An organization can invest heavily in cybersecurity and still lose money if a legitimate user is deceived into doing what a fraudster wants. This is where the human side of cyber fraud begins.
Criminals do not always need to break into a system. Instead, they may manipulate the person who already has access, authority, or information.
Strong cybersecurity controls remain essential. However, systems alone cannot protect an organization when an authorized person is persuaded to misuse access or bypass verification.
Five Takeaways for Boards and Management
- Cyber-enabled fraud can succeed without defeating the underlying technology if an authorized user is manipulated into acting.
- Fraudsters often exploit authority, urgency, confidentiality, familiarity, and fear to influence human judgment.
- Strong authentication does not eliminate fraud risk when the authenticated person acts on a fraudulent instruction.
- Employees should be expected and supported to stop, verify, and question unusual requests involving money, credentials, access, or sensitive information.
- Controls should be designed so that no single convincing message, call, or apparent instruction can authorize a high-risk transaction.
A Familiar Cyber Fraud Scenario
A finance employee receives an email that appears to come from the CEO. It refers to a confidential transaction and instructs the employee to transfer funds urgently. The employee is told not to discuss the matter because only a small group knows about it.
The name is correct. The message appears familiar. The request carries authority and urgency.
The employee has legitimate access to the payment system and is authorized to initiate transactions.
Nothing necessarily needs to be technically broken. Instead, the fraud succeeds if the employee is persuaded to use legitimate access in response to a fraudulent instruction.
Cybersecurity and Anti-Fraud Governance Ask Different Questions
Cybersecurity Asks:
Can an unauthorized person get into the system?
Anti-Fraud Governance Must Also Ask:
Can a criminal persuade an authorized person to use the system improperly?
That distinction matters because the system may recognize valid credentials but still be unable to determine whether the person using them has been deceived.
When Phishing Captures Trusted Access
According to the U.S. Department of Justice (2021), an executive at Unatrac Holding Limited fell victim to a phishing email in April 2018, enabling conspirators to obtain login credentials and submit fraudulent wire-transfer requests supported by fake invoices. The DOJ reported that fraudulent wire transfers associated with the effort to victimize Unatrac totaled nearly US$11 million. The DOJ further reported that Obinwanne Okeke pleaded guilty and was sentenced in 2021 to 10 years in prison.
The lesson is clear: cyber fraud can begin by manipulating the person who holds legitimate access. A legitimate user may be deceived, enabling fraudsters to capture valid credentials and use them to facilitate fraud.
When Apparent Authority Replaces Verification
According to the U.S. Department of Justice (2018), Adeyemi Odufuye and others were involved in emails sent to the controller of a company in Torrington, Connecticut, that appeared to originate from the company’s CEO and requested wire transfers. The DOJ reported that the company made five transfers totaling more than US$500,000. The DOJ further reported that Odufuye pleaded guilty and was sentenced to 45 months in prison.
The governance lesson is equally important: apparent seniority should increase verification discipline, not replace it.
Competent Questioning before Action
This is precisely where Competent Questioning becomes operational (Masoud, 2026). Before acting on an unusual digital instruction, employees should ask:
Who is actually asking me to act?
Does this request fit normal business activity?
Why is urgency or confidentiality being emphasized?
Why is the established process being changed or bypassed?
Can I independently verify the instruction through a previously established channel?
Would I make the same decision if the apparent sender were not a senior executive?
Digital authenticity should never substitute for competent verification.
Five Controls Organizations Should Consider
- Require independent verification for material or unusual instructions involving payments, account changes, credentials, access, or sensitive information.
- Do not verify a questionable instruction through the same channel that delivered it.
- Require additional verification for changes to beneficiary or payment instructions.
- Separate initiation from authorization where transaction risk warrants it.
- Give employees explicit authority to stop and question unusual requests without fear of penalty for reasonable verification.
What Boards Should Ask
Boards should ask:
Are we relying on employees to spot a fake request instead of requiring independent verification before money, credentials, access, or sensitive information can be transferred or disclosed?
And:
Which transactions could a criminal complete simply by convincing one authorized employee that the request is genuine?
One Hard Takeaway
The strongest cybersecurity technology cannot eliminate fraud risk when a criminal can manipulate an authorized person into using access, authority, or information against the organization.
Cyber fraud prevention therefore requires more than technical protection. It requires verification discipline, effective internal control, Competent Questioning, and a culture in which employees can stop an unusual request—even when it appears to come from someone powerful. In short, support people to verify before they act.
References
Masoud, M. (2026) Competent Questioning: An Anti-Corruption Governance Concept. The American Anti-Corruption Institute. Available at: https://www.theaaci.net/Competent-Questioning (Accessed: 28 September 2026).
U.S. Department of Justice (2018) ‘Nigerian National Sentenced to 45 Months in Federal Prison for Role in Business E-Mail Compromise Scheme’, U.S. Attorney’s Office, District of Connecticut, 12 December. Available at: https://www.justice.gov/usao-ct/pr/nigerian-national-sentenced-45-months-federal-prison-role-business-e-mail-compromise (Accessed: 28 September 2026).
U.S. Department of Justice (2021) ‘Nigerian National Sentenced to Prison for $11 Million Global Fraud Scheme’, U.S. Attorney’s Office, Eastern District of Virginia, 16 February. Available at: https://www.justice.gov/usao-edva/pr/nigerian-national-sentenced-prison-11-million-global-fraud-scheme (Accessed: 28 September 2026).
Disclaimer
This article is provided by The American Anti-Corruption Institute (AACI) for educational and informational purposes only and does not constitute legal, cybersecurity, audit, compliance, regulatory, or financial advice.
References to individuals, organizations, and legal proceedings are based on the official sources cited. Judicial outcomes are reported only as stated in those sources. Nothing in this article should be interpreted as an independent finding by AACI of fraud, corruption, misconduct, or criminal liability.
Case examples are used solely to illustrate anti-fraud governance, internal control, and corruption-prevention principles. Readers should consider the circumstances and applicable laws of their own jurisdictions and obtain professional advice where appropriate.







































