The threat of CEO fraud and one NGO's resilient response

The threat of CEO fraud and one NGO's resilient response | GZERO Media

In January 2020, Heidi Kühn, founder and CEO of Roots of Peace, returned from an overseas trip to devastating news: her finance department had unwittingly transferred over $1 million to an unfamiliar bank account. Kühn and her team quickly realized they’d become victims of a CEO fraud cyber attack—cybercriminals had infiltrated the company’s email accounts via spear phishing and impersonated Kühn to trick the finance team into sending funds abroad.

The theft had an enormous impact on Roots of Peace, a nonprofit dedicated to converting minefields into arable farmland in former war zones. Following the attack, Roots of Peace reached out to the CyberPeace Insitute, an organization that provides free cybersecurity assistance, threat detection and analysis to NGOs and other critical sectors. Roots of Peace was able to recover some of the funds, but to date, only $175,000 of the $1.34 million total stolen has been returned.

Roots of Peace is an international humanitarian organization, but their story isn’t unusual: In 2021, CEO fraud caused $2.4 billion in losses to US businesses alone, according to the FBI Internet Crime Report. Kühn’s story is featured in the second episode of “Caught in the Digital Crosshairs: The Human Impact of Cyberattacks,” a new video series on cyber security produced by GZERO in partnership with Microsoft and the CyberPeace Institute. GZERO spoke with Kühn and Derek Pillar, a cyber security expert from Mastercard, to learn more about the threat of CEO fraud, the real-life impact of cyberattacks against the humanitarian sector, and how you can prevent similar attacks from happening to you and your organization.

More from GZERO Media

A robot waiter, serving drinks at the Vivatech technology startups and innovation fair, in Paris, on May 24, 2024.

  • Magali Cohen / Hans Lucas via Reuters Connect

Imagine sitting down at a restaurant, speaking your order into your menu, and immediately watching a robot arrive with your food. Imagine the food being made quickly, precisely — and without a human involved, because the entire restaurant is fully roboticized.

- YouTube

Forget the fancy cars, futuristic gadgets, and martinis “shaken, not stirred.” In his book "Sell Like a Spy: The Art of Persuasion from the World of Espionage", Jeremy Hurewitz tells GZERO's Tony Maciulis that intelligence officers are a lot more like therapists than James Bond-style action heroes.

ZOHRAN MAMDANI, Rama Duwaji, MIRA NAIR, MAMOOD MAMDANI during an election night event at The Brooklyn Paramount Theater in the Brooklyn borough of New York, US, on Tuesday, Nov. 4, 2025.
(Photo by Neil Constantine/NurPhoto)

Last Tuesday, a self-identified democratic socialist who ran on making New York affordable for the 99% won the city’s mayoral race in a landslide, defeating former Governor Andrew Cuomo. And the reactions have been predictably hysterical.

A fruit and vegetable stall is lit by small lamps during a blackout in a residential neighborhood in Kyiv, Ukraine, on November 6, 2025, after massive Russian attacks on Ukraine's energy infrastructure in October.
(Photo by Maxym Marusenko/NurPhoto)

As a fourth winter of war approaches, Russia is destroying Ukraine’s energy grid faster than it can be rebuilt.