CEO fraud in Chur: apprentice narrowly avoids 1,000-franc scam

Cybercriminals posed as the boss of a Chur recruitment agency via email and demanded that a 16-year-old apprentice purchase Apple gift cards worth 1,000 francs.

CEO fraud in Chur: apprentice narrowly avoids 1,000-franc scam

Forged boss email targets Chur apprentice

Cybercriminals nearly defrauded a 16-year-old apprentice in Chur of 1,000 francs by posing as his superior in an email. Blick reports on the case involving Nathalie von Arx (39), owner of the recruitment agency Prime International Jobs, and her apprentice Linus S.*, who recognised the scam at the last moment.

S. had begun his commercial apprenticeship only a few weeks earlier when he received an email one morning. The sender appeared to be von Arx. The tone was casual: "Hi Linus. How are you? I have a confidential request and need your help," it said – with a note that the boss was in a meeting and could only respond by email.

S. knew that von Arx was indeed in a meeting, and replied unsuspectingly. The actual demand then became clear: he was to purchase Apple gift cards from various shops totalling 1,000 francs, scratch off the PIN codes, and send photos of them back along with the receipts. The reason given was that it was a surprise for particularly diligent employees.

When S. asked questions and demanded a telephone conversation, the tone became harsher. He was to obtain the cards "immediately"; if 1,000 francs was too much, he should buy what he could afford. S. nonetheless called von Arx – and thereby uncovered the fraud. The sender turned out to be an obscured Russian email address.

"My name was misused to defraud my apprentice," said von Arx. S. described his impression to Blick: "The message seemed deceptively genuine, caught me off guard and put me under pressure." He only truly got over the shock of narrowly escaping the fraud a few days later. "I want to warn other apprentices so they are even more careful."

Authorities warn of targeted attacks on career starters

The Federal Office of Cybersecurity (Bacs) refers to this method as "CEO fraud" and notes that apprentices, interns and new employees are particularly frequently targeted. According to a spokeswoman for the authority, these individuals are particularly attractive to fraudsters: "They are new to the company, do not yet know internal procedures and contact persons well, want to make a good impression and therefore rarely question unusual instructions."

The perpetrators obtain the necessary names without technical hacking knowledge. Platforms such as LinkedIn, where companies welcome new employees or staff report their job changes themselves, provide the information readily available. Company websites with staff portraits – such as von Arx's – also serve as a source.

Bacs does not generally advise against publishing such information, but emphasises: "It is important to be aware that every piece of public information can be a building block for fraudsters in later attacks." Artificial intelligence additionally makes it easier for attackers to automatically evaluate public data and thus quickly create personalised, seemingly credible messages. "Attacks are becoming increasingly personalised," predicts Bacs.

Clear processes as protection

The authority recommends that companies specifically inform new employees, apprentices and interns about fraud attempts. They should also establish binding internal rules governing the conditions under which payments can be authorised or information shared – for example, that payment instructions should generally not be made by email.

Bacs recommends that employees always verify unusual or urgent requests via an independent, known channel. That is exactly what Linus S. did: he picked up the telephone – and thereby prevented the loss.

*Name known to the editorial team.

Source: Blick

Read this article in the original language