Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 23 of 47 entries · page 2 of 2
December 2018·Professional Services

Tecnimont India loses $18.6 million to fake CEO conference calls

Tecnimont SpA (Indian subsidiary, Maire Tecnimont group) · India

The Indian arm of Italian engineering group Tecnimont SpA transferred approximately $18.6 million in three installments to Hong Kong bank accounts in late 2018 after a fraud ring impersonated the group's chief executive. The attackers emailed from a lookalike address and staged conference calls in which people posed as the CEO, other senior executives and a Swiss lawyer, discussing a confidential acquisition in China. The company launched a forensic investigation and dismissed its India head and finance chief.

Business Email Compromise
$18.6M funds lostReported2 sources
November 2018·Government

Cabarrus County, NC diverts $2.5 million school payment to BEC actors

Cabarrus County, North Carolina · United States

Cabarrus County, North Carolina paid $2,504,601 to accounts controlled by criminals who impersonated Branch and Associates, Inc., the general contractor building West Cabarrus High School. The scammers emailed a request to update the contractor's banking information, supplying supporting documentation and signed approvals. The county discovered the fraud in January 2019. It recovered $776,518.40; roughly $1.7 million was never recovered.

Vendor / Supply Chain Impersonation
$2.5M funds lostConfirmed1 source
July 2018·Government

City of Ottawa treasurer wires about US$98,000 to fake city manager

City of Ottawa · Canada

In July 2018 Ottawa city treasurer Marian Simulik wired about US$98,000 after receiving emails purporting to come from city manager Steve Kanellakos requesting funds to complete an acquisition. Five days later a second email requested US$150,000; Simulik happened to be sitting beside Kanellakos at a council meeting, asked him directly, and learned the request was fraudulent. The auditor general found no wrongdoing by city staff, and U.S. authorities arrested an individual linked to the receiving account.

Business Email Compromise
$98K funds lostConfirmed1 source
April 2018·Manufacturing

Obinwanne Okeke sentenced to 10 years over $11 million Unatrac BEC fraud

Unatrac Holding Limited (Caterpillar export sales affiliate) · United Kingdom

Obinwanne Okeke, a Nigerian businessman known as Invictus Obi, was arrested at Dulles Airport in August 2019, pleaded guilty in June 2020 and was sentenced on February 16, 2021 to 10 years in federal prison. Between 2015 and 2019 he ran computer-enabled fraud including a April 2018 attack on Unatrac Holding Limited, the UK export sales office for Caterpillar equipment, where a phished CFO mailbox was used to send about $11 million in fraudulent wire instructions.

Business Email Compromise
$11.0M funds lostConfirmed1 source
March 2018·Media & Entertainment

Pathé Dutch branch wires €19 million in fake CEO acquisition scam

Pathé (Netherlands branch) · Netherlands

In March 2018 fraudsters impersonating the chief executive of French film company Pathé's parent persuaded the Dutch branch's leadership to make a series of payments totaling more than €19 million for a purported acquisition of a Dubai-based company. Branch director Dertje Meijer and CFO Edwin Slutter were both dismissed after the loss surfaced. An external investigation cleared them of involvement, and Slutter later won partial relief in a wrongful-termination suit.

Business Email Compromise
$21.5M funds lostConfirmed1 source
March 2018·Media & Entertainment

Cinema group Pathe loses EUR 19.2 million to CEO fraud; Dutch executives dismissed

Pathe (Pathe Nederland) · Netherlands

Between March and May 2018 the Dutch arm of the French cinema chain Pathe transferred about EUR 19.2 million in a series of payments to accounts in Dubai, acting on emails purporting to come from Pathe's French head office. The company dismissed the managing director and financial director of Pathe Nederland; a Dutch court ruling later published details of the case and upheld the dismissals.

Business Email Compromise
$21.5M funds lostConfirmed2 sources
March 2018·Healthcare

UnityPoint Health phishing of executive-spoofed emails exposes 1.4 million patients

UnityPoint Health · United States

UnityPoint Health, an Iowa-based health system, disclosed in July 2018 that a phishing campaign had compromised multiple employee email accounts between 14 March and 3 April 2018, exposing data on approximately 1.4 million patients. It was the largest US health data breach reported that year. Investigators concluded the attackers were most likely trying to divert vendor or payroll payments rather than steal medical records.

Business Email Compromise
$2.8M business impact1.4M affectedConfirmed2 sources
May 2017·Nonprofit

Save the Children Federation loses nearly $1 million in charity BEC fraud

Save the Children Federation, Inc. · United States

In May 2017 an attacker took over a Save the Children employee's email account and created fraudulent invoices and payment documents for solar panels supposedly destined for health centers in Pakistan. Nearly $1 million was wired to an entity in Japan instead. Insurance covered most of the loss, leaving roughly $112,000 unrecovered. The incident became public in December 2018 when a journalist found the diversion disclosed in the charity's IRS filing.

Business Email Compromise
$1.0M funds lostConfirmed1 source
February 2, 2017·EducationCampaign

IRS warns of W-2 phishing epidemic spreading to school districts and nonprofits

US school districts, tribal organizations, nonprofits and employers (multi-victim campaign) · United States

In news release IR-2017-20, issued 2 February 2017, the IRS warned that the W-2 spear phishing scam had spread well beyond corporations to school districts, tribal organizations and casinos, nonprofits, chain restaurants, temporary staffing agencies, healthcare providers and shipping and freight companies. The agency also flagged an evolved variant that follows the W-2 theft with a fraudulent wire transfer request.

Business Email Compromise
Confirmed1 source
2017·Other

Dublin Zoo defrauded of about €500,000 in invoice redirection scam

Dublin Zoo · Ireland

Dublin Zoo was the victim of an invoice redirection fraud in 2017 in which criminals intercepted genuine supplier invoices and had payments totaling roughly €500,000 sent to accounts they controlled. The zoo reported the matter to Gardaí at Cabra Garda Station, which referred it to the Garda National Economic Crime Bureau, and most of the money was recovered with the assistance of financial institutions. The zoo said no customer data was compromised.

Vendor / Supply Chain Impersonation
Reported1 source
August 2016·Manufacturing

Leoni AG Romanian subsidiary wires €40 million to fraudsters

Leoni AG (Bistrița, Romania subsidiary) · Romania

German wiring-systems maker Leoni AG announced in August 2016 that its subsidiary in Bistrița, Romania had been defrauded of about €40 million. Attackers cloned the email identities of Leoni executives in Germany and sent transfer instructions to the subsidiary's financial director, who processed them believing they were legitimate. The money was sent to a bank account in the Czech Republic. Leoni said the fraud involved falsified documents and identities.

Business Email Compromise
$44.0M funds lostConfirmed2 sources
April 26, 2016·Media & Entertainment

Milwaukee Bucks employee sends players' and staff W-2s to an impersonator

Milwaukee Bucks (NBA) · United States

The NBA's Milwaukee Bucks disclosed in May 2016 that an employee had emailed 2015 W-2 tax documents for players and staff to an unknown party in response to a message impersonating the team's president. The documents included names, addresses, Social Security numbers and compensation figures. The team offered three years of credit monitoring to those affected.

Business Email Compromise
Confirmed2 sources
March 1, 2016·Technology

Seagate CEO-impersonation phish exposes every US employee's W-2

Seagate Technology · United States

On 1 March 2016 a Seagate employee responded to a phishing email spoofing a request from the CEO and sent the 2015 W-2 tax forms for all current and former US-based employees to an unauthorized recipient. Seagate described the number affected as several thousand but well under 10,000, and offered two years of credit monitoring. Seagate's CFO called the incident a result of human error and a lack of vigilance.

Business Email Compromise
Confirmed2 sources
March 2016·Retail

Sprouts Farmers Market payroll employee emails 21,000 staff W-2s to a scammer

Sprouts Farmers Market · United States

In late March 2016 an employee in the payroll department of the US grocery chain Sprouts Farmers Market responded to an email that appeared to come from a company executive and attached the W-2 tax forms of approximately 21,000 employees. The forms contained names, addresses, Social Security numbers and wage data. Class-action litigation followed within weeks.

Business Email Compromise
21K affectedConfirmed2 sources
February 28, 2016·Technology

Snapchat payroll staff phished by fake CEO request for employee W-2s

Snapchat, Inc. · United States

On 28 February 2016 Snapchat's payroll department received an email impersonating chief executive Evan Spiegel and requesting employee W-2 forms, and complied. Snapchat publicly acknowledged the error, said it would take care of those affected, and offered two years of free credit monitoring. It did not disclose the number of employees whose data was disclosed.

Business Email Compromise
Confirmed1 source
January 2016·Manufacturing

Austrian aerospace supplier FACC loses about €50 million to CEO fraud

FACC AG · Austria

FACC AG, an Austrian manufacturer of aircraft components for Airbus and Boeing, disclosed in January 2016 that it had lost about €50 million after criminals impersonating company leadership instructed staff to transfer funds for a purported acquisition project. The supervisory board subsequently dismissed the chief financial officer and, in May 2016, the chief executive officer over the incident.

Business Email Compromise
$54.0M funds lostConfirmed3 sources
January 2016·Financial Services

Belgian bank Crelan loses €70 million to CEO-fraud payment orders

Crelan NV/SA · Belgium

Belgian bank Crelan disclosed in January 2016 that an internal audit had uncovered a fraud costing approximately €70 million. Attackers either compromised or convincingly imitated a senior executive's email account and sent payment orders to the bank's finance department. Crelan notified Belgian authorities and its risk and audit committees, and said the loss was covered by reserves without impact on customers or partners.

Business Email Compromise
$75.8M funds lostConfirmed1 source
June 5, 2015·Technology

Ubiquiti Networks loses $46.7M to executive-impersonation business email compromise

Ubiquiti Networks · United States

In its quarterly SEC filing in August 2015, Ubiquiti Networks disclosed that criminals had induced its Hong Kong subsidiary's finance staff to wire $46.7 million to attacker-controlled overseas accounts. The company said the fraud involved employee impersonation and fraudulent requests from an outside entity, with no intrusion into Ubiquiti's systems or loss of customer data.

Business Email Compromise
$46.7M funds lostConfirmed4 sources
April 30, 2015·Consumer

Mattel wires $3 million to Chinese account in CEO impersonation scam, recovers it

Mattel, Inc. · United States

On April 30, 2015 a Mattel finance executive wired $3 million to a bank in Wenzhou, China after receiving an email purporting to come from newly appointed chief executive Christopher Sinclair. The fraud was recognized the same day. Because May 1 was a banking holiday in China, Mattel was able to work with U.S. and Chinese law enforcement and the receiving bank to freeze the account, and the funds were returned within days.

Business Email Compromise
$3.0M funds lostConfirmed1 source
April 2015·Transportation & Logistics

Ryanair loses nearly $5 million from fuel account via fraudulent transfer

Ryanair Holdings plc · Ireland

In April 2015 Ryanair disclosed that roughly €4.6 million had been removed from a bank account used to purchase aircraft fuel, via an electronic transfer routed through a Chinese bank. The airline said the funds had been frozen and that it expected them to be repaid. Ireland's Criminal Assets Bureau worked with Asia-Pacific counterparts on recovery. Ryanair did not publicly detail the intrusion method, and contemporaneous reporting speculated about both fraudulent transfer instructions and banking malware.

Business Email Compromise
$5.0M funds lostReported1 source
December 30, 2014·Financial Services

Xoom Corporation loses $30.8 million to employee impersonation fraud

Xoom Corporation · United States

Online money-transfer provider Xoom Corporation disclosed in a Form 8-K on January 5, 2015 that on December 30, 2014 it had determined it was the victim of a criminal fraud involving employee impersonation and fraudulent requests targeting its finance department, resulting in $30.8 million of corporate cash being transferred to overseas accounts. Chief Financial Officer Matt Hibbard resigned effective immediately the same day. Federal law enforcement opened a multi-agency investigation and the audit committee commissioned an independent review.

Business Email Compromise
$30.8M funds lostConfirmed1 source
June 2014·Other

Scoular Company wires $17.2 million after fake CEO and auditor emails

The Scoular Company · United States

In June 2014 the corporate controller of Omaha-based commodities trading firm The Scoular Company wired $17.2 million to a Chinese bank in three installments after receiving emails impersonating chief executive Chuck Elsea and the company's outside auditor at KPMG. The messages described a confidential international acquisition and demanded secrecy. The emails were sent from accounts associated with Germany, France and Israel using servers in Moscow.

Business Email Compromise
$17.2M funds lostConfirmed1 source
2013·Technology

Rimasauskas BEC scheme defrauds Google and Facebook of over $120 million

Google LLC and Facebook, Inc. · United States

From roughly 2013 to 2015 Evaldas Rimasauskas registered a Latvian company using the same name as Quanta Computer, a genuine Asian hardware supplier to two large U.S. internet companies, and invoiced them for goods and services the real supplier had delivered. Payments totaling more than $120 million were wired to accounts he controlled in Latvia and Cyprus and then laundered through several countries. He was arrested in Lithuania in March 2017, extradited in August 2017, pleaded guilty in March 2019, and was sentenced on December 19, 2019 to five years in prison.

Vendor / Supply Chain Impersonation
$120.0M funds lostConfirmed6 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?vector=Business+Email+Compromise.