A complex criminal phishing scheme induced Argan, Inc. to send two outbound wires in March 2023, producing a roughly $3 million pre-tax loss.
Social Engineering Examples·6 sources
On March 7, 2023, Argan, Inc. determined it had been the victim of what it called a "complex criminal phishing scheme" that resulted in two fraudulently-induced outbound wire transfers, on March 6 and March 7, 2023, to a third-party account. Argan disclosed the event in a Form 8-K filed with the SEC (Item 8.01, accession 0001558370-23-003484, signed by CFO Richard H. Deily, dated March 10, 2023).
The company said it self-discovered the fraud and promptly contacted the remitting bank, the receiving bank, dispute-resolution experts, and federal and local law enforcement, who continued to pursue recovery of the funds. Argan found no evidence of additional fraudulent activity and did not believe the incident led to unauthorized access to other company data.
It expected a one-time pre-tax charge of about $3.0 million if no further funds were recovered, with up to $0.2M recoverable through insurance. In its Q1 fiscal 2024 results (June 8, 2023), Argan reported the actual charge at roughly $3.2 million (about $0.24 per diluted share, pre-tax) in the "other loss" line, which along with a weaker revenue mix drove net income down to $2.1 million from $7.5 million a year earlier.
Notably, the loss was not material to the balance sheet: Argan reported $317 million in cash and liquid investments and no debt as of April 30, 2023.
Argan's public filings describe the outcome, not the exact deception mechanics. It was a phishing scheme that "fraudulently induced" the company's own personnel to authorize outbound wires. This is the hallmark of business email compromise (BEC): rather than breaching bank systems, criminals deceive an authorized employee into initiating a legitimate-looking payment to an account the attacker controls.
The two wires occurring across consecutive days is consistent with an attacker sustaining a false pretext long enough to extract a second payment before detection. Argan explicitly said it was evaluating and had already implemented "certain redundant controls" over outgoing electronic cash transfers, which points to a gap in payment-verification controls (for example, out-of-band confirmation of new or changed payee details) as the exploited weakness.
The specific lure (executive impersonation versus vendor/invoice redirection) was not disclosed by the company.
Lure: a fraudulent instruction that appeared to be a legitimate, authorized payment request, convincing enough that internal staff processed two wires on back-to-back days. Tells for this class of fraud: payment instructions that arrive by email and introduce new or changed banking details; pressure to move quickly; requests that bypass or shortcut normal approval and verification steps; and payee bank accounts that do not match a known, previously verified vendor or counterparty.
The reliable defense against these tells is out-of-band verification using a phone number or contact obtained independently of the request itself.
Funds were largely unrecovered: Argan booked an approximately $3.2 million pre-tax loss, initially expecting only up to about $0.2M back through insurance (its later 10-Q downgraded expected insurance reimbursement to not material). The company engaged specialized legal counsel and a cybersecurity firm for an independent forensic investigation, implemented additional redundant controls over outbound electronic transfers, and reported the matter to banks and to federal and local law enforcement.
No public arrest, indictment, or fund-recovery outcome was subsequently disclosed. Argan stated it did not expect the incident to materially affect its business or its ability to serve customers.
This is a well-documented, primary-sourced example of a phishing/BEC wire fraud hitting a mid-cap public company: it shows that a single successful social-engineering deception, requiring no malware or system breach, can extract $3M in two days. It underscores that finance-process controls (payment verification, dual approval, out-of-band confirmation of banking changes) are the real line of defense, since insurance recovered a trivial fraction and law enforcement recovery of wired funds is difficult once transfers clear.
The SEC-filing disclosure also illustrates how such losses surface publicly for reporting companies, making it a clean, citable teaching case.
Require out-of-band verification (a call to a known, pre-established number) for any new or changed payee banking details and for unusual or urgent wire requests. Enforce dual authorization and segregation of duties on outbound wires above a threshold. Treat email-delivered payment instructions as unverified by default. Add "redundant controls" over outgoing electronic transfers, as Argan did post-incident.
Train finance staff to recognize BEC pressure tactics and to slow down on urgency. Prepare an incident playbook: immediately notify the remitting and receiving banks to attempt recall/freeze, report to the FBI/IC3 within the recovery window, and engage forensic and legal counsel. Review commercial-crime and cyber/social-engineering insurance coverage and its verification-procedure conditions before an incident.
Social Engineering Examples. “Argan, Inc. $3M Phishing-Induced Wire Fraud (2023)”. Accessed 19 September 2026. https://socialengineeringexamples.com/argan-inc-3m-phishing-wire-fraud-2023
Argan's filings do not describe this step, but a targeted BEC of this kind is typically preceded by attackers researching the target company's finance staff, vendor relationships, and payment cadence through sources like LinkedIn, corporate filings, and vendor or project-partner websites, building enough context to draft a convincing payment request.
Public-facing OSINT about staff roles, vendors, and filings is very hard to eliminate at a public company; the realistic control assumes attackers already have this context and hardens the payment-verification process that gets used against, rather than trying to hide it.
consistent with common BEC patterns, this stage typically involves either compromising a vendor or executive email account, or registering a look-alike domain and spoofed sender identity, so a fraudulent payment request appears to come from a legitimate, already-trusted counterparty.
Email-authentication enforcement (SPF, DKIM, DMARC) and monitoring for newly registered look-alike domains reduce, though do not eliminate, the chance a spoofed or compromised sender lands convincingly in an employee's inbox.
Argan called the incident a "complex criminal phishing scheme"; consistent with that description, a finance employee likely received an email-based lure, plausibly framed as a routine or executive-authorized payment instruction, that was convincing enough to be acted on.
Phishing-aware email filtering and staff training to treat unexpected or unusually timed payment-related emails as unverified by default, matching Argan's own post-incident emphasis on control over outgoing transfers.
the deception induced staff to treat new or altered payee banking details, delivered by email, as trustworthy without out-of-band confirmation, the specific gap Argan later addressed with "redundant controls" over outgoing transfers.
Mandatory out-of-band verification, a call to a known, independently-obtained phone number, for any new or changed payee banking details before a wire is processed; this is the single highest-leverage control against this fraud pattern.
finance staff processed the first outbound wire to the attacker-controlled account.
Dual authorization and segregation of duties on outbound wires above a set threshold introduces a second, independent check before funds leave the company.
the attacker sustained the same pretext long enough to extract a second wire on the following day, before the fraud was discovered.
Same-day reconciliation and velocity monitoring of large outbound wires against expected payment schedules would flag an unplanned second transfer to a new payee before it clears.
per the 8-K, funds moved to a third-party receiving account; attackers in this fraud category typically move proceeds onward quickly through intermediary or mule accounts to frustrate recall once a fraudulent wire clears, though Argan's filings do not detail what happened to the funds after receipt.
Once a wire clears, defense is largely limited to speed of discovery; there is little a victim can add at this stage beyond what Stage 8's rapid-notification response provides, since fund layering by the receiving party is outside the victim's control.
Argan self-discovered the fraud the same day as the second wire and notified its remitting and receiving banks, dispute-resolution experts, and law enforcement.
Argan's own response, same-day self-detection and immediate notification of both banks, dispute-resolution experts, and law enforcement, is close to best practice for this stage; the broader lesson is investing in finance-team reconciliation habits so self-detection happens within hours rather than days, maximizing the narrow window banks have to attempt a recall.
Browse by what this case has in common with others in the library.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
Scammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
Operation Buckshot Yankee: a malware-laden USB drive plugged into a U.S. military laptop in 2008 spread the agent.btz worm onto…
Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012.
A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title…
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.