What happened
In May 2017 an attacker took over a Save the Children employee's email account and created fraudulent invoices and payment documents for solar panels supposedly destined for health centers in Pakistan. Nearly $1 million was wired to an entity in Japan instead. Insurance covered most of the loss, leaving roughly $112,000 unrecovered. The incident became public in December 2018 when a journalist found the diversion disclosed in the charity's IRS filing.
How the deception worked
The attacker first phished credentials and gained control of a legitimate internal mailbox, which removed the usual lookalike-domain tell from the fraud. Operating from inside the organization's own email, they generated invoices and supporting documentation for a plausible program expense, solar equipment for Pakistani health facilities, that matched the charity's real field activities. Approvals then flowed through normal internal channels because every message came from a trusted colleague's real address. Payment was directed to a bank account in Japan, a jurisdiction inconsistent with the stated project, and the funds were gone before the discrepancy was noticed during later reconciliation.
AI involvement · No AI reported
No AI or synthetic media reported.
The control that would have caught it· our reading, not a claim from the sources
Account takeover defeats sender-based trust, so payment approvals for program expenses need out-of-band confirmation plus a geography sanity check between the vendor, the project and the receiving bank.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.