Case Library / Phishing / Alkem Laboratories: Ascend Laboratories Impersonation BEC and Enzene Biosciences Email Compromise
Phishing Confirmed

Alkem Laboratories: Ascend Laboratories Impersonation BEC and Enzene Biosciences Email Compromise

Fraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake US bank account under a bogus tax-refund pretext; Rs 22.31 crore was never recovered, and a second, separate business-email-compromise hit Alkem's Enzene Biosciences US subsidiary roughly 18 months later.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Alkem Laboratories, a major Indian pharmaceutical multinational, suffered two distinct, disclosed business-email-compromise incidents roughly 18 months apart. In the first, occurring between 27 October and 17 November 2023, fraudsters impersonated named executives of Alkem's US subsidiary Ascend Laboratories LLC via spoofed/compromised email accounts, exploiting genuine knowledge of a real Rs 51.30 crore intercompany payment Ascend had just made to parent Alkem. Using a fabricated "excess tax liability, please refund to this new account" pretext, they convinced Alkem's Mumbai-based treasury manager, Manoj Mishra, to wire the full Rs 51.30 crore via SWIFT to a fraudulent US bank account. The scheme was discovered only when a follow-up email requested an implausibly large additional "refund" of Rs 90 crore, prompting Alkem to call the real Ascend executive directly and learn the earlier emails were fake. Alkem's board resolved on 12 January 2024 to disclose the incident to BSE/NSE, and its Q3FY24 press release (9 February 2024) confirmed the ~Rs 51.31 crore fraudulent transfer from compromised subsidiary business email IDs. US law enforcement subsequently seized and returned Rs 28.98 crore, leaving a reported net loss of Rs 22.31 crore (per Mumbai Police/media reporting; Alkem's own FY24 accounts book a closely comparable Rs 290.4 million recovered / Rs 222.7 million net exceptional loss). Separately, on 15 May 2025, Alkem disclosed that its subsidiary Enzene Biosciences Ltd's US subsidiary had suffered its own cybersecurity incident in which employees' business email accounts were compromised, again resulting in a fraudulent fund transfer; the financial quantum was described as still under investigation at the time of that filing.

How the Attack Worked

Ascend Laboratories LLC (Alkem's New Jersey-based US subsidiary) made a legitimate Rs 51.30 crore payment to parent Alkem on 25 October 2023 for materials supplied between November 2022 and January 2023. Two days later, on 27 October 2023, Alkem's Mumbai-based manager of treasury operations, Manoj Mishra, received an email purporting to be from Amit Ghare, Ascend's head of international operations, claiming Ascend's bank had flagged that the payment would trigger exorbitant taxes and asking Alkem to "refund" the sum to a new account so it could be re-sent correctly. A follow-up email on 17 November 2023, purporting to be from an Ascend accounting manager named Mary Smith, supplied the fraudulent US bank account details. Believing the correspondence genuine, Mishra wired the full Rs 51.30 crore via SWIFT to the fraudulent account. The scheme was built on real, non-public knowledge of an actual intercompany payment and impersonated named, legitimate counterparties using compromised or subtly altered look-alike email addresses, not a generic cold lure.

The Lure & the Tell

The lure combined three elements: (1) precise, non-public knowledge of a real intercompany payment made just two days earlier, lending immediate plausibility; (2) impersonation of two specifically-named real counterparts, Ascend's "head of international operations" and an "accounting manager", via compromised or lookalike email addresses, rather than an anonymous sender; and (3) a bureaucratic, low-suspicion pretext (avoiding an "exorbitant tax" charge) that framed the fraudulent transfer as protecting the company's money, not risking it. The tell that finally broke the scheme was a follow-up request, apparently from the same "Ghare" account, asking for an additional Rs 90 crore, a jump in scale abnormal enough that Alkem staff called Ghare directly through an independent channel, and he denied ever sending it, exposing that the prior emails had come from spoofed/compromised addresses with subtly altered characters.

Outcome

US law enforcement seized Rs 28.98 crore of the stolen funds before they could be fully laundered out, and this amount was refunded to Alkem; the company's reported net unrecovered loss was Rs 22.31 crore (Mumbai Police/media figures) or Rs 22.27 crore per Alkem's own FY2023-24 exceptional-item accounting. Mumbai's cyber police registered an FIR against unidentified persons under IPC sections 419 (cheating by personation), 420 (cheating), 465/467/468/471 (forgery-related) and 34 (common intention), plus relevant IT Act provisions; no arrests were reported as of the sources reviewed. Alkem stated the incident did not involve any fraudulent act by its own promoters, directors, KMPs, or senior management, engaged independent external agencies to investigate, and disclosed the matter to BSE/NSE per SEBI materiality/governance norms even though it said the amount did not cross formal materiality thresholds. Separately, on 15 May 2025 Alkem disclosed that Enzene Biosciences Ltd's US subsidiary had suffered a distinct incident in which employee business email accounts were compromised, resulting in a fraudulent fund transfer whose amount was still under investigation at disclosure time.

Why It Matters

This case is a well-documented, dual illustration of business email compromise risk in cross-border intercompany treasury operations at a large, publicly-listed multinational: attackers weaponized real, non-public transaction context (an actual recent invoice payment) combined with impersonation of named real executives to make a fraudulent refund request highly credible, defeating a trained treasury professional. It also shows that a single company can suffer materially significant, near-identical BEC-style incidents at different subsidiaries within about 18 months despite remediation efforts (Alkem's post-2024 partnership with Check Point Software), because the newly-compromised foreign subsidiary was reportedly still outside the upgraded security perimeter. The case additionally illustrates that cross-border law-enforcement cooperation can claw back a meaningful share (roughly 56%) of stolen funds if reported and acted on quickly, and it is a clean example of India's SEBI-driven listed-company cyber-incident disclosure regime in action via BSE/NSE filings.

Defenses

Recommended controls highlighted by this case: independently-sourced callback verification (phone, not numbers/addresses from the suspect email) before honoring ANY change-of-bank-account or refund request; heightened scrutiny of urgent requests to redirect funds tied to a real, recently-completed invoice/payment; automated detection of lookalike/spoofed vendor and executive domains; dual-approval/maker-checker sign-off for cross-border SWIFT transfers above a threshold; extending email/endpoint security tooling uniformly across ALL subsidiaries (Alkem's own post-incident statement noted the affected foreign subsidiary was "operating independently outside the corporate systems" and not yet covered by the company's Check Point deployment); rapid law-enforcement and correspondent-bank engagement to freeze funds in the destination country before they are laundered out (this is what enabled partial recovery here).

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and pretext development: attackers likely built their pretext around genuine, close-in-time knowledge of a real intercompany payment (the Rs 51.30 crore Ascend-to-Alkem transfer of 25 October 2023) and named senior Ascend personnel, including the actual head of international operations; this level of detail is consistent with either a mailbox the attackers already had visibility into or targeted OSINT and social engineering against Ascend/Alkem staff and public corporate materials, though no source confirms exactly how this information was obtained.
Countering Stage 1: non-public transaction and personnel detail can leak through a compromised mailbox, a compromised counterparty, or patient social engineering, and is very hard to fully deny an attacker at enterprise scale; the realistic control is limiting who can see sensitive payment and org-chart data internally and monitoring for signs of mailbox compromise, rather than assuming this information stays secret.
2
Email compromise or look-alike spoofing setup: to send messages that appeared to come from named real Ascend employees, the scheme relied on either genuinely compromised Ascend or Alkem business email accounts, or look-alike sender addresses with subtly altered characters, the kind of domain-spoofing typically registered and prepared before a BEC lure is sent.
Countering Stage 2: enforcing strict email-authentication controls (SPF, DKIM, DMARC), monitoring for newly registered look-alike domains, and deploying mailbox-security tooling that flags subtly altered sender addresses or suspicious mailbox rule changes, consistently across every subsidiary rather than only at corporate headquarters, closes the gap the case itself identifies as the reason a second, near-identical incident happened at a different subsidiary.
3
Initial pretext contact: on 27 October 2023, Alkem's treasury manager received an email purporting to be from Ascend's head of international operations, warning that the recent payment would trigger exorbitant taxes and asking for the funds to be refunded to a new account, an urgency-plus-plausibility lure grounded in a real, recent transaction.
Countering Stage 3: training staff to treat any urgent, bureaucratically framed request to redirect a payment, especially one tied to taxes or penalties, as requiring independent verification regardless of how routine or plausible it sounds, directly counters the psychological lever this stage relies on.
4
Fraudulent payment-details delivery: on 17 November 2023, a second email, purporting to be from a named Ascend accounting employee, supplied the actual fraudulent US bank account details needed to complete the diversion.
Countering Stage 4: mandatory callback verification through previously known, independently sourced phone numbers or contacts, never numbers or addresses taken from the suspect email itself, before accepting any change of bank account or refund destination, is the single control best matched to stopping this exact step.
5
Social engineering of the victim into authorizing the wire: relying on the credibility built in stages 1 through 4 and without an independent callback to the real counterparts, Alkem's treasury manager wired the full Rs 51.30 crore via SWIFT to the fraudulent account.
Countering Stage 5: dual-approval or maker-checker sign-off for cross-border wire transfers above a set threshold, requiring a second, independent reviewer to confirm any payee or account change before release, would have given the scheme a second chance to be caught before the money left Alkem's control.
6
Fund receipt and attempted extraction (objective completion): once the funds landed in the fraudulent US account, the attackers moved to disperse or launder them out, the point at which the scheme's financial objective was substantially achieved, before US law enforcement intervened and seized a portion of the money.
Countering Stage 6: rapid engagement with law enforcement and the correspondent/receiving bank as soon as fraud is suspected, requesting an emergency SWIFT recall or account freeze, can claw back funds before they are fully laundered out; this is the control that produced Alkem's partial Rs 28.98 crore recovery in this case, though full recovery is never guaranteed once funds leave the origin account.
Quick Facts
Victim
Alkem Laboratories Ltd. (Mumbai-headquartered multinational pharmaceutical company; NSE/BSE-listed) via its US subsidiary Ascend Laboratories LLC being impersonated, and separately via employee email compromise at its subsidiary Enzene Biosciences Ltd.'s US operation
Location
Mumbai, India (Alkem Laboratories parent treasury office, victim of the wire fraud) and Parsippany-Troy Hills, New Jersey, US (Ascend Laboratories LLC, the impersonated subsidiary; also where the fraudulent account and subsequent law-enforcement seizure were located)
Date
27 October 2023 - 17 November 2023 (fraud execution window); fraud discovered ~mid-November 2023; board resolved to disclose 12 January 2024; separate Enzene Biosciences US subsidiary incident disclosed 15 May 2025
Impact
Ascend Laboratories impersonation case: Rs 51.30 crore (~$6.2M, company filings round to Rs 51.31 crore / Rs 513.1 million) fraudulently wired via SWIFT to a fraudulent US bank account. Rs 28.98 crore was seized by US law enforcement and refunded to Alkem; net unrecovered loss reported as Rs 22.31 crore (per Mumbai Police/Hindustan Times reporting). Alkem's own FY2023-24 statutory accounts record a slightly different rounding: Rs 29.04 crore (Rs 290.4 million) recovered in Q4FY24 and a Rs 22.27 crore (Rs 222.7 million) net exceptional loss booked for the incident. Separately, the Enzene Biosciences US subsidiary email-compromise incident (disclosed 15 May 2025) resulted in an undisclosed fraudulent fund transfer; Alkem stated the total quantum was "under investigation" and did not publish a figure in the primary filings reviewed.
Status
Confirmed
Case Type
Real-World Incident
Sector
Healthcare
Related

Related Cases

Retool smishing + deepfake vishing breach (2023)

A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…

Incident 2023Read →

New Haven Public Schools $6M COO-email vendor thread-hijack BEC

Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread, spoofed the vendor to…

Incident 2023Read →

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…

Incident 2022Read →