Fraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake US bank account under a bogus tax-refund pretext; Rs 22.31 crore was never recovered, and a second, separate business-email-compromise hit Alkem's Enzene Biosciences US subsidiary roughly 18 months later.
Reviewed by the Social Engineering Examples team.
Alkem Laboratories, a major Indian pharmaceutical multinational, suffered two distinct, disclosed business-email-compromise incidents roughly 18 months apart. In the first, occurring between 27 October and 17 November 2023, fraudsters impersonated named executives of Alkem's US subsidiary Ascend Laboratories LLC via spoofed/compromised email accounts, exploiting genuine knowledge of a real Rs 51.30 crore intercompany payment Ascend had just made to parent Alkem. Using a fabricated "excess tax liability, please refund to this new account" pretext, they convinced Alkem's Mumbai-based treasury manager, Manoj Mishra, to wire the full Rs 51.30 crore via SWIFT to a fraudulent US bank account. The scheme was discovered only when a follow-up email requested an implausibly large additional "refund" of Rs 90 crore, prompting Alkem to call the real Ascend executive directly and learn the earlier emails were fake. Alkem's board resolved on 12 January 2024 to disclose the incident to BSE/NSE, and its Q3FY24 press release (9 February 2024) confirmed the ~Rs 51.31 crore fraudulent transfer from compromised subsidiary business email IDs. US law enforcement subsequently seized and returned Rs 28.98 crore, leaving a reported net loss of Rs 22.31 crore (per Mumbai Police/media reporting; Alkem's own FY24 accounts book a closely comparable Rs 290.4 million recovered / Rs 222.7 million net exceptional loss). Separately, on 15 May 2025, Alkem disclosed that its subsidiary Enzene Biosciences Ltd's US subsidiary had suffered its own cybersecurity incident in which employees' business email accounts were compromised, again resulting in a fraudulent fund transfer; the financial quantum was described as still under investigation at the time of that filing.
Ascend Laboratories LLC (Alkem's New Jersey-based US subsidiary) made a legitimate Rs 51.30 crore payment to parent Alkem on 25 October 2023 for materials supplied between November 2022 and January 2023. Two days later, on 27 October 2023, Alkem's Mumbai-based manager of treasury operations, Manoj Mishra, received an email purporting to be from Amit Ghare, Ascend's head of international operations, claiming Ascend's bank had flagged that the payment would trigger exorbitant taxes and asking Alkem to "refund" the sum to a new account so it could be re-sent correctly. A follow-up email on 17 November 2023, purporting to be from an Ascend accounting manager named Mary Smith, supplied the fraudulent US bank account details. Believing the correspondence genuine, Mishra wired the full Rs 51.30 crore via SWIFT to the fraudulent account. The scheme was built on real, non-public knowledge of an actual intercompany payment and impersonated named, legitimate counterparties using compromised or subtly altered look-alike email addresses, not a generic cold lure.
The lure combined three elements: (1) precise, non-public knowledge of a real intercompany payment made just two days earlier, lending immediate plausibility; (2) impersonation of two specifically-named real counterparts, Ascend's "head of international operations" and an "accounting manager", via compromised or lookalike email addresses, rather than an anonymous sender; and (3) a bureaucratic, low-suspicion pretext (avoiding an "exorbitant tax" charge) that framed the fraudulent transfer as protecting the company's money, not risking it. The tell that finally broke the scheme was a follow-up request, apparently from the same "Ghare" account, asking for an additional Rs 90 crore, a jump in scale abnormal enough that Alkem staff called Ghare directly through an independent channel, and he denied ever sending it, exposing that the prior emails had come from spoofed/compromised addresses with subtly altered characters.
US law enforcement seized Rs 28.98 crore of the stolen funds before they could be fully laundered out, and this amount was refunded to Alkem; the company's reported net unrecovered loss was Rs 22.31 crore (Mumbai Police/media figures) or Rs 22.27 crore per Alkem's own FY2023-24 exceptional-item accounting. Mumbai's cyber police registered an FIR against unidentified persons under IPC sections 419 (cheating by personation), 420 (cheating), 465/467/468/471 (forgery-related) and 34 (common intention), plus relevant IT Act provisions; no arrests were reported as of the sources reviewed. Alkem stated the incident did not involve any fraudulent act by its own promoters, directors, KMPs, or senior management, engaged independent external agencies to investigate, and disclosed the matter to BSE/NSE per SEBI materiality/governance norms even though it said the amount did not cross formal materiality thresholds. Separately, on 15 May 2025 Alkem disclosed that Enzene Biosciences Ltd's US subsidiary had suffered a distinct incident in which employee business email accounts were compromised, resulting in a fraudulent fund transfer whose amount was still under investigation at disclosure time.
This case is a well-documented, dual illustration of business email compromise risk in cross-border intercompany treasury operations at a large, publicly-listed multinational: attackers weaponized real, non-public transaction context (an actual recent invoice payment) combined with impersonation of named real executives to make a fraudulent refund request highly credible, defeating a trained treasury professional. It also shows that a single company can suffer materially significant, near-identical BEC-style incidents at different subsidiaries within about 18 months despite remediation efforts (Alkem's post-2024 partnership with Check Point Software), because the newly-compromised foreign subsidiary was reportedly still outside the upgraded security perimeter. The case additionally illustrates that cross-border law-enforcement cooperation can claw back a meaningful share (roughly 56%) of stolen funds if reported and acted on quickly, and it is a clean example of India's SEBI-driven listed-company cyber-incident disclosure regime in action via BSE/NSE filings.
Recommended controls highlighted by this case: independently-sourced callback verification (phone, not numbers/addresses from the suspect email) before honoring ANY change-of-bank-account or refund request; heightened scrutiny of urgent requests to redirect funds tied to a real, recently-completed invoice/payment; automated detection of lookalike/spoofed vendor and executive domains; dual-approval/maker-checker sign-off for cross-border SWIFT transfers above a threshold; extending email/endpoint security tooling uniformly across ALL subsidiaries (Alkem's own post-incident statement noted the affected foreign subsidiary was "operating independently outside the corporate systems" and not yet covered by the company's Check Point deployment); rapid law-enforcement and correspondent-bank engagement to freeze funds in the destination country before they are laundered out (this is what enabled partial recovery here).
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread, spoofed the vendor to…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…