On-site Pretoria, Midrand, Centurion, Johannesburg | Anywhere else - Remote Avg response <1hr • +27 76 948 9154
+27 76 948 9154WhatsApp
NextGrid
NextGrid
Technologies
Back to Blog
CEO Fraud • BEC12 Jul 2026 • 5 min read • Updated 25 Jul 2026

CEO Fraud: How We Stopped R87k Invoice Scam With 2 Free Rules

Finance received an email from the “CEO” asking to pay a supplier urgently. It was a lookalike domain + hidden inbox rule. Here's the 2 free Exchange rules that stop 99% of these.

The attack: Accounts received email from ceo@nextgridtechnologiez.co.za (note the extra z) — display name “Clem Chikanya”. Real email thread from supplier was hijacked, new banking details inserted. Finance almost paid R87,430.

What we found in M365 audit:

2 Free Rules we enabled (Business Standard + Premium):

  1. Anti-impersonation for CEO + Finance: Exchange Admin > Anti-phishing policy > Add impersonated users (CEO, Finance Manager) + Enable mailbox intelligence + Enable spoof intelligence. Quarantine if impersonated.
  2. External banner + Safe Links: Transport rule: If sender is external, prepend [EXTERNAL] + warning. Defender > Safe Links > Enable for email + Teams + Rewrite URLs at click time.

Result: Next week same attacker tried again — email quarantined automatically, banner visible, Safe Links blocked click. Finance now calls supplier on known number to verify any bank change — 30-sec process we added to POPIA manual.

Our M365 Secure package at R450/user enables both + monthly impersonation report. Part of R950 Health Check — we check these 2 rules in 5 minutes. Call +27 76 948 9154.

Want this as a checklist?

Download the free CEO Fraud Prevention Checklist — 2 rules + finance verification script.

Free CEO Fraud Checklist PDF ↓
Need help implementing? Book the R950 Health Check — we enable both rules in 15 minutes on-site. Book R750 launch →

Secure Your Microsoft 365 Before Hackers Do

Book the R950 POPIA Health Check — 2hr on-site, plain-English report.

Book R950 Check