Belgian bank Crelan lost close to EUR 70 million (~US$75.8M) after fraudsters impersonating its CEO induced internal staff to execute a series of unauthorized wire transfers, discovered via internal controls in January 2016.
Reviewed by the Social Engineering Examples team.
In January 2016, Crelan, a mid-sized Belgian cooperative bank, discovered it had been the victim of a large-scale "fake president" (CEO fraud) scheme. Attackers impersonating the bank's own CEO induced employees to execute a series of unauthorized wire transfers over an extended period. Crelan said the fraud was uncovered on 14 January 2016 through its internal controls/audit process and publicly disclosed the incident on 19 January 2016, describing a gross loss of "nearly" or "up to" EUR 70 million (about US$75.8 million at the time). The bank stated the scheme was organized from abroad, that no customer funds or accounts were affected, and that it would absorb the loss through its own financial reserves without requiring external support. Crelan's FY2015 annual report confirms the fraud materially reduced that year's net result (to EUR 40.59 million from a hypothetical EUR 71 million); a separate FSMA-approved 2018 prospectus confirms Crelan recovered EUR 10 million from its insurer during 2016, the maximum payable under that policy; and the bank's 2020 consolidated financial statements later noted an additional "exceptional recovery" in FY2019 tied to the 2016 fraud, though the exact accounting split of the original loss across fiscal years and the amount of that later 2019 recovery are not clearly documented in the sources reviewed.
Fraudsters impersonating Crelan's CEO (a classic "fake president"/BEC-style attack) contacted employees within the bank's payment-authorization chain, reportedly via email, and issued instructions to execute wire transfers under false pretenses, invoking the authority of the chief executive to bypass or move quickly through internal controls. Belgian press reporting (not confirmed directly by Crelan) indicated the scheme was carried out via a series of repeated mid-sized transfers (reportedly around EUR 500,000 each, repeated dozens of times using the same authorization procedure) rather than a single large wire, which helped it evade some threshold-based controls, and that a substantial share of the funds were routed toward accounts in Hong Kong. Two employees were reportedly involved in initiating/executing the transfers, though Crelan never publicly named them. One secondary source (Slim Beleggen) additionally described the attackers as having first thoroughly mapped the bank's internal structure and covertly accessed its email correspondence before impersonating the CEO, though that specific technical detail is not corroborated by Crelan's own disclosures or by the other press accounts reviewed and should be read as unverified color rather than a confirmed intrusion method. The fraud was organized from abroad according to the bank's own characterization.
The lure was authority impersonation rather than a crafted phishing email lure in the consumer-fraud sense: attackers posed as Crelan's own chief executive, a figure whose instructions internal staff would be strongly disposed to comply with quickly and without challenge, particularly if the message conveyed urgency and requested discretion/confidentiality (hallmarks of the "fake president" playbook used across dozens of similar 2015-2016 European CEO-fraud cases). The "tell," visible only in hindsight, was that legitimate CEOs do not personally initiate ad hoc wire-transfer instructions to operational staff outside normal payment workflows, especially not ones requiring secrecy or bypassing standard dual-control/callback verification, and repeated transfers to new or foreign (Hong Kong) beneficiary accounts should have been a monitoring flag.
Crelan absorbed the loss through its own reserves and reported no impact to customer funds. Its own annual reports confirm the fraud reduced the Crelan Group's FY2015 net result to EUR 40.59 million (versus a hypothetical EUR 71 million without the impact). A precise, source-confirmed breakdown of how much of the roughly EUR 70 million was booked in FY2015 versus FY2016 could not be verified in the primary or secondary sources reviewed (a commonly-repeated "EUR 44.6M FY2015 / EUR 24.5M FY2016" split should be treated as unconfirmed, and the EUR 24.5M figure specifically coincides with an unrelated 2019 dividend figure elsewhere in Crelan's reporting). The EUR 10 million insurance-payout figure often cited alongside that breakdown IS independently confirmed: CrelanCo's FSMA-approved 2018 prospectus states Crelan received a EUR 10 million payment from its insurer during 2016 for the fraud damage, the maximum recoverable under that policy. Separately, Crelan's 2020 Consolidated Financial Statements note that the bank realized an additional "exceptional recovery" in FY2019 tied to the 2016 CEO fraud, meaning further funds were likely recovered after the initial 2016 insurance payout, though that later amount is not stated in the sources reviewed. Belgian authorities, the Brussels prosecutor, opened a criminal investigation into fraud and criminal-organization offenses, but no public reporting reviewed identified, indicted, or convicted a specific attacker. The perpetrators remain publicly unidentified. No named employees faced public disciplinary or legal consequences in available sources.
Crelan's case became one of the most-cited European examples of the scale CEO fraud/BEC can reach when it targets employees with wire-transfer authority at a financial institution rather than a corporate finance department: a single social-engineering campaign exploiting internal deference to executive authority produced a loss large enough to visibly depress a fiscal year's net income. It illustrates that "whaling" attacks don't need to fool the executive being impersonated; they only need to fool the staff who trust that executive's (apparent) word, and that repeated transfers under an authority threshold can slip past controls calibrated for single large anomalies. It also shows the limits of after-the-fact remedies: despite a criminal investigation, the attackers were never publicly identified, and even years later the precise accounting resolution of the loss (what was recovered, via insurance or otherwise) remains murky in public reporting.
Belgian and European banks responded to Crelan and similar 2015-2016 CEO-fraud cases by tightening dual-authorization and callback-verification requirements for any payment instruction attributed to a CEO or senior executive, especially for transfers described as urgent, confidential, or originating outside normal channels; segregating instruction-initiation from execution so no single employee (even one who believes they are following the CEO's direct order) can complete a large transfer alone; mandating out-of-band verification (a phone call to a known, pre-verified number, not one supplied in the suspect email) before executing any unusual high-value wire; running internal-fraud and social-engineering awareness training specifically warning staff that "the CEO" asking for secrecy and urgency is a classic red flag rather than a reason for special deference; and increasing use of transaction-monitoring/internal-audit controls capable of flagging repeated mid-sized transfers to new or foreign beneficiary accounts, which is reportedly how Crelan's fraud was ultimately caught.
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…