The threat of CEO fraud and one NGO's resilient response

The threat of CEO fraud and one NGO's resilient response | GZERO Media

In January 2020, Heidi Kühn, founder and CEO of Roots of Peace, returned from an overseas trip to devastating news: her finance department had unwittingly transferred over $1 million to an unfamiliar bank account. Kühn and her team quickly realized they’d become victims of a CEO fraud cyber attack—cybercriminals had infiltrated the company’s email accounts via spear phishing and impersonated Kühn to trick the finance team into sending funds abroad.

The theft had an enormous impact on Roots of Peace, a nonprofit dedicated to converting minefields into arable farmland in former war zones. Following the attack, Roots of Peace reached out to the CyberPeace Insitute, an organization that provides free cybersecurity assistance, threat detection and analysis to NGOs and other critical sectors. Roots of Peace was able to recover some of the funds, but to date, only $175,000 of the $1.34 million total stolen has been returned.

Roots of Peace is an international humanitarian organization, but their story isn’t unusual: In 2021, CEO fraud caused $2.4 billion in losses to US businesses alone, according to the FBI Internet Crime Report. Kühn’s story is featured in the second episode of “Caught in the Digital Crosshairs: The Human Impact of Cyberattacks,” a new video series on cyber security produced by GZERO in partnership with Microsoft and the CyberPeace Institute. GZERO spoke with Kühn and Derek Pillar, a cyber security expert from Mastercard, to learn more about the threat of CEO fraud, the real-life impact of cyberattacks against the humanitarian sector, and how you can prevent similar attacks from happening to you and your organization.

More from GZERO Media

A 24-hour Yonhapnews TV broadcast at Yongsan Railway Station shows South Korean President Yoon Suk Yeol delivering a speech at the Presidential Office in Seoul. South Korean President Yoon Suk Yeol, defended his botched martial law declaration, as an act of governance and denied insurrection charges facing him, while vowing to fight until the last moment against whether it is impeachment or a martial law probe.
Kim Jae-Hwan / SOPA Images via Reuters Connect

South Korean President Yoon Suk Yeol looks highly likely to be impeached on Saturday after the leader of his own party on Thursday told members to vote according to their “conviction and conscience.”

Turkish President Tayyip Erdogan poses with Somali President Hassan Sheikh Mohamud and Ethiopian Prime Minister Abiy Ahmed following a press conference in Ankara, Turkey, December 11, 2024.
Murat Kula/Presidential Press Office/Handout via REUTERS

Ethiopian President Abiy Ahmed and Somali President Hassan Sheikh Mohamud announced a critical agreement to end a yearlong dispute over Ethiopia’s access to the Arabian Sea.

Press conference about Romania and Bulgaria, former Soviet Bloc countries becoming EU members.
REUTERS/Bernadett Szabo

For Romania and Bulgaria, former Soviet Bloc countries that are now EU members, the light finally changed from red to green on Thursday as EU interior ministers agreed to let the two countries fully join the border-free Schengen zone on Jan. 1.

U.S. President Donald Trump attends a bilateral meeting with China's President Xi Jinping during the G20 leaders summit in Osaka, Japan, June 29, 2019.
REUTERS/Kevin Lamarque

US President-elect Donald Trump has extended an unprecedentedinvitation to Chinese President Xi Jinping to attend his inauguration in Washington, DC, on Jan. 20, 2025.

Luisa Vieira

GZERO Publisher Evan Solomon responds to comments made by two of our top 2024 game changers, Donald Trump and Elon Musk, about cutting foreign aid. “A dramatic turn to US isolationism in a world of crisis,” Solomon writes, “would be a troubling, game-changing trend that would only make the US more vulnerable.”