Fraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake US bank.
Social Engineering Examples·7 sources
Alkem Laboratories, a major Indian pharmaceutical multinational, suffered two distinct, disclosed business-email-compromise incidents roughly 18 months apart. In the first, occurring between 27 October and 17 November 2023, fraudsters impersonated named executives of Alkem's US subsidiary Ascend Laboratories LLC via spoofed/compromised email accounts, exploiting genuine knowledge of a real Rs 51.30 crore intercompany payment Ascend had just made to parent Alkem.
Using a fabricated "excess tax liability, please refund to this new account" pretext, they convinced Alkem's Mumbai-based treasury manager, Manoj Mishra, to wire the full Rs 51.30 crore via SWIFT to a fraudulent US bank account. The scheme was discovered only when a follow-up email requested an implausibly large additional "refund" of Rs 90 crore, prompting Alkem to call the real Ascend executive directly and learn the earlier emails were fake.
Alkem's board resolved on 12 January 2024 to disclose the incident to BSE/NSE, and its Q3FY24 press release (9 February 2024) confirmed the ~Rs 51.31 crore fraudulent transfer from compromised subsidiary business email IDs. US law enforcement subsequently seized and returned Rs 28.98 crore, leaving a reported net loss of Rs 22.31 crore (per Mumbai Police/media reporting; Alkem's own FY24 accounts book a closely comparable Rs 290.4 million recovered / Rs 222.7 million net exceptional loss).
Separately, on 15 May 2025, Alkem disclosed that its subsidiary Enzene Biosciences Ltd's US subsidiary had suffered its own cybersecurity incident in which employees' business email accounts were compromised, again resulting in a fraudulent fund transfer; the financial quantum was described as still under investigation at the time of that filing.
Ascend Laboratories LLC (Alkem's New Jersey-based US subsidiary) made a legitimate Rs 51.30 crore payment to parent Alkem on 25 October 2023 for materials supplied between November 2022 and January 2023. Two days later, on 27 October 2023, Alkem's Mumbai-based manager of treasury operations, Manoj Mishra, received an email purporting to be from Amit Ghare, Ascend's head of international operations, claiming Ascend's bank had flagged that the payment would trigger exorbitant taxes and asking Alkem to "refund" the sum to a new account so it could be re-sent correctly.
A follow-up email on 17 November 2023, purporting to be from an Ascend accounting manager named Mary Smith, supplied the fraudulent US bank account details. Believing the correspondence genuine, Mishra wired the full Rs 51.30 crore via SWIFT to the fraudulent account. The scheme was built on real, non-public knowledge of an actual intercompany payment and impersonated named, legitimate counterparties using compromised or subtly altered look-alike email addresses, not a generic cold lure.
The lure combined three elements: (1) precise, non-public knowledge of a real intercompany payment made just two days earlier, lending immediate plausibility; (2) impersonation of two specifically-named real counterparts, Ascend's "head of international operations" and an "accounting manager", via compromised or lookalike email addresses, rather than an anonymous sender; and (3) a bureaucratic, low-suspicion pretext (avoiding an "exorbitant tax" charge) that framed the fraudulent transfer as protecting the company's money, not risking it.
The tell that finally broke the scheme was a follow-up request, apparently from the same "Ghare" account, asking for an additional Rs 90 crore, a jump in scale abnormal enough that Alkem staff called Ghare directly through an independent channel, and he denied ever sending it, exposing that the prior emails had come from spoofed/compromised addresses with subtly altered characters.
US law enforcement seized Rs 28.98 crore of the stolen funds before they could be fully laundered out, and this amount was refunded to Alkem; the company's reported net unrecovered loss was Rs 22.31 crore (Mumbai Police/media figures) or Rs 22.27 crore per Alkem's own FY2023-24 exceptional-item accounting. Mumbai's cyber police registered an FIR against unidentified persons under IPC sections 419 (cheating by personation), 420 (cheating), 465/467/468/471 (forgery-related) and 34 (common intention), plus relevant IT Act provisions; no arrests were reported as of the sources reviewed.
Alkem stated the incident did not involve any fraudulent act by its own promoters, directors, KMPs, or senior management, engaged independent external agencies to investigate, and disclosed the matter to BSE/NSE per SEBI materiality/governance norms even though it said the amount did not cross formal materiality thresholds. Separately, on 15 May 2025 Alkem disclosed that Enzene Biosciences Ltd's US subsidiary had suffered a distinct incident in which employee business email accounts were compromised, resulting in a fraudulent fund transfer whose amount was still under investigation at disclosure time.
This case is a well-documented, dual illustration of business email compromise risk in cross-border intercompany treasury operations at a large, publicly-listed multinational: attackers weaponized real, non-public transaction context (an actual recent invoice payment) combined with impersonation of named real executives to make a fraudulent refund request highly credible, defeating a trained treasury professional.
It also shows that a single company can suffer materially significant, near-identical BEC-style incidents at different subsidiaries within about 18 months despite remediation efforts (Alkem's post-2024 partnership with Check Point Software), because the newly-compromised foreign subsidiary was reportedly still outside the upgraded security perimeter.
The case additionally illustrates that cross-border law-enforcement cooperation can claw back a meaningful share (roughly 56%) of stolen funds if reported and acted on quickly, and it is a clean example of India's SEBI-driven listed-company cyber-incident disclosure regime in action via BSE/NSE filings.
Recommended controls highlighted by this case: independently-sourced callback verification (phone, not numbers/addresses from the suspect email) before honoring ANY change-of-bank-account or refund request; heightened scrutiny of urgent requests to redirect funds tied to a real, recently-completed invoice/payment; automated detection of lookalike/spoofed vendor and executive domains; dual-approval/maker-checker sign-off for cross-border SWIFT transfers above a threshold; extending email/endpoint security tooling uniformly across ALL subsidiaries (Alkem's own post-incident statement noted the affected foreign subsidiary was "operating independently outside the corporate systems" and not yet covered by the company's Check Point deployment); rapid law-enforcement and correspondent-bank engagement to freeze funds in the destination country before they are laundered out (this is what enabled partial recovery here).
Social Engineering Examples. “Alkem Laboratories: Ascend Laboratories Impersonation BEC and Enzene Biosciences Email Compromise”. Accessed 19 September 2026. https://socialengineeringexamples.com/alkem-laboratories-ascend-enzene-bec-2023-2024
attackers likely built their pretext around genuine, close-in-time knowledge of a real intercompany payment (the Rs 51.30 crore Ascend-to-Alkem transfer of 25 October 2023) and named senior Ascend personnel, including the actual head of international operations; this level of detail is consistent with either a mailbox the attackers already had visibility into or targeted OSINT and social engineering against Ascend/Alkem staff and public corporate materials, though no source confirms exactly how this information was obtained.
non-public transaction and personnel detail can leak through a compromised mailbox, a compromised counterparty, or patient social engineering, and is very hard to fully deny an attacker at enterprise scale; the realistic control is limiting who can see sensitive payment and org-chart data internally and monitoring for signs of mailbox compromise, rather than assuming this information stays secret.
to send messages that appeared to come from named real Ascend employees, the scheme relied on either genuinely compromised Ascend or Alkem business email accounts, or look-alike sender addresses with subtly altered characters, the kind of domain-spoofing typically registered and prepared before a BEC lure is sent.
enforcing strict email-authentication controls (SPF, DKIM, DMARC), monitoring for newly registered look-alike domains, and deploying mailbox-security tooling that flags subtly altered sender addresses or suspicious mailbox rule changes, consistently across every subsidiary rather than only at corporate headquarters, closes the gap the case itself identifies as the reason a second, near-identical incident happened at a different subsidiary.
on 27 October 2023, Alkem's treasury manager received an email purporting to be from Ascend's head of international operations, warning that the recent payment would trigger exorbitant taxes and asking for the funds to be refunded to a new account, an urgency-plus-plausibility lure grounded in a real, recent transaction.
training staff to treat any urgent, bureaucratically framed request to redirect a payment, especially one tied to taxes or penalties, as requiring independent verification regardless of how routine or plausible it sounds, directly counters the psychological lever this stage relies on.
on 17 November 2023, a second email, purporting to be from a named Ascend accounting employee, supplied the actual fraudulent US bank account details needed to complete the diversion.
mandatory callback verification through previously known, independently sourced phone numbers or contacts, never numbers or addresses taken from the suspect email itself, before accepting any change of bank account or refund destination, is the single control best matched to stopping this exact step.
relying on the credibility built in stages 1 through 4 and without an independent callback to the real counterparts, Alkem's treasury manager wired the full Rs 51.30 crore via SWIFT to the fraudulent account.
dual-approval or maker-checker sign-off for cross-border wire transfers above a set threshold, requiring a second, independent reviewer to confirm any payee or account change before release, would have given the scheme a second chance to be caught before the money left Alkem's control.
once the funds landed in the fraudulent US account, the attackers moved to disperse or launder them out, the point at which the scheme's financial objective was substantially achieved, before US law enforcement intervened and seized a portion of the money.
rapid engagement with law enforcement and the correspondent/receiving bank as soon as fraud is suspected, requesting an emergency SWIFT recall or account freeze, can claw back funds before they are fully laundered out; this is the control that produced Alkem's partial Rs 28.98 crore recovery in this case, though full recovery is never guaranteed once funds leave the origin account.
Browse by what this case has in common with others in the library.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
A spoofed email impersonating a company executive tricked a Main Line Health employee into emailing all ~11,000 staff W-2s to…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data…
An unrelated MHRA search warrant found care-home patient prescription and NHS records rotting in unlocked crates and bin bags at…
CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters.
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
California's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured.
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from…
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…