{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ryanair-loses-nearly-5-million-from-fuel-account-via-fraudulent-transfer"},"incident":{"title":"Ryanair loses nearly $5 million from fuel account via fraudulent transfer","date":"2015-04","date_precision":"month","victim_org":"Ryanair Holdings plc","sector":"Transportation & Logistics","country":"Ireland","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":5000000,"loss_note":"About €4.6 million (just under $5 million) transferred out of an aircraft fuel account via a Chinese bank; Ryanair said the funds were frozen and it expected repayment.","records_affected":null,"threat_actor":null,"summary":"In April 2015 Ryanair disclosed that roughly €4.6 million had been removed from a bank account used to purchase aircraft fuel, via an electronic transfer routed through a Chinese bank. The airline said the funds had been frozen and that it expected them to be repaid. Ireland's Criminal Assets Bureau worked with Asia-Pacific counterparts on recovery. Ryanair did not publicly detail the intrusion method, and contemporaneous reporting speculated about both fraudulent transfer instructions and banking malware.","how_it_worked":"The fraud targeted a single-purpose corporate account used for high-value, recurring commodity purchases, where large outbound payments are normal and unlikely to stand out. An unauthorized electronic transfer instruction moved nearly €4.6 million out of the fuel account and into the banking system via a Chinese institution, a common laundering corridor for payment-diversion fraud in that period. Ryanair identified the loss quickly enough for Irish authorities and their Asian counterparts to reach the receiving bank and freeze the balance. The airline declined to describe the precise attack vector, citing legal proceedings, and said corrective measures had been put in place.","lessons":"High-value commodity payment accounts need transaction-level anomaly alerting and a dedicated approval path, so that a single unexpected instruction cannot drain them before anyone reviews it.","confidence":"Reported","sources":[{"title":"Ryanair Loses $5m in Bank Hack","url":"https://www.infosecurity-magazine.com/news/ryanair-loses-5-million-in-bank/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","slug":"2015-ryanair-loses-nearly-5-million-from-fuel-account-via-fraudulent-transfer","year":2015,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ryanair-loses-nearly-5-million-from-fuel-account-via-fraudulent-transfer"}}