Email

msanders@acme-inc.co

First reported 2026-03-20
Last reported
Victims 5
Est. losses $487,000
92
Risk score / 100
High risk — CEO impersonation

Why we flagged this

Matched across multiple trusted sources and community reports.

⚠ FBI IC3 — active 5 community reports Category: Business Email Compromise →

Community reports (5)

Real stories from verified victims. Most recent first.

Finance manager · Dallas, TX · lost $87,000

An email from our CEO said he was about to board a flight and needed me to wire $87k to a new vendor 'today, confidential.' Same writing style. Same signature. The domain was off by one letter.

Lookalike domain

How this scam type works

From our Business Email Compromise guide.

  1. Reconnaissance. Attackers study your company's public org chart, vendor relationships, and email patterns (often from LinkedIn).
  2. Account compromise or spoofing. They either hack a real executive's email via phishing or register a lookalike domain (acme-inc.co instead of acme-inc.com).
  3. The urgent request. 'Hi, I'm about to board a flight — I need you to wire $87,000 to this new vendor today. Confidential, don't loop in anyone else.'
  4. New banking details. Legitimate vendor suddenly sends 'updated wiring instructions' — but they're from the attacker's lookalike domain.
  5. The wire, gone in minutes. Recovery is nearly impossible once funds hit the receiving account.

Take action

Report your experience

Also report to

Official channels where this matters.

  • FBI IC3ic3.gov
  • FTCreportfraud.ftc.gov
  • Chainabusechainabuse.com
🚨 Report a Scam