- Barbora Arnold
- 4 min read
Few cyberattacks on companies today are technical masterpieces. It is far easier for an attacker to write in a supplier's name, call pretending to be a manager, or use the false identity of a well-known institution. They rely on haste, authority, and employees' natural willingness to comply. The goal need not be just a clicked link, it may be an approved payment to a fraudulent account, a change to a supplier's bank details, or the release of access credentials. And that is exactly what corporate cyber fraud looks like today. It starts with an ordinary message, phone call, or request that seems trustworthy. How can you defend against it?
Fraud that looks like ordinary work communication
Corporate cyber fraud increasingly presents itself as a routine work request. It need not even contain a suspicious link, an attachment, or any technically sophisticated element. Often all it takes is a well-written message, the right tone, and a request that at first glance fits into the company's day-to-day operations. That is precisely where its strength lies. The attack does not look like a security threat, but like ordinary business: something to confirm, change, approve, or handle urgently.
Attacks of this kind are now among the most common threats facing Czech organisations. According to NÚKIB, more than 90 % of them have encountered phishing and fraudulent emails. In its most recent report for 2024, it records a record 268 cyber incidents handled directly by NÚKIB. In its report for 2025, the Ministry of the Interior states that crime committed in cyberspace rose year on year by 14.3 %. A total of 21,137 registered offences committed in cyberspace were recorded in 2025.
The figures themselves, however, are not the most important thing. What matters above all is that the nature of the attacks is changing. Among the main trends, the Ministry of the Interior lists the mass use of artificial intelligence and exploitation of the human factor, that is phishing, deepfake and social engineering. Attackers are also making greater use of trust, urgency, and knowledge of how organisations normally operate.
🔗 NÚKIB: Report on the State of Cybersecurity in the Czech Republic for 2024
🔗 Ministry of the Interior of the Czech Republic: Report on the Internal Security Situation for 2025 (clicking the link will download the report automatically)
CEO fraud: when the attacker poses as company management
One of the best-known forms is what is known as CEO fraud – a scam in which the attacker acts in the name of company management. This may involve, for example, a request for an extraordinary payment, a change to the account number on an invoice, or the rapid handling of a sensitive request. The attacker relies on authority, urgency, and trust in internal communication. If a request appears to come from a manager, an employee under time pressure may act on it without further verification.
What makes this dangerous is that such a request no longer has to come from an obviously suspicious address. Attackers may be working with a compromised account or a very convincing imitation of someone's identity. The message can therefore look as though it genuinely came from a colleague, a manager, or a supplier.
Artificial intelligence makes attacks more credible
The Czech language used to give companies a certain advantage. With many fraudulent emails, it was fairly easy to spot poor grammar, unnatural turns of phrase, or odd styling. Artificial intelligence tools, however, are gradually erasing that advantage.
Fraudulent messages today come across as far more naturali and professional, and blend more easily into everyday operations. Generative AI makes it easier for attackers to prepare texts that do not look like a typical scam email. What is more, the risk is not limited to email. Attackers also use voice, video, or a combination of several channels. Telling what is real and what is not will therefore become increasingly difficult even for company employees.
Why telling employees "don't click on links" is not enough
Warning employees to watch out for suspicious links still makes sense, but on its own it is not enough. Many of today's scams are not primarily aimed at getting a click. They are aimed at a decision: approving a payment, changing a supplier's account, setting up access, or confirming a request that looks urgent.
The risk therefore does not arise solely with the individual who might make a mistake. It also arises wherever a company has no clearly defined procedure for verifying sensitive requests. If it is not clear how a change of bank account, an extraordinary payment, or a non-standard request from management is to be verified, security remains largely dependent on an employee making the right decision under stress.
The risk therefore does not arise solely with the individual who might make a mistake. It also arises wherever a company has no clearly defined procedure for verifying sensitive requests.
That is precisely why it is necessary to address not only individual vigilance, but also simple rules: who approves what, how changes to details are verified, and when an employee should rather stop the process and verify the request through a different channel. For example:
- verify a change to a supplier's bank account through a channel other than the one the request came through,
- have an extraordinary payment confirmed by a second person,
- verify a request from management that falls outside the standard procedure via a predetermined contact,
- make it clear to employees that stopping a suspicious request is not causing delays, but following the correct procedure.
- This content was prepared with the help of AI and subsequently underwent thorough human editing and fact-checking.