The threat of CEO fraud and one NGO's resilient response

The threat of CEO fraud and one NGO's resilient response | GZERO Media

In January 2020, Heidi Kühn, founder and CEO of Roots of Peace, returned from an overseas trip to devastating news: her finance department had unwittingly transferred over $1 million to an unfamiliar bank account. Kühn and her team quickly realized they’d become victims of a CEO fraud cyber attack—cybercriminals had infiltrated the company’s email accounts via spear phishing and impersonated Kühn to trick the finance team into sending funds abroad.

The theft had an enormous impact on Roots of Peace, a nonprofit dedicated to converting minefields into arable farmland in former war zones. Following the attack, Roots of Peace reached out to the CyberPeace Insitute, an organization that provides free cybersecurity assistance, threat detection and analysis to NGOs and other critical sectors. Roots of Peace was able to recover some of the funds, but to date, only $175,000 of the $1.34 million total stolen has been returned.

Roots of Peace is an international humanitarian organization, but their story isn’t unusual: In 2021, CEO fraud caused $2.4 billion in losses to US businesses alone, according to the FBI Internet Crime Report. Kühn’s story is featured in the second episode of “Caught in the Digital Crosshairs: The Human Impact of Cyberattacks,” a new video series on cyber security produced by GZERO in partnership with Microsoft and the CyberPeace Institute. GZERO spoke with Kühn and Derek Pillar, a cyber security expert from Mastercard, to learn more about the threat of CEO fraud, the real-life impact of cyberattacks against the humanitarian sector, and how you can prevent similar attacks from happening to you and your organization.

More from GZERO Media

Malawi soldiers part of the Southern African Development Community (SADC) military mission for eastern Congo, wait for the ceremony to repatriate the two bodies of South African soldiers killed in the ongoing war between M23 rebels and the Congolese army in Goma, North Kivu province of the Democratic Republic of Congo February 20, 2024.
REUTERS/Arlette Bashizi

Fighters from the M23 rebel group in northeastern Congo have been targeting civilians in violation of a July ceasefire agreement, according to the Southern African Development Community, whose peacekeeping mandate was extended by a year on Wednesday.

Ari Winkleman

Donald Trump has promised a laundry list of things he will accomplish “on Day 1” in office. To name a few, he has vowed to immediately begin a mass deportation of immigrants, streamline the federal government, pardon Jan. 6 rioters, and roll back the Biden administration’s education and climate policies.

Ambassador Robert Wood of the US raises his hand to vote against the ceasefire resolution at the United Nations Security Council, on November 20, 2024.
Lev Radin/Sipa USA, via Reuters
- YouTube

Ukraine has launched US-made long-range missiles into Russia for the first time. Will this change the course of the war? How likely will Trump be able to carry out mass deportations when he's in office? Will there be political fallout from Hong Kong's decision to jail pro-democracy activists? Ian Bremmer shares his insights on global politics this week on World In :60.

A man rushes past members of security forces during clashes between gangs and security forces, in Port-au-Prince, Haiti November 11, 2024.
REUTERS/Marckinson Pierre

The UN Humanitarian Air Service is scheduled to restart flights to Haiti on Wednesday, a week after several planes attempting to land at Port-au-Prince airport came under small arms fire.