{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam"},"incident":{"title":"Dublin Zoo defrauded of about €500,000 in invoice redirection scam","date":"2017","date_precision":"year","victim_org":"Dublin Zoo","sector":"Other","country":"Ireland","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Approximately €500,000 was diverted; Gardaí recovered most of the funds, with reporting indicating roughly €130,000 outstanding. No official USD figure was published.","records_affected":null,"threat_actor":null,"summary":"Dublin Zoo was the victim of an invoice redirection fraud in 2017 in which criminals intercepted genuine supplier invoices and had payments totaling roughly €500,000 sent to accounts they controlled. The zoo reported the matter to Gardaí at Cabra Garda Station, which referred it to the Garda National Economic Crime Bureau, and most of the money was recovered with the assistance of financial institutions. The zoo said no customer data was compromised.","how_it_worked":"The scheme substituted the destination account on invoices the zoo already expected to pay, so nothing about the amount, the supplier name or the timing looked unusual. Criminals obtained or replicated genuine invoices and presented altered bank details as a routine change of the supplier's account, communicated by email or phone. Finance staff updated the payment details and released the payments in the ordinary run. Gardaí publicly warned after the case that no business should change a supplier's bank account number on the basis of a call or email without verifying the change with a known contact at the supplier, which is precisely the control gap the fraud exploited.","lessons":"Treat supplier bank-detail changes as a security event requiring verification with a known contact using previously held numbers, and reconcile with suppliers promptly so a diversion is caught while funds are still recoverable.","confidence":"Reported","sources":[{"title":"Dublin Zoo lost €500k after falling victim to cyber scam","url":"https://www.irishexaminer.com/ireland/dublin-zoo-lost-500k-after-falling-victim-to-cyber-scam-464818.html","publisher":"Irish Examiner"}],"entry_type":"incident","slug":"2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam","year":2017,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2017-dublin-zoo-defrauded-of-about-500-000-in-invoice-redirection-scam"}}