Back to Blog

The Six Roles Attackers Target Most, and Why

Cyber criminals target specific roles within companies, exploiting their access to finances, data, and systems. Learn how to protect these key positions.

Cyber criminals do not attack companies. They attack people, often one specific person doing one specific job. 

Real cases from the Nordic and Baltic region show a clear pattern. Attackers do not send the same message to everyone. They study what a role can do. Can this person approve a payment? Reset a password? Ship new code? Hire someone? Wire company money? Then they build the attack around that one power. 

Six roles carry most of this risk: Finance, HR and Payroll, IT Admins, IT Helpdesk, DevOps, and Executives. Below is what happened when each role was targeted. These are real, documented cases. To protect the companies involved, we removed their names. The facts, dates, and numbers are real and come from public news reports.

CFO

Finance: A Fake CEO Email Cost 130 Million Kroner 

In late 2019, the general manager at the Norwegian arm of a European energy company got a string of emails. The sender claimed to be the CEO of the Italian parent company. The story was simple. A secret deal was underway in China. The instructions were strict. Communicate only in writing. Tell no one, not even by phone. 

Over two weeks, the general manager approved 13 separate payments[1]. The total came to about 130 million Norwegian kroner, or roughly 11 million euros. The money went to two new shell companies in Hong Kong. The company had never sent money to Hong Kong before. By the time anyone noticed, most of the money was gone. Two Italian fraudsters, aged 29 and 30, were later extradited from Israel, and each received a six-year prison sentence, which both accepted[2].

In 2024, the Norwegian Supreme Court ruled that the bank was not at fault[3], even though the company had been mistakenly left out of the bank's automatic fraud detection system ("fraud engine") from November 2015 onwards[4]. The lower courts had earlier found Danske Bank negligent, but the Supreme Court overturned that outcome[5], leaving Edison to bear the loss[6]. 

The attackers did not hack a computer. They hacked trust and chain of command. Every warning sign got reframed as proof the general manager had been chosen for something important. Secrecy meant the deal was significant. Urgency meant opportunity. No phone calls meant discipline. A framework agreement with the bank contemplated dual authorization for account transfers, but the general manager had sole signing authority for the company, and the finance manager actively pushed the transactions through. Nobody picked up the phone to confirm a transfer of this size to a country the company had never paid before. 

This is exactly what finance teams need to train for. Not generic phishing awareness, but the real pattern behind fake CEO emails and fake invoice payments aimed at the people who can move money. 

 

HR and Payroll

HR and Payroll: A LinkedIn Update Almost Redirected a Paycheck 

In the spring of 2024, an employee at a large Norwegian phone and internet company updated their job title on LinkedIn[7]. It was a small, proud update. Within days, criminals noticed the change and moved fast. They pretended to be that employee and emailed the company's HR team. The message said the employee had switched banks and needed their paycheck sent to a new account. The email mentioned the real job change to sound believable. It included bank details that belonged entirely to the criminals. 

If HR had processed this request without checking, the next paycheck would have gone straight to the criminals instead. The scam was caught only because HR had a required verification step for any request to change payment details[8]. 

LinkedIn works like a public notice board. It shows who works where and what just changed for them. A title update tells a criminal that a real person just had a career moment. It also tells them that HR is probably already in touch with that person, so a follow up email about updating account details will feel routine instead of suspicious. The real weak point is not a hacked system. It is the simple assumption that an email from someone you recognize is really from that person. This is the exact blind spot behind direct deposit scams and fake new hire schemes. 

IT Admins

IT Admins: Even a Security Company Got Talked Past MFA 

On the night of 19–20 February 2022, attackers targeted a Swedish company that makes security technology. Yes, even a security company. Using social engineering, the attackers signed in as a user despite protective mechanisms such as multi factor authentication[9]. They then elevated their access and reached the company's directory service, which works like a master key to every system in the building. 

The company came through in relatively good shape because it moved fast. Threat detection alerts fired early on the Sunday morning. To protect internal and external data, Axis made the decision to completely disconnect all internet-facing services worldwide, cutting the attackers off in the setup phase before ransomware or exfiltration could complete. Forensic analysis later confirmed that remote-control and network-scanning software had been installed, and that employee names and phone numbers had been exposed, but found no evidence that customer, partner, supplier, product data or source code was affected[10]. 

Multi factor authentication is like a second lock on the door. But a convincing phone call or message can still talk an employee into opening that door anyway. Once the attackers had one administrator's login, they went straight for the directory service that controls every other door in the building. The lesson for IT admin teams is not just turn on MFA and stop there. Admin accounts need training built around the exact tricks attackers use to talk their way past the safeguards that are already in place. 

IT Helpdesk

IT Helpdesk: A Fake Police Call Drained Two Bank Accounts 

In 2024, an office clerk at a company in Latvia got a phone call. The caller claimed to be a police officer. He said someone was using her stolen identity to apply for loans in the company's name. He said a bank was already involved. He told her to act fast and tell no one. To make it convincing, he sent a photo of a fake police ID over WhatsApp. 

Then the story changed. This was now described as a secret operation to protect the company's money. She was told to install AnyDesk, a real and legitimate remote-access tool. This gave the scammers a live view of her computer screen. Over the course of the operation, they walked her through 42 separate payment approvals via Smart-ID, spread across two different banks. The company lost roughly 100,000 euros to more than a dozen personal accounts. The total would have reached close to 200,000 euros if one of the banks had not blocked the final batch of payments[11]. This was one instance of a broader pattern the Latvian State Police and CERT.lv were tracking through 2024, in which fake police officers, WhatsApp IDs and AnyDesk installations were used to drain company accounts across the country[12]. Losses from self-certified payments were running at roughly one to one-and-a-half million euros a month in Latvia over the same period[13]. 

This case did not target an IT helpdesk worker directly. But it plays out almost exactly like the attacks used against IT helpdesks everywhere. Pretend to be a trusted authority. Create urgency and secrecy so the target skips normal verification steps. Then talk the target into resetting a password or installing remote access software. This is exactly why helpdesk specific training matters. The people who have the power to reset access or start a remote session are the people attackers most want to trick into doing it for them. 

DevOps

DevOps: One Broken Door Into the Research Vault 

In December 2021, a major Swedish car maker confirmed that an unauthorised third party had accessed one of its file repositories and stolen a limited amount of research and development property[14]. The Snatch extortion group claimed responsibility and posted a 35.9 MB sample as proof[15]. The company's public disclosure did not describe how attackers first got in, and independent coverage noted that the mechanism was never confirmed[16]. 

Even a limited intrusion into a development environment matters, because that environment is rarely limited in what it touches. At many companies, a single developer login can reach the code library, the pipeline that builds and ships the product, the cloud accounts that host it, and sometimes the systems the finished product depends on. One reused credential, one leaked token, one poisoned dependency can open several doors in a row. That is why R&D and build systems are such attractive targets: they are often the shortest path from one compromised identity to a company's most valuable ideas. 

DevOps and engineering teams need training built around their actual risks. That means password and secret hygiene, and attacks that come in through outside code libraries and tools. It does not mean a generic phishing course that has nothing to do with the tools they use every day. 

Executives

Executives: A Deepfake Video Call Almost Approved a Transfer 

On 21 January 2025, managers at the Singapore and London offices of the largest bank in the Nordic region got WhatsApp messages that looked like they came from the bank's CFO and CEO. They were invited to a Teams meeting about a "new and exciting product." Two days later, on 23 January, that meeting took place. The person appearing as the CFO joined late, spoke to the group with the CFO's recognisable English accent, and asked the Singapore office to transfer several million Singapore dollars to complete a "unique investment opportunity"[4]. The total transfer requested was close to 24 million Norwegian kroner[17]. 

Neither executive was actually in that meeting. Both video images and voices were fake, built from real footage of the two leaders taken from publicly available interviews and clips and looped in real time. The Singapore office had already reported the first WhatsApp message to the bank's security department. The bank chose to let the Teams meeting continue for a short while to study how the attackers worked, then cut contact the moment on-screen payment instructions appeared. No money left the bank[19]. 

Everything the attackers needed was already public. Years of clean audio and video from talks, interviews, and the bank's own marketing videos gave them plenty to work with. Add a messaging app that sits outside monitored email systems, plus a video call tool that lets outsiders join a meeting, and you get a stage where a fake executive can appear right next to real employees. The old assumption was simple. If I can see and hear my boss, it really is my boss. That assumption no longer holds. Executive teams need training that treats this as the real risk it has become. 

The Same Lesson, Six Times Over 

Six roles. Six completely different kinds of access. A finance leader can approve payments. An HR team controls payroll data. An admin holds privileged system access. A helpdesk worker can reset credentials. A developer can touch the code that ships a product. An executive is publicly visible to the whole world. Training every one of these roles with the same generic phishing course leaves most of this risk unaddressed, because the real attacks were never generic in the first place. 

This is the whole idea behind role based security training. Instead of sending every employee the same course, training gets matched to the real attacks most often aimed at each specific role. A finance employee, a developer, and a CEO do not just have different jobs. They face different threats, and they deserve training built around that difference. 

Sources

[1]Supreme Court of Norway, HR-2024-990-A (English translation), paragraph on 13 payments from 24 September to 8 October 2019, https://www.domstol.no/globalassets/upload/hret/translated-rulings/2024/hr-2024-990-a.pdf

[2]Kystens Næringsliv, "Etter å ha svindlet selskapet for drøyt 120 millioner…" — six-year sentences for a 30-year-old Israeli/Italian citizen and a 29-year-old Italian citizen, both extradited from Israel, https://www.kystens.no/nyheter/etter-a-ha-svindlet-selskapet-for-droyt-120-millioner-ville-mennene-slippe-erstatning-fordi-de-mente-selskapet-hadde-darlige-rutiner/2-1-1430026

[3]Norwegian Supreme Court decision page, HR-2024-990-A — Danske Bank acquitted (31 May 2024), https://www.domstol.no/no/hoyesterett/avgjorelser/avgjorelser-2024/hoyesterett---sivil/HR-2024-990-A/

[4]Rett24, "Full seier i Høyesterett for Danske Bank" — Supreme Court on Edison Norge being exempted from Danske Bank's fraud engine from November 2015 onwards, https://rett24.no/articles/full-seier-i-hoyesterett-for-danske-bank--tilkjennes-18-millioner-i-sakskostnader

[5]Schjødt, "The Supreme Court of Norway decides on several interesting matters" — English-language summary of HR-2024-990-A, https://schjodt.com/news/the-supreme-court-of-norway-decides-on-several-interesting-matters

[6]EnergyWatch, "Edison left with bill after Danske Bank acquitted in scammer case" (4 June 2024), https://energywatch.com/EnergyNews/Oil___Gas/article17162473.ece

[7]Telenor, "The booming cybercrime business" — describes a LinkedIn job-update paycheck-redirect attempt against Telenor in spring 2024, caught by HR verification routines, https://www.telenor.com/who-we-are/our-companies/nordics/digitalsecurity/2024/the-booming-cybercrime-business/

[8]Telenor Norge, "Sanntidssvindel" (Norwegian-language version) — confirms the "våren 2024" LinkedIn-triggered payroll fraud attempt and HR's dual-verification catch, https://www.telenor.no/bedrift/blogg/sikkerhet/sanntidssvindel/

[9]KnowBe4 (Stu Sjouwerman) quoting Axis, "Social Engineering a Major Factor in Cyberattack on Camera Maker Axis Communications" — Axis: "Using several combinations of social engineering, attackers were able to sign in as a user despite protective mechanisms such as multifactor authentication" and later "elevate their access and eventually gain access to directory services," https://blog.knowbe4.com/social-engineering-a-major-factor-in-cyberattack-on-camera-maker-axis-communications

[10]Axis Communications, "Response to cyberattack February 2022" — official incident timeline: attack on the night of 19–20 February 2022, all internet-facing services disconnected by Sunday 20 February, remote-control and network-scanning software installed, names and phone numbers exposed, https://www.axis.com/response-to-cyberattack-february-2022

[11]LSM.lv, "Grāmatveži telefonkrāpnieku tēmēklī – kā no uzņēmumiem izzog milzīgas naudas summas" (12 September 2024) — documents the AnyDesk + fake-police pattern, 42 Smart-ID confirmations across two Latvian banks, near-€200,000 loss avoided in part when one bank blocked the last payments, https://www.lsm.lv/raksts/zinas/latvija/12.09.2024-gramatvezi-telefonkrapnieku-temekli-ka-no-uznemumiem-izzog-milzigas-naudas-summas.a568346/

[12]Latvian State Police, "No kurzemnieces izkrāpti 160 tūkstoši eiro…" (22 February 2024) — parallel case: WhatsApp fake police ID, AnyDesk installed, ~€150,000 transferred from employer accounts, cash placed in a parcel locker, https://www.vp.gov.lv/lv/jaunums/no-kurzemnieces-izkrapti-160-tukstosi-eiro-valsts-policija-bridina-par-krapnieku-aktivitati

[13]CERT.lv Q4 2024 Activity Report — Latvian citizens are defrauded of roughly EUR 1–1.5 million every month through self-certified payments, with AnyDesk-assisted scams a recurring vector, https://cert.lv/uploads/eng/CERT_Report_2024_Q4_ENG.pdf

[14]Volvo Cars, official notice via Nasdaq news service, "Volvo Cars investigates unauthorised access to one of its file repositories" (10 December 2021) — confirms that a third party accessed one file repository and that a limited amount of R&D property was stolen, https://view.news.eu.nasdaq.com/view?id=bfcfcefef308c37da76d12fed87d0e351&lang=en

[15]BleepingComputer, "Volvo Cars discloses security breach leading to R&D data theft" — reports that the Snatch extortion group claimed responsibility and leaked a 35.9 MB sample as proof, https://www.bleepingcomputer.com/news/security/volvo-cars-discloses-security-breach-leading-to-randd-data-theft/

[16]SecurityWeek, "Hackers steal research data from Sweden's Volvo Cars" — additional coverage of the December 2021 disclosure, https://www.securityweek.com/hackers-steal-research-data-swedens-volvo-cars/

[17]BankShift, "DNB utsatt for sofistikert deepfake-angrep" (3 February 2025) — full account of the 21 January WhatsApp lure to Singapore and London offices, the 23 January Teams meeting, CEO Kjerstin Braathen and CFO Ida Lerner deepfaked, several million Singapore dollars requested, contact cut when payment instructions appeared on screen, https://www.bankshift.no/nyheter/dnb-utsatt-for-sofistikert-deepfake-angrep/375139

[18]Finansavisen, "Direktørsvindel har fått nye våpen med kunstig intelligens…" (25 March 2025) — reports the DNB attempt at close to 24 million NOK and describes similar Teams-based deepfake attacks on other companies, https://www.finansavisen.no/teknologi/2025/03/25/8250514/direktorsvindel-har-fatt-nye-vapen-med-kunstig-intelligens-og-fyller-skjermen-med-deepfakes

[19]AI Incident Database entry 1246 — curated summary of the DNB deepfake Teams incident, 21–23 January 2025, https://incidentdatabase.ai/cite/1246/ 

 

Author

Nimblr Security Awareness

Nimblr Security Awareness

The Nimblr team is made up of people who are passionate about cyber security, developing training for real people, and tracking behavioral change.