CEO Fraud: How We Stopped R87k Invoice Scam With 2 Free Rules
Finance received an email from the “CEO” asking to pay a supplier urgently. It was a lookalike domain + hidden inbox rule. Here's the 2 free Exchange rules that stop 99% of these.
The attack: Accounts received email from ceo@nextgridtechnologiez.co.za (note the extra z) — display name “Clem Chikanya”. Real email thread from supplier was hijacked, new banking details inserted. Finance almost paid R87,430.
What we found in M365 audit:
- No anti-impersonation policy for CEO / Finance
- No external email banner — staff couldn't see it was external
- Compromised mailbox had hidden rule: “If from finance, forward to external Gmail and mark as read”
- Safe Links was OFF — link to fake banking letter wasn't scanned
2 Free Rules we enabled (Business Standard + Premium):
- Anti-impersonation for CEO + Finance: Exchange Admin > Anti-phishing policy > Add impersonated users (CEO, Finance Manager) + Enable mailbox intelligence + Enable spoof intelligence. Quarantine if impersonated.
- External banner + Safe Links: Transport rule: If sender is external, prepend [EXTERNAL] + warning. Defender > Safe Links > Enable for email + Teams + Rewrite URLs at click time.
Result: Next week same attacker tried again — email quarantined automatically, banner visible, Safe Links blocked click. Finance now calls supplier on known number to verify any bank change — 30-sec process we added to POPIA manual.
Our M365 Secure package at R450/user enables both + monthly impersonation report. Part of R950 Health Check — we check these 2 rules in 5 minutes. Call +27 76 948 9154.
Want this as a checklist?
Download the free CEO Fraud Prevention Checklist — 2 rules + finance verification script.
Secure Your Microsoft 365 Before Hackers Do
Book the R950 POPIA Health Check — 2hr on-site, plain-English report.
