This section captures critical information about the targeted executive and the employee reporting this incident. Accurate details are essential for forensic analysis and organizational response. All fields marked mandatory must be completed to ensure proper case documentation.
Targeted Executive's Full Name
Targeted Executive's Official Title/Role
Targeted Executive's Department/Division
Targeted Executive's Primary Office Location
Targeted Executive's Corporate Email Address
Targeted Executive's Official Corporate Phone Number
How many years has the targeted executive been with the organization?
What is the level of the targeted executive's public digital presence? (Select all that apply)
Active on professional social media (LinkedIn)
Regular conference speaker
Participates in media interviews
Company website biography with photo
Voice recordings publicly available (podcasts, webinars)
Minimal public presence
Other public presence
Is the executive's authentic voice publicly available through official channels (e.g., earnings calls, recorded presentations, podcasts)?
Specify where the authentic voice can be found (provide URLs or descriptions):
Does the executive regularly use voice or video calls for business communications?
Which platforms are routinely used? (Select all that apply)
Corporate VoIP phone system
Microsoft Teams
Zoom
WebEx
Google Meet
WhatsApp Business
WeChat Work
Other platform
Describe the executive's typical communication style or known phrases that colleagues would recognize:
Now please provide your details as the reporting employee:
Reporting Employee's Full Name
Reporting Employee's Official Title/Role
Reporting Employee's Department/Division
What is your professional relationship to the targeted executive?
Direct report
Indirect report (skip-level)
Cross-functional peer
Subordinate in different department
Executive assistant
Communications partner
Finance business partner
Other relationship
Reporting Employee's Corporate Email Address
Reporting Employee's Official Employee ID Number
How many years have you been with the organization?
Have you completed the organization's security awareness training within the last 12 months?
Date of most recent training completion:
Explain why training was not completed:
How familiar are you with the targeted executive's authentic voice and communication patterns?
Very familiar (daily interaction)
Moderately familiar (weekly interaction)
Somewhat familiar (monthly interaction)
Not familiar (rare or no direct interaction)
Only familiar through recordings
Your location (city/country) at the time of the incident:
Preserve all technical evidence before completing this section. Do not delete any recordings, emails, or logs. This information is crucial for digital forensics and potential law enforcement involvement.
Exact date and time when the incident communication began
Exact date and time when the incident communication ended (if applicable)
Your timezone at the time of incident
Was the impersonation communication delivered live in real-time or as a recorded message?
Live real-time communication
Recorded voicemail/message
Pre-recorded video
Live video call
Uncertain
What was the primary communication channel used for the attack?
Corporate telephone system (PSTN/VoIP)
Mobile phone call (SIM-based)
Voicemail system
Video conferencing platform
Instant messaging app (voice note)
Email with audio/video attachment
Social media platform
Other channel
What caller ID or phone number was displayed? (exactly as shown)
What mobile number was displayed? (exactly as shown)
Which video conferencing platform was used?
Which messaging app was used?
What was the sender's email address?
Did the displayed phone number, email address, or user ID appear to be the executive's authentic corporate contact information?
Explain why the spoofed credentials appeared authentic (e.g., matched internal directory, previous correspondence):
Describe the discrepancies you noticed (e.g., slight spelling difference, unknown number):
Do you suspect the communication was transmitted using caller ID spoofing, email spoofing, or similar identity falsification techniques?
Provide any technical identifiers available (IP addresses, email headers, message IDs, server logs, etc.):
Device used to receive the communication (your device)
Network environment when incident was received
Corporate office network
Corporate VPN
Home network (employee's)
Public Wi-Fi
Mobile carrier network
Other network
Was the communication recorded by you or your organization?
Upload the recorded file (audio, video, or voicemail file):
Upload screenshots of call logs, messaging interface, email headers, or any visual evidence:
Duration of the communication in minutes (if applicable):
Rate the overall audio quality of the impersonation (1 star = very poor quality, 5 stars = excellent quality, indistinguishable)
Rate the technical quality of specific characteristics of the impersonation:
Very Poor | Poor | Neutral | Good | Excellent | |
|---|---|---|---|---|---|
Voice tone and pitch accuracy | |||||
Speech pattern and cadence | |||||
Accent or dialect replication | |||||
Background noise authenticity | |||||
Audio clarity and lack of artifacts | |||||
Video lip-sync accuracy (if video) |
Did you notice any audio artifacts, robotic sounds, unnatural pauses, or other anomalies suggesting synthetic generation?
For video calls: Were there noticeable lip-sync issues, facial rendering anomalies, or unusual eye movements?
Did the attacker attempt to use screen sharing, file transfer, or other collaboration features?
Provide as much detail as possible about the conversation content, the attacker's requests, and any social engineering tactics employed. Your detailed recollection is vital for understanding the attack methodology.
Summarize the pretext or storyline the attacker used to justify the communication:
What specific fraudulent instruction(s) were you given? (Select all that apply)
Initiate an urgent wire transfer or payment
Share confidential financial data or reports
Provide system access credentials
Bypass normal approval procedures
Arrange an emergency meeting with external parties
Install software or applications
Share employee personal information
Authorize a transaction outside normal channels
Other fraudulent instruction
Provide details of each wire transfer or payment request:
Requested Amount | Currency | Destination Account/Beneficiary | Bank Name or Payment System | Purported Reason | Marked as Urgent? | ||
|---|---|---|---|---|---|---|---|
A | B | C | D | E | F | ||
1 | |||||||
2 | |||||||
3 | |||||||
4 | |||||||
5 | |||||||
6 | |||||||
7 | |||||||
8 | |||||||
9 | |||||||
10 |
What type of confidential data was requested? (Select all that apply)
Unreleased financial statements
M&A deal information
Customer lists
Employee salary data
Strategic plans
IT security architecture
Other sensitive data
Describe what credentials or access was requested:
Which approval procedures were you instructed to bypass and how?
Describe the emergency meeting arrangement request (who, when, why):
Total financial amount requested across all instructions:
What social engineering tactics were employed to create urgency or pressure? (Select all that apply)
Extreme time pressure ('within minutes')
Emphasized confidentiality ('do not tell anyone')
Crisis situation ('system failure', 'deal collapsing')
Authority pressure ('board demands this')
Isolation tactic ('only you can help')
Flattery or rapport building
Threat of negative consequences
Reference to personal knowledge
Other tactic
Did the attacker demonstrate specific knowledge of internal company processes, projects, or organizational structure?
Detail the specific insider knowledge revealed (e.g., names of real colleagues, current projects, internal systems):
Did the attacker reference specific names of real colleagues, assistants, or board members?
Was there any follow-up communication from the attacker after the initial contact?
Did the attacker explicitly instruct you to maintain secrecy or not verify the request through other channels?
What specific language was used to prevent verification?
List any suspicious phrases, unusual word choices, or language patterns that raised concerns:
Did the attacker claim the executive was in a situation where they were unavailable for normal verification (e.g., traveling, in secure meetings, device issues)?
Describe any background noises that seemed inconsistent with the claimed location (e.g., office sounds when claiming to be traveling):
What red flags or suspicious indicators did you notice during the interaction?
Detail all immediate actions taken from the moment of initial contact through to this report. Precise timeline information is critical for incident response and potential recovery efforts.
Were any financial transactions partially or fully executed before the impersonation was detected?
Provide transaction details:
Transaction Amount | Currency | Transaction Initiation Time | Transaction Status | Destination | Funds Recovered? | ||
|---|---|---|---|---|---|---|---|
A | B | C | D | E | F | ||
1 | |||||||
2 | |||||||
3 | |||||||
4 | |||||||
5 | |||||||
6 | |||||||
7 | |||||||
8 | |||||||
9 | |||||||
10 |
Was any sensitive corporate data or documents transmitted to the attacker?
Describe what data was shared and the potential sensitivity level:
Were any system credentials, or access tokens compromised or shared?
Specify what credentials were involved and immediate remediation taken:
What immediate IT security countermeasures were executed? (Select all that apply)
Blocked the attacker's contact number/email
Changed potentially compromised credentials
Forced sign-out of active sessions
Enabled additional MFA for affected accounts
Isolated or scanned affected systems
Preserved call logs and metadata
Escalated to Security Operations Center (SOC)
Engaged incident response team
Initiated forensic imaging
No immediate IT action taken
Other countermeasure
Which internal stakeholders were notified and when? (Select all that apply)
Chief Information Security Officer (CISO)
Chief Financial Officer (CFO)
Chief Executive Officer (CEO)
General Counsel/Legal Department
Corporate Communications/Public Relations
Human Resources
Board of Directors
Executive Assistant to targeted executive
Internal Audit
Risk Management
No internal notification yet
Other stakeholder
Which external parties were notified? (Select all that apply)
Law enforcement agency
Cyber insurance provider
External forensic investigation firm
Affected business partners
Banking/payment institutions
Regulatory authority
No external notification
Other external party
Has a formal incident response case number or ticket been created?
Provide the case number:
Timeline of key response actions (complete as precisely as possible):
Action Timestamp | Action Taken | Person/Team Responsible | Outcome/Status | ||
|---|---|---|---|---|---|
A | B | C | D | ||
1 | |||||
2 | |||||
3 | |||||
4 | |||||
5 | |||||
6 | |||||
7 | |||||
8 | |||||
9 | |||||
10 |
Did you terminate or disconnect the communication with the attacker?
How many minutes elapsed from start of communication to disconnection?
Describe any additional preventive controls or monitoring implemented after the incident was detected:
Estimated total time in minutes from initial incident contact to this formal report submission:
This final section assesses the broader enterprise risk implications and establishes proper authorization for investigative activities. Information provided here may be subject to legal privilege and should be completed in consultation with legal counsel where appropriate.
Estimated maximum potential financial loss exposure from this incident (if transaction had succeeded):
Rate the potential reputational risk to the organization if this incident became public (1 = minimal impact, 10 = catastrophic reputational damage)
Which regulatory frameworks or compliance regimes could be implicated by this incident? (Select all that apply)
Data protection/privacy regulation
Financial services regulation
Publicly traded company disclosure requirements
Critical infrastructure protection
Industry-specific compliance
No regulatory implications
Unknown at this time
Other regulatory framework
What is the highest data classification level of any information potentially compromised or requested?
Public information
Internal use only
Confidential (business sensitive)
Restricted (highly sensitive)
Secret (trade secrets)
Unknown
Does this incident appear to be part of a coordinated campaign targeting multiple executives or organizations?
Provide reasoning and any evidence of broader campaign indicators:
Has internal or external legal counsel been formally engaged regarding this incident?
Name of legal counsel or firm engaged:
Could this incident trigger coverage under a cyber insurance, crime insurance, or professional liability policy?
Specify policy types and notification status:
Is regulatory notification to authorities required or being considered?
Specify which authorities and timeline requirements:
What is the required confidentiality level for handling this incident?
Strictly confidential (attorney-client privilege)
Highly confidential (limited need-to-know)
Confidential (internal security team)
Internal use only
Public disclosure anticipated
I authorize the organization's Information Security and Incident Response teams to investigate this incident, including forensic analysis of all related systems and communications.
I authorize engagement with external forensic investigation firms if deemed necessary by security leadership.
I authorize notification and cooperation with law enforcement agencies if deemed appropriate by legal counsel.
Preferred method for receiving incident updates and follow-up actions:
Secure corporate email only
Phone call to mobile number
Encrypted messaging platform
In-person briefing
No updates required
Other method
Additional comments, observations, or recommendations for enterprise-wide prevention:
Upload any additional supporting documents, threat intelligence, or evidence files not previously attached:
To configure an element, select it on the form.