A hacked inbox's own AI assistant helped steal $247,500 by impersonating the CEO

A hacked inbox's own AI assistant helped steal $247,500 by impersonating the CEO

An AI assistant inside one compromised email account was enough to impersonate a CEO and move US$247,500 out the door, with no malware and no new access required. That's what a controlled test by email security company Barracuda found. The same failure is already showing up in real fraud cases beyond the lab.

The attack didn't need new tools, just faster ones

In a controlled test, Barracuda's Red Team compromised a single employee's email account, then used Microsoft Copilot to do the rest. Copilot built an inbox rule to hide sign-in alerts, mapped the org chart from email history and drafted a phishing email in the victim's own writing style, in a handful of prompts. From there, the attack escalated to full CEO account takeover and the US$247,500 wire fraud. The attackers needed no malware and no new privileges; the AI assistant simply did exactly what it was built to do, for the wrong person. This isn't a fringe scenario. Business Email Compromise (BEC) losses reported to the FBI's Internet Crime Complaint Center came in just under US$2.8 billion for 2024, and email remains one of the most common routes into that kind of fraud.

This isn't limited to compromised inboxes, either. In April, the CEO of a Singapore-based firm authorised a US$36.3 million transfer after a WhatsApp call from someone posing as his own chairman (Eftsure has already looked at what that case reveals about approval culture). Both failed for the same reason: nothing in the process asked anyone to confirm the request through a channel the attacker didn't already control.

Verification stayed inside the channel that was already compromised

Once inside the CEO's own mailbox, what the attackers did with Copilot there should worry finance teams more than the initial phishing. A single prompt asking Copilot for a refresher on financial emails pulled up wire transfer documents and outstanding invoices in seconds, including one live payment still awaiting final approval. From there, the attackers impersonated the CEO to the finance team, asked for a bank detail change on that exact transaction, and quietly rerouted the CEO's inbox replies so nothing looked out of place. Nothing about the email would have triggered a flag: it came from a real, authenticated account, referenced an actual pending payment and sounded exactly like the CEO always did. With every signal pointing to a legitimate request, the finance team made the change and released the transfer, sending the funds straight into the attacker's account.

The request to change the bank details and the apparent confirmation that it was legitimate both came from the same compromised email account. When the channel itself is the attacker's foothold, checking that same channel more carefully will not catch the fraud.

Four-step diagram: an employee's inbox is compromised, the AI assistant hides the break-in, a bank change request appears to come from the CEO, and $247,500 is wired to the attacker.

Verify outside the channel that's already under attack

Email filtering helps at the perimeter, but a bank detail change also needs independent verification, regardless of how convincing the email's tone is or how closely it matches a real transaction. That means verifying supplier and payee bank details through a second, independent channel, and checking that verification continuously, not just once at onboarding, so a change slipped in mid-relationship gets caught before the payment goes out, not after. The Singapore WhatsApp case shows what that looks like even after the fact: the fraud only came apart once the CEO called his chairman's real number and heard him deny the request, four days and US$36.3 million after the first transfer. Applying that same check earlier in the process is what would have stopped it before the money moved.

Trust in the channel is no longer enough

Eftsure exists for exactly this gap: a payment assurance layer that verifies who you're actually paying before money moves, independent of whichever inbox, phone call or video meeting happens to be carrying the request. As AI makes it faster and cheaper to fake a trusted voice, face or writing style, the channel a request arrives through matters less than whether the payee behind it has been independently confirmed. See how Eftsure verifies bank details through a channel the attacker never controls.

Author

Catherine Chipeta

Published

13 Aug 2026

Reading Time

4 minutes

security-image

The New Security Standard for Business Payments

security-image
security-image