-payment diversion.”

Precise classification tells identity teams whether they need to revoke sessions, finance teams whether they need to freeze or recall a payment, vendor managers whether a supplier relationship is affected, and security teams which control failed.

Match the Control to the Mechanism

The right control depends on the layer of the attack:

  • Spoofing and lookalike domains: Enforce SPF, DKIM, and DMARC for domains you control. Add external-sender cues, monitor confusingly similar domains, and inspect display-name impersonation. These controls do not authenticate a genuinely compromised third-party mailbox.
  • Email account takeover: Use phishing-resistant MFA where possible, restrict legacy authentication, monitor suspicious sessions and OAuth grants, harden account recovery, secure endpoints, and investigate mailbox rules and delegates during response. A password reset alone may not remove persistent access.
  • CEO fraud: Require independent verification for consequential requests, especially urgent or confidential exceptions. Use a known phone number or approved internal channel rather than contact details supplied in the request. Do not let apparent executive identity replace authorization.
  • Whaling: Give executives strong identity protection and tailored rehearsal. Reduce public exposure of schedules and approval relationships where practical, and establish a fast reporting route that senior leaders will actually use.
  • VEC and invoice diversion: Verify every new or changed bank account through a previously established contact. Separate vendor-master changes from payment approval, require dual authorization, and alert on unusual changes followed by rapid payment.
  • All variants: Make escalation safe, simple, and fast. If money moved, contact the financial institution immediately and report the incident through the appropriate law-enforcement channel. The FBI advises victims to contact their bank and report BEC to IC3 as quickly as possible.

No individual control covers every row. DMARC can reduce direct domain spoofing but cannot stop mail sent from a compromised supplier account. MFA can reduce some account takeovers but cannot validate a fraudulent instruction sent from a lookalike domain. Training can improve recognition and reporting but cannot enforce dual approval or secure a cloud session. A complete BEC prevention framework has to connect these layers.

How Brightside Rehearses High-Risk Decisions

Employees don’t need to recite a perfect taxonomy while an urgent payment request is waiting. They need to recognize the relevant signals, pause, verify the identity independently, follow the payment process, and report the attempt.

Brightside helps organizations rehearse those decisions through interactive CEO-fraud and social-engineering education, plus realistic simulations. Email campaigns can cover vendor impersonation and BEC scenarios and can be assigned to higher-risk groups such as Finance & Accounting.

For attacks that move beyond email, Brightside supports live AI-powered vishing simulations and hybrid scenarios that combine a phone call with a trackable phishing email. Administrators can also create self-service audio simulations using a custom executive voice generated from a one-to-two-minute recording. Teams can practice their response when apparent authority is reinforced across channels.

Rehearsal belongs inside a broader control system. Brightside does not replace email authentication, phishing-resistant identity controls, vendor-master governance, dual payment approval, or incident response. Its role is to help people apply verification, escalation, and reporting procedures when a realistic pretext puts them under pressure.

CEO Fraud vs. BEC FAQs

Is CEO fraud the same as business email compromise?

CEO fraud is best understood as a type of business email compromise in which an attacker impersonates a senior executive. BEC is broader and also includes vendor impersonation, payroll diversion, attorney impersonation, invoice-payment changes, and other trusted business requests. Some sources use the terms as aliases, so incident reports should state who was impersonated and what action was requested.

Can business email compromise happen without an email account being hacked?

Yes. Attackers can conduct BEC through display-name impersonation, forged sender information, lookalike domains, or messages that move the victim to phone or messaging apps. A real mailbox takeover makes a pretext more credible, but it isn’t required. Confirm account compromise through technical evidence rather than inferring it from a persuasive message.

What is the difference between vendor email compromise and invoice fraud?

VEC describes abuse of a supplier’s identity or trusted relationship, usually through a compromised vendor mailbox in the strict sense. Invoice fraud describes the payment tactic: a false or altered invoice redirects money. A compromised supplier can send an altered invoice, making the incident both VEC and invoice fraud, but either category can occur without the other.

Is whaling aimed at the CEO or sent by someone pretending to be the CEO?

A practical distinction is that whaling targets a CEO or another high-value person, while CEO fraud uses the executive as the impersonated identity to target someone else. However, industry sources frequently use “whaling” and “CEO fraud” interchangeably. State who received the lure and who was impersonated instead of relying on the label alone.

Is email account compromise the same as email account takeover?

In everyday security usage, the phrases often describe the same basic event: unauthorized access to a real mailbox. “Email account compromise” can sometimes be used more broadly, and the FBI also uses “email account compromise” as a name associated with BEC. For clarity, specify whether technical mailbox access was confirmed and distinguish that access from the fraud conducted afterward.

Use the Most Specific Label the Evidence Supports

BEC names the fraud family. CEO fraud, VEC, email ATO, whaling, and invoice fraud add detail about identity, access, target, or outcome. More than one label may be correct. Record the facts each label represents, then choose controls based on the mechanism that made the attack possible.