What happened
Belgian bank Crelan disclosed in January 2016 that an internal audit had uncovered a fraud costing approximately €70 million. Attackers either compromised or convincingly imitated a senior executive's email account and sent payment orders to the bank's finance department. Crelan notified Belgian authorities and its risk and audit committees, and said the loss was covered by reserves without impact on customers or partners.
How the deception worked
The scheme attacked a bank's own treasury payment process rather than customer accounts. Fraudsters used a compromised or spoofed executive mailbox to issue payment instructions to finance staff, relying on the authority of the sender and on urgency and confidentiality to suppress questions. Because the orders came through the expected internal channel and carried apparently legitimate executive approval, they were processed without out-of-band confirmation. The diversion went undetected until routine internal audit work flagged irregularities, at which point the funds had already left the institution. Crelan reported the matter to prosecutors and reviewed its internal control framework.
AI involvement · No AI reported
No AI or synthetic media reported.
The control that would have caught it· our reading, not a claim from the sources
Internal payment instructions deserve the same scrutiny as external ones: even executive-originated transfers should require verification through a separate channel and a segregation-of-duties check before release.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.