Executive Impersonation Texts and Urgent Wire or Gift Card Requests

A text that looks like it is from the owner asking for a quick favor is a common fraud setup. Teach staff to spot it and what to do instead.

3 min readBy Ironfield Cyber Team

A project coordinator gets a text from an unfamiliar number: "This is the boss, I'm in a meeting and cannot talk. I need a favor." Soon it becomes a request for gift cards, an urgent wire, or a change to a payment. The scammer knows the owner's name from the company website and counts on loyalty and speed to do the rest.

Executive impersonation is among the oldest and most reliable fraud tactics. It succeeds because it exploits trust and hierarchy, not technology. Defending against it is mostly a matter of culture and procedure.

What these scams look like

Common patterns include:

  • A text or email claiming to be from the owner, president, or a senior leader, often from a new number or look-alike email address
  • A claim that the executive is traveling, in a meeting, or unable to talk
  • A request for secrecy or speed, framed as a favor or a confidential deal
  • Requests for gift cards, wire transfers, vendor payment changes, or sensitive employee data
  • Pressure to bypass normal approval, with a hint that questioning will be unwelcome

The FBI's Internet Crime Complaint Center has long described business email compromise and impersonation as a major source of losses, and the same pattern applies across email, text, and messaging apps.

Why people fall for it

Employees want to be helpful and fear disappointing leadership. Small companies and tight-knit crews are especially vulnerable, since the boss really does sometimes ask for quick favors. Scammers also gather details from social media and company websites, such as names, roles, and who reports to whom, to sound credible.

Policies that remove the pressure

A clear rule for unusual requests

Adopt a simple, publicly stated rule: no payment, banking change, gift card purchase, or sensitive data transfer is made on the basis of a text, email, or chat alone, regardless of who appears to be asking. Verification by a call to a known number is always required.

Leadership endorsement

Executives should say out loud, and put in writing, that staff will never be criticized for verifying a request, even one that appears to come from them. Without this, the policy is just paper.

Real approval workflows

Payments should flow through documented approval steps with dual authorization above defined limits. An executive's request for an exception should still be verified and logged.

Limit what can be bought

Where practical, restrict gift card purchases on company cards, and set purchase controls so large unusual transactions require sign-off.

What staff should do

  1. Pause. Urgency and secrecy are warning signs, not reasons to hurry.
  2. Check the sender. Look at the actual number or email address, not just the display name.
  3. Verify through a different channel. Call the executive on a known number, or ask in person.
  4. Do not reply to the suspicious message with details or to challenge the sender.
  5. Report it to IT or the designated contact so others can be warned.
  6. Screenshot and save the message for follow-up.

Reduce what scammers can learn

  • Limit detailed org charts and direct contact information on public pages where practical.
  • Remind leaders that public posts about travel or schedules can be used against them.
  • Be cautious about phone numbers published in public directories.

Do not overdo this. Companies need to be reachable. The point is awareness, not secrecy.

Technical protections

  • Enable multifactor authentication on email so real accounts are harder to take over.
  • Configure email authentication, such as SPF, DKIM, and DMARC, and add warnings on external senders using display names that match employees.
  • Consider registering look-alike versions of your domain name, or monitoring for them.
  • Use mobile device policies that help staff identify company-issued numbers.

If someone already sent money

Move quickly. Contact your bank immediately to try to recall or freeze the transfer, preserve all messages, report to law enforcement and the FBI's Internet Crime Complaint Center, and notify your insurer according to your policy. Speed improves the odds, but recovery is not guaranteed.

Where Ironfield Cyber fits

Ironfield Cyber helps contractors and energy firms tighten email protections, write simple verification policies, and train staff with realistic examples. If you want help rehearsing this scenario with your office team, we are happy to run a short session.