Case Library / Phishing / Crelan Bank CEO Fraud (Belgium, 2016)
Phishing Confirmed

Crelan Bank CEO Fraud (Belgium, 2016)

Belgian bank Crelan lost close to EUR 70 million (~US$75.8M) after fraudsters impersonating its CEO induced internal staff to execute a series of unauthorized wire transfers, discovered via internal controls in January 2016.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In January 2016, Crelan, a mid-sized Belgian cooperative bank, discovered it had been the victim of a large-scale "fake president" (CEO fraud) scheme. Attackers impersonating the bank's own CEO induced employees to execute a series of unauthorized wire transfers over an extended period. Crelan said the fraud was uncovered on 14 January 2016 through its internal controls/audit process and publicly disclosed the incident on 19 January 2016, describing a gross loss of "nearly" or "up to" EUR 70 million (about US$75.8 million at the time). The bank stated the scheme was organized from abroad, that no customer funds or accounts were affected, and that it would absorb the loss through its own financial reserves without requiring external support. Crelan's FY2015 annual report confirms the fraud materially reduced that year's net result (to EUR 40.59 million from a hypothetical EUR 71 million); a separate FSMA-approved 2018 prospectus confirms Crelan recovered EUR 10 million from its insurer during 2016, the maximum payable under that policy; and the bank's 2020 consolidated financial statements later noted an additional "exceptional recovery" in FY2019 tied to the 2016 fraud, though the exact accounting split of the original loss across fiscal years and the amount of that later 2019 recovery are not clearly documented in the sources reviewed.

How the Attack Worked

Fraudsters impersonating Crelan's CEO (a classic "fake president"/BEC-style attack) contacted employees within the bank's payment-authorization chain, reportedly via email, and issued instructions to execute wire transfers under false pretenses, invoking the authority of the chief executive to bypass or move quickly through internal controls. Belgian press reporting (not confirmed directly by Crelan) indicated the scheme was carried out via a series of repeated mid-sized transfers (reportedly around EUR 500,000 each, repeated dozens of times using the same authorization procedure) rather than a single large wire, which helped it evade some threshold-based controls, and that a substantial share of the funds were routed toward accounts in Hong Kong. Two employees were reportedly involved in initiating/executing the transfers, though Crelan never publicly named them. One secondary source (Slim Beleggen) additionally described the attackers as having first thoroughly mapped the bank's internal structure and covertly accessed its email correspondence before impersonating the CEO, though that specific technical detail is not corroborated by Crelan's own disclosures or by the other press accounts reviewed and should be read as unverified color rather than a confirmed intrusion method. The fraud was organized from abroad according to the bank's own characterization.

The Lure & the Tell

The lure was authority impersonation rather than a crafted phishing email lure in the consumer-fraud sense: attackers posed as Crelan's own chief executive, a figure whose instructions internal staff would be strongly disposed to comply with quickly and without challenge, particularly if the message conveyed urgency and requested discretion/confidentiality (hallmarks of the "fake president" playbook used across dozens of similar 2015-2016 European CEO-fraud cases). The "tell," visible only in hindsight, was that legitimate CEOs do not personally initiate ad hoc wire-transfer instructions to operational staff outside normal payment workflows, especially not ones requiring secrecy or bypassing standard dual-control/callback verification, and repeated transfers to new or foreign (Hong Kong) beneficiary accounts should have been a monitoring flag.

Outcome

Crelan absorbed the loss through its own reserves and reported no impact to customer funds. Its own annual reports confirm the fraud reduced the Crelan Group's FY2015 net result to EUR 40.59 million (versus a hypothetical EUR 71 million without the impact). A precise, source-confirmed breakdown of how much of the roughly EUR 70 million was booked in FY2015 versus FY2016 could not be verified in the primary or secondary sources reviewed (a commonly-repeated "EUR 44.6M FY2015 / EUR 24.5M FY2016" split should be treated as unconfirmed, and the EUR 24.5M figure specifically coincides with an unrelated 2019 dividend figure elsewhere in Crelan's reporting). The EUR 10 million insurance-payout figure often cited alongside that breakdown IS independently confirmed: CrelanCo's FSMA-approved 2018 prospectus states Crelan received a EUR 10 million payment from its insurer during 2016 for the fraud damage, the maximum recoverable under that policy. Separately, Crelan's 2020 Consolidated Financial Statements note that the bank realized an additional "exceptional recovery" in FY2019 tied to the 2016 CEO fraud, meaning further funds were likely recovered after the initial 2016 insurance payout, though that later amount is not stated in the sources reviewed. Belgian authorities, the Brussels prosecutor, opened a criminal investigation into fraud and criminal-organization offenses, but no public reporting reviewed identified, indicted, or convicted a specific attacker. The perpetrators remain publicly unidentified. No named employees faced public disciplinary or legal consequences in available sources.

Why It Matters

Crelan's case became one of the most-cited European examples of the scale CEO fraud/BEC can reach when it targets employees with wire-transfer authority at a financial institution rather than a corporate finance department: a single social-engineering campaign exploiting internal deference to executive authority produced a loss large enough to visibly depress a fiscal year's net income. It illustrates that "whaling" attacks don't need to fool the executive being impersonated; they only need to fool the staff who trust that executive's (apparent) word, and that repeated transfers under an authority threshold can slip past controls calibrated for single large anomalies. It also shows the limits of after-the-fact remedies: despite a criminal investigation, the attackers were never publicly identified, and even years later the precise accounting resolution of the loss (what was recovered, via insurance or otherwise) remains murky in public reporting.

Defenses

Belgian and European banks responded to Crelan and similar 2015-2016 CEO-fraud cases by tightening dual-authorization and callback-verification requirements for any payment instruction attributed to a CEO or senior executive, especially for transfers described as urgent, confidential, or originating outside normal channels; segregating instruction-initiation from execution so no single employee (even one who believes they are following the CEO's direct order) can complete a large transfer alone; mandating out-of-band verification (a phone call to a known, pre-verified number, not one supplied in the suspect email) before executing any unusual high-value wire; running internal-fraud and social-engineering awareness training specifically warning staff that "the CEO" asking for secrecy and urgency is a classic red flag rather than a reason for special deference; and increasing use of transaction-monitoring/internal-audit controls capable of flagging repeated mid-sized transfers to new or foreign beneficiary accounts, which is reportedly how Crelan's fraud was ultimately caught.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: the attackers likely researched Crelan's organizational structure, senior-executive identities (including then-CEO Luc Versele), and internal payment-authorization workflow before making contact, consistent with the standard 'fake president' playbook and with one secondary account's (uncorroborated) claim that they thoroughly mapped the bank's internal structure first.
Countering Stage 1: employee and executive OSINT exposure (org charts, leadership bios, press coverage) is very hard to eliminate at enterprise scale; the realistic control assumes attackers already have this information and hardens the downstream verification step (Stage 3) that it gets used against, rather than trying to suppress public information about who runs the bank.
2
Establishing an impersonation channel: to appear as the CEO in outbound correspondence, this style of attack typically relies on a look-alike or spoofed sender domain and/or a compromised mailbox; one secondary source claims the attackers had covertly accessed the bank's internal email correspondence, though that specific claim is not corroborated by Crelan's own disclosures.
Countering Stage 2: email-authentication controls (SPF/DKIM/DMARC enforcement) and automated banners flagging messages that impersonate internal executives from external or look-alike domains reduce, though cannot fully eliminate, the odds that a spoofed 'CEO' email reaches an employee's inbox looking legitimate.
3
Initial impersonated contact: fraudsters, posing as the CEO, contacted employees inside the bank's payment-authorization chain, reportedly via email, issuing instructions to execute wire transfers under false pretenses.
Countering Stage 3: any payment instruction attributed to a CEO or senior executive, especially one arriving only by email, should require mandatory out-of-band verification via a phone call to a known, pre-verified number rather than any contact information supplied in the message itself.
4
Social-engineering pressure: the messages invoked the CEO's authority and combined it with urgency and confidentiality framing, discouraging the targeted staff from questioning the instruction or verifying it through normal channels.
Countering Stage 4: social-engineering awareness training should explicitly frame a superior's request for urgency and secrecy as a red flag rather than a reason for special deference, and should give staff explicit psychological permission and a clear process to pause and escalate an executive's payment instruction without fear of appearing insubordinate.
5
Structuring the transfers to evade controls: rather than one large wire, the scheme was reportedly carried out as repeated mid-sized transfers of roughly EUR 500,000 each, executed dozens of times through the same authorization procedure, keeping each individual transaction under thresholds that would have triggered tighter scrutiny.
Countering Stage 5: transaction-monitoring and internal-audit rules should be tuned to flag repeated sub-threshold transfers sharing the same authorization pattern or requester, not just single large-value anomalies, and payment workflows should segregate instruction-initiation from execution so no one employee can both receive and complete a transfer alone.
6
Cross-border fund routing and cash-out: a substantial share of the stolen funds was reportedly directed to beneficiary accounts in Hong Kong, completing the theft by moving the money into accounts outside the bank's normal correspondent-banking relationships and Belgian jurisdiction.
Countering Stage 6: enhanced beneficiary and geographic-risk screening for wires to jurisdictions with no prior business relationship, combined with correspondent-bank and anti-money-laundering monitoring for rapid cross-border fund dispersal, gives the best chance of catching or unwinding the transfer before funds are fully cashed out; this class of control is reportedly close to how Crelan's own internal audit ultimately surfaced the fraud.
Quick Facts
Victim
Crelan Bank (Belgium)
Location
Belgium (Crelan Bank, headquartered in Brussels)
Date
2016-01-14 (fraud discovered internally); 2016-01-19 (publicly disclosed by Crelan)
Impact
Gross loss of nearly/up to EUR 70 million (~US$75.8 million at contemporaneous exchange rates). This top-line figure is directly confirmed by Crelan's own 2016 press statement ("fraude van bijna 70 miljoen EUR" / "fraude de près de 70 mio EUR") and by contemporaneous Belgian press (VRT, De Standaard, De Tijd, RTBF, De Morgen). The finer FY-by-FY accounting breakdown is only partially verifiable. Crelan's 2015 annual report confirms the fraud reduced the Crelan Group's FY2015 net result to EUR 40.59 million (from a hypothetical EUR 71 million "without this impact"), implying an after-tax FY2015 hit of roughly EUR 30.4 million that year, with the remainder of the loss presumably absorbed in FY2016. A widely-circulated granular breakdown of "EUR 44.6 million booked in FY2015, EUR 24.5 million in FY2016" could NOT be corroborated in either Crelan's 2015/2016 annual report PDFs or in any secondary press coverage found across multiple searches, and should be treated as unverified rather than confirmed. Notably, EUR 24.5 million also recurs, unrelated, as a 2019 cooperative-dividend figure in Crelan's later (2019/2020) consolidated financial statements, raising concern that figure may have been misattributed to the fraud loss rather than drawn from the actual disclosure. On the insurance side, CrelanCo's FSMA-approved 2018 cooperative-share prospectus states plainly that during 2016 Crelan received a EUR 10 million payment from its insurer for the fraud damage, the maximum amount recoverable under the relevant policy, so the widely-repeated "EUR 10 million insurance payout" figure IS independently confirmed by a primary regulatory filing. That 2016 insurance payout is distinct from, and should not be confused with, the separately-disclosed "exceptional recovery" that Crelan's 2020 Consolidated Financial Statements say occurred in FY2019 in relation to the 2016 fraud, whose amount is not stated in that document. Crelan stated no customers were financially affected and that the bank could absorb the loss through its reserves/capital buffers without external assistance.
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance
Threat Actor
Organized Crime
Related

Related Cases

Seagate CEO-Spoof W-2 Phishing Breach (2016)

A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…

Incident 2016Read →

Snapchat W-2 Payroll Phishing Breach (2016)

A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…

Incident 2016Read →

Pivotal Labs W-2 Phishing (CEO-Spoof), 2016

A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…

Incident 2016Read →