What happened
In April 2015 Ryanair disclosed that roughly €4.6 million had been removed from a bank account used to purchase aircraft fuel, via an electronic transfer routed through a Chinese bank. The airline said the funds had been frozen and that it expected them to be repaid. Ireland's Criminal Assets Bureau worked with Asia-Pacific counterparts on recovery. Ryanair did not publicly detail the intrusion method, and contemporaneous reporting speculated about both fraudulent transfer instructions and banking malware.
How the deception worked
The fraud targeted a single-purpose corporate account used for high-value, recurring commodity purchases, where large outbound payments are normal and unlikely to stand out. An unauthorized electronic transfer instruction moved nearly €4.6 million out of the fuel account and into the banking system via a Chinese institution, a common laundering corridor for payment-diversion fraud in that period. Ryanair identified the loss quickly enough for Irish authorities and their Asian counterparts to reach the receiving bank and freeze the balance. The airline declined to describe the precise attack vector, citing legal proceedings, and said corrective measures had been put in place.
AI involvement · No AI reported
No AI or synthetic media reported.
The control that would have caught it· our reading, not a claim from the sources
High-value commodity payment accounts need transaction-level anomaly alerting and a dedicated approval path, so that a single unexpected instruction cannot drain them before anyone reviews it.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.