The threat of CEO fraud and one NGO's resilient response

The threat of CEO fraud and one NGO's resilient response | GZERO Media

In January 2020, Heidi Kühn, founder and CEO of Roots of Peace, returned from an overseas trip to devastating news: her finance department had unwittingly transferred over $1 million to an unfamiliar bank account. Kühn and her team quickly realized they’d become victims of a CEO fraud cyber attack—cybercriminals had infiltrated the company’s email accounts via spear phishing and impersonated Kühn to trick the finance team into sending funds abroad.

The theft had an enormous impact on Roots of Peace, a nonprofit dedicated to converting minefields into arable farmland in former war zones. Following the attack, Roots of Peace reached out to the CyberPeace Insitute, an organization that provides free cybersecurity assistance, threat detection and analysis to NGOs and other critical sectors. Roots of Peace was able to recover some of the funds, but to date, only $175,000 of the $1.34 million total stolen has been returned.

Roots of Peace is an international humanitarian organization, but their story isn’t unusual: In 2021, CEO fraud caused $2.4 billion in losses to US businesses alone, according to the FBI Internet Crime Report. Kühn’s story is featured in the second episode of “Caught in the Digital Crosshairs: The Human Impact of Cyberattacks,” a new video series on cyber security produced by GZERO in partnership with Microsoft and the CyberPeace Institute. GZERO spoke with Kühn and Derek Pillar, a cyber security expert from Mastercard, to learn more about the threat of CEO fraud, the real-life impact of cyberattacks against the humanitarian sector, and how you can prevent similar attacks from happening to you and your organization.

More from GZERO Media

Will the Gaza campus protests work? | Ian Bremmer explains | GZERO World

College campuses nationwide have become protest hubs, echoing past movements demanding change. The core demand: divestment from Israel. Whether it's cutting ties with Israeli donors or businesses, students are risking penalties to be heard. Have the student protests worked? Ian Bremmer explains on GZERO World.

House Speaker Mike Johnson (R-LA) talks to reporters after surviving a vote to remove him from the Speaker’s position, Washington, DC, May 8, 2024. Marjorie Taylor Greene (R-GA) introduced a motion to vacate the Speaker’s office, which was defeated by a motion to table the issue immediately afterward.
Photo by Allison Bailey/NurPhoto via Reuters
FILE PHOTO: Israeli Prime Minister Benjamin Netanyahu speaks with Minister of Finance Bezalel Smotrich during the weekly cabinet meeting at the Defence Ministry in Tel Aviv, Israel, January 7, 2024.
REUTERS/Ronen Zvulun/Pool/File Photo

Israeli Prime Minister Benjamin Netanyahu said Thursday his country would “stand alone” and fight “with its fingernails” if Joe Biden followed through on a threat to cut certain arms shipments to the Jewish state.

An Israeli delegation reacts to their advancing the ESC finale during the second semi-final of the 2024 Eurovision Song Contest, in Malmo, Sweden, May 9, 2024.
REUTERS/Leonhard Foeger

As musicians from around the world prepare to represent their country in the Eurovision Song Contest, thousands of demonstrators waving Palestinian flags are flooding the host city of Malmö, Sweden, to protest Israel’s participation.

House Speaker Mike Johnson (R-LA) speaking at a press conference at the U.S. Capitol.
(Photo by Michael Brochstein/Sipa USA)

Earlier this week, House Speaker Mike Johnson (R-LA) faced down a would-be Republican rebellion against his leadership driven by Rep. Marjorie Taylor Greene (R-GA) – and he did it emphatically.