{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-leoni-ag-romanian-subsidiary-wires-40-million-to-fraudsters"},"incident":{"title":"Leoni AG Romanian subsidiary wires €40 million to fraudsters","date":"2016-08","date_precision":"month","victim_org":"Leoni AG (Bistrița, Romania subsidiary)","sector":"Manufacturing","country":"Romania","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":44000000,"loss_note":"About €40 million (roughly $44 million) transferred to an account in the Czech Republic. Recovery not confirmed.","records_affected":null,"threat_actor":null,"summary":"German wiring-systems maker Leoni AG announced in August 2016 that its subsidiary in Bistrița, Romania had been defrauded of about €40 million. Attackers cloned the email identities of Leoni executives in Germany and sent transfer instructions to the subsidiary's financial director, who processed them believing they were legitimate. The money was sent to a bank account in the Czech Republic. Leoni said the fraud involved falsified documents and identities.","how_it_worked":"The attackers researched Leoni's internal payment culture before striking, and reporting indicated they knew that German group executives had previously requested transfers by email. They created lookalike sender identities for those executives and directed instructions to the Romanian subsidiary's finance director, who was accustomed to acting on such requests. The messages mimicked the format, tone and approval language of genuine intra-group transfers and were supported by falsified documents. Because the request pattern matched prior legitimate behavior, the finance director executed the wire to a Czech account without a callback to Germany, and the funds were dispersed before the group detected the loss.","lessons":"Intra-group cash movements need a codified verification protocol, ideally a signed treasury workflow rather than email, so that familiarity with past email requests cannot be weaponized.","confidence":"Confirmed","sources":[{"title":"Hackers steal EUR 40 mln from German group Leoni's subsidiary in Romania","url":"https://www.romania-insider.com/hackers-steal-eur-40-mln-german-group-leoni-subsidiary-romania","publisher":"Romania Insider"},{"title":"German wire supplier Leoni loses EUR 40m in email impersonation scam","url":"https://www.bitdefender.com/en-us/blog/businessinsights/leoni-fraud-email-impersonation-scam","publisher":"Bitdefender Business Insights"}],"entry_type":"incident","slug":"2016-leoni-ag-romanian-subsidiary-wires-40-million-to-fraudsters","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-leoni-ag-romanian-subsidiary-wires-40-million-to-fraudsters"}}