How do I spot an email pretending to be from a colleague?
The name is your boss's, the address isn't. Four ten-second checks, the Swiss figures on email fraud and what to do if you've already replied.
“Hi, are you in the office? I need a quick favour, I’m writing here because I’m in a meeting.” The name is your boss’s. The tone is almost theirs. And two messages later the request is always the same: a payment, an IBAN to change, some gift cards.
How does a fraudster pass themselves off as a colleague?
In three ways, from the simplest to the sneakiest:
- The display name. The sender chooses the name you see, freely: “Marco Rossi” can come from any address at all. On a phone you often see only the name.
- An almost identical domain.
company-ltd.chinstead ofcompany.ch, or anlinstead of ani. Read in a hurry, it looks right. - The real mailbox, compromised. If a colleague’s password has been stolen, the message comes from their genuine address, sometimes inside a real conversation.
What should I check before replying to a suspicious email?
Four things, and it takes ten seconds:
- Look at the address, not the name. Tap or hover over the sender and read the domain letter by letter.
- Look at where the reply goes. If the recipient changes when you press “Reply”, that’s a strong warning sign.
- Be wary of urgency and secrecy together. “Right now” plus “don’t tell anyone” is the signature of this scam.
- Confirm every request for money or data by voice. Call your colleague on a number you already know, never the one in the email.
The last check is the only one that also works against a compromised mailbox. Make it a written company rule: that way nobody feels rude calling the boss.
How common is email fraud in Switzerland?
Very, and it’s growing. According to the police crime statistics of the Federal Statistical Office (FSO), reports of phishing rose from 642 in 2020 to 7,409 in 2025. CEO fraud has its own category: 560 reports in 2025, and only 5.5% of cases were solved.
These are reports, not attacks: many companies don’t report, so the real numbers are higher. At European level, the cybersecurity agency ENISA identifies phishing as the way in for around 60% of the incidents analysed in its 2025 report.
Aren’t spam filters enough?
They help, but they don’t see everything. Technical domain checks (SPF, DKIM, DMARC) can stop anyone forging your company’s real domain, if the domain is set up to have forged messages rejected. They don’t stop an almost identical domain registered for the purpose, and they can’t stop a message sent from a genuine mailbox.
That’s why your defence has two layers: a serious filter before the mailbox, and an email program that helps you see what you’re actually reading.
What does Akomodix do against fake emails?
On Akomodix, mail from the internet goes through the CybeTower anti-spam and anti-virus gateways, another product of ours, before it reaches the server. In the Akomodix apps, for web, iPhone, Android and desktop, you see clear warnings when a sender pretends to be someone else, and before you open a link you see the real site.
But you can bring in the most effective check tomorrow morning, without buying anything: write the rule “every payment request by email gets confirmed by phone” in one line and send it to everyone. The next attempt won’t warn you first.
Frequently asked questions on this topic
What is CEO fraud?
It's an email pretending to come from the owner or a manager, asking for an urgent, confidential payment, a change of IBAN or the purchase of gift cards. Swiss police crime statistics list it separately: 560 reports in 2025, of which only 5.5% were solved by the police. One rule stops it: every request for money by email gets confirmed by voice.
If the email comes from my colleague's real address, can I trust it?
Not always. If your colleague's mailbox has been compromised, the fraudster writes from their real address, often replying within a genuine conversation. In that case the address is right and everything else is off: an unusual tone, urgency, a new IBAN, an unexpected attachment. A phone check is still the only test that always works.
I replied or clicked: what do I do now?
Tell whoever handles IT straight away and, if you entered a password, change it from another device. If you made a payment, call your bank immediately: sometimes a transfer can still be stopped. Then report the case to the Swiss Federal Office for Cyber Security (FOCS), or outside Switzerland to your national reporting service, and, if there's been a loss, file a report with the police.