BG Beter Geregeld ICT
Security zonder IT-afdeling · 5 min leestijd · 23 July 2026

"The boss is on holiday, can you sort this?" — recognising summer fraud

The holiday season brings a sharp rise in CEO fraud and urgent payment requests "on behalf of the boss". Here's how to spot these messages — and what ground rules will stop you from falling for them.

It's a classic summer scenario: a colleague or regular supplier calls from a private number, or sends a WhatsApp message from someone "quickly checking in while on holiday". The number doesn't match what you have saved in your phone, or the sender says: "I'm using my personal email for now". Sounds plausible — it's summer, people switch devices, laptops stay home. But these are exactly the weeks that fraudsters exploit so eagerly.

This summer we're seeing a striking number of reports from SMB owners who were asked to arrange something "on behalf of the director who's on holiday". It's usually an urgent payment, a gift card, or forwarding login details. How do you recognise one of these messages, and what can you agree on in advance so you don't make a panicked decision?

Why the holiday period is peak season for CEO fraud

Fraudsters know two things: in July and August the boss is harder to reach, and normal procedures tend to get more relaxed. Someone who usually needs three sign-offs for an invoice is far more likely to hear "can you just handle it?" in the summer. That's precisely the gap being exploited.

The approach is almost always the same:

  • A message from a "familiar" contact (director, accountant, major client) from an unknown number or email address.
  • A story explaining why the usual channel isn't available: "my phone was stolen", "I'm abroad with no Wi-Fi", "I'm in a meeting".
  • Time pressure: it needs to happen today, ideally within the hour.
  • A request that falls just outside normal procedure: a payment to a new account number, buying gift cards, or passing on login credentials.

What makes this clever is that almost no technical tricks are involved. No hacked accounts, no viruses. Pure social manipulation through a channel you can't verify.

Five checks before you take any action

1. Call back on the number you already know

Not the number the message came from. Look the number up in your own contacts or on the company website. Getting voicemail? Wait. "I'm in a meeting and can't talk" is a classic fraudster's excuse.

2. Check the email address character by character

Fraudsters register domains that look almost identical: jansen-bv.nl instead of jansenbv.nl, or a capital I instead of a lowercase l. If in doubt, paste the address into a text editor and increase the font size.

3. Ask something only the real person would know

Not something from LinkedIn or the company website. Something from a recent conversation: "which project were you calling about yesterday?" A fraudster will usually drop the conversation at that point — or get annoyed ("no time for games").

4. Never trust a change of bank account details received by email or message

A new account number must always be verified by phone, using the number you already had on file. This applies to colleagues too. We wrote earlier about this specific trick.

5. Bring in a second person

Even if it seems urgent: having a colleague take a quick look takes two minutes. Fraudsters count on you being alone. A second pair of eyes almost always breaks the pattern.

What should you agree on within your organisation?

The most important protection isn't technical — it's clear agreements that everyone knows. Especially the people holding the fort over the summer.

  • Four-eyes principle for payments above a set amount. For example: anything over €500 requires sign-off from two people, even if the director calls personally.
  • No changes to bank details via email or messaging apps. Full stop. Only by phone, on the number you already know.
  • A code word for emergencies. It sounds over the top, but it works. If someone contacts you "out of office" with an unusual request, they must provide the code word.
  • Holiday cover is clearly defined. Who makes decisions when the director is away? And who definitely doesn't? Write this down before the holiday starts.
  • Report suspicious messages internally. Even if you didn't fall for it. That way colleagues know something is doing the rounds.

Getting the technical basics right

Agreements are the foundation, but a few technical measures do make life harder for fraudsters:

  • SPF, DKIM and DMARC configured on your mail. This makes it much harder to send messages that appear to come from your own domain. See our email security service.
  • 2FA on all business accounts. A stolen password alone won't be enough. See implementing 2FA.
  • Verify IBANs before making a payment. Our IBAN check quickly shows whether an account number is valid and which bank it belongs to.

What if something has already gone wrong?

If you discover within a few hours that a payment has gone to a fraudster, call your bank immediately — it is sometimes possible to recall a transfer. Also report it to the police and to the Fraud Helpdesk. And discuss it internally: how did this happen, and which agreement was missing? Not to point fingers, but to prevent it happening next year.

Summer is for switching off. Make sure your business is set up so that one absent decision-maker doesn't become a fraud opportunity. Not sure about your current email and access arrangements? Our access check maps out who can do what and where the risks lie.

Onderwerpen

#ceo-fraude #Mail Beveiliging #Fraudepreventie #Vakantieperiode #Betalingen

Volledige gids: Security for SMBs without an IT department: what should you do this quarter?

Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →