Case Library / Phishing / FACC "Fake President" CEO fraud drains ~EUR 42M from Austrian aerospace supplier
Phishing Confirmed

FACC "Fake President" CEO fraud drains ~EUR 42M from Austrian aerospace supplier

Fraudsters impersonating FACC's CEO by email convinced finance staff to wire roughly EUR 50M for a fake acquisition project; EUR 41.9M was lost and both the CEO and CFO were later fired.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On January 19, 2016, FACC AG disclosed via an ad-hoc regulatory statement (it is listed on the Vienna Stock Exchange) that it had become the victim of "fraudulent activities involving communication and information technologies." The financial accounting department of subsidiary FACC Operations GmbH was the target of what FACC itself later termed the "Fake President Incident." Attackers impersonating CEO Walter Stephan sent email instructions requesting a large transfer of funds for a purported acquisition/project. Staff wired approximately EUR 50M (nearly 10% of annual revenue). FACC stressed that its IT infrastructure, data security, IP rights and operational business were not compromised, and that no malware was involved: this was a social-engineering/deception fraud, not a system breach. FACC filed a criminal complaint and launched a forensic investigation. It managed to block EUR 10.9M in recipient accounts, resulting in a net one-time charge of EUR 41.9M. The company fired its CFO (Minfen Gu) in February 2016 and dismissed CEO Walter Stephan, a 17-year veteran, with immediate effect on May 24, 2016, concluding he had "severely violated his duties, in particular in relation to the Fake President Incident." Facts are drawn from FACC's own ad-hoc disclosures and corroborated by Reuters, Bloomberg and trade press.

How the Attack Worked

This was a Business Email Compromise / CEO fraud (also called "fake president," "bogus boss," or whaling). Rather than exploiting a technical vulnerability, the fraudsters exploited organizational trust: they crafted email(s) appearing to come from the CEO instructing finance staff to transfer money for a confidential, time-sensitive acquisition project. FACC confirmed no malware and no IT-system breach was found, underscoring that the attack succeeded through impersonation and manipulation of authority rather than hacking. The request routed around normal scrutiny because it appeared to carry executive authority and framed the transfer as an urgent, legitimate business deal.

The Lure & the Tell

Lure: an email purporting to be from the CEO directing accounting staff to wire funds for a fake acquisition/project, leveraging executive authority, urgency and confidentiality. Tells (in hindsight): a payment request that bypasses standard authorization and dual-control procedures; unusually large, out-of-pattern transfer to a new/external account; a "confidential deal" framing that discourages verification; and instructions arriving only by email without independent, out-of-band confirmation from the named executive.

Outcome

Net loss of EUR 41.9M after EUR 10.9M was frozen. FACC's share price fell sharply (roughly 17% on disclosure). The CFO was fired in February 2016 and the CEO on May 24, 2016; Robert Machtlinger was appointed interim CEO. FACC pursued insurance claims and civil recovery. No public confirmation of arrests or full recovery of the remaining funds in the company disclosures reviewed.

Why It Matters

FACC is one of the most-cited, best-documented BEC/CEO-fraud cases because the victim publicly disclosed it as a listed company, quantified the loss, and took the rare step of firing both its long-serving CEO and its CFO. It shows that a pure social-engineering attack, with no malware and no system breach, can inflict eight-figure damage on a sophisticated global manufacturer, and that finance controls (payment authorization, dual approval, out-of-band verification) matter more than perimeter security against this threat. It also illustrates board-level accountability for wire-fraud controls.

Defenses

Require out-of-band verification (a call-back to a known number, not one supplied in the email) for any executive-initiated or large/unusual wire. Enforce dual authorization and segregation of duties for payments above a threshold. Treat "confidential, urgent" transfer requests as a red flag and empower staff to pause and verify without fear of contradicting an executive. Deploy email authentication (SPF/DKIM/DMARC) and flag external/look-alike senders. Train finance teams specifically on CEO-fraud/BEC patterns and run simulations. Maintain fraud-response and recovery playbooks (rapid bank recall requests can freeze funds, as FACC's EUR 10.9M block showed).

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: CEO-fraud actors typically research a target's public filings, press releases, and executive bios before making contact. FACC's status as a Vienna Stock Exchange listed company with detailed ad-hoc disclosures and public executive bios would have given attackers the CEO's name (Walter Stephan), his tenure and standing, and the fact that FACC was mid-ramp on major Airbus and Boeing programs, consistent with the "acquisition/project" pretext later used.
Countering Stage 1: Public-company disclosure obligations and executive visibility are structurally very hard to hide. The realistic control assumes attackers already know the CEO's name and business context, and instead hardens the payment-approval process that this knowledge gets weaponized against.
2
Pretext and Infrastructure Setup: Consistent with known fake-president schemes, the actors likely spoofed or closely mimicked the CEO's email identity and identified the financial accounting department of subsidiary FACC Operations GmbH, rather than the parent company, as the specific team holding wire authority.
Countering Stage 2: Enforce email authentication (SPF/DKIM/DMARC) and monitor for look-alike domain registrations or spoofed sender infrastructure targeting the corporate domain, so impersonation attempts are flagged before reaching an inbox.
3
Initial Contact and Authority Framing: An email purporting to come from CEO Walter Stephan was sent directly to finance staff, invoking his authority as chairman of the management board rather than routing through normal procurement or treasury channels.
Countering Stage 3: Train finance staff that a payment instruction leaning on the sender's title or authority, rather than on standard documentation and approval workflow, is a red flag requiring escalation regardless of who appears to have sent it.
4
Urgency and Confidentiality Pressure: The message framed the request as a confidential, time-sensitive acquisition or project, a standard fake-president lever meant to discourage staff from consulting colleagues or verifying through ordinary channels.
Countering Stage 4: Institutionalize a rule that "confidential" or "urgent" framing is never a valid reason to skip verification, paired with a no-blame culture so staff can pause and question an apparent executive without fear of career consequences.
5
Fraudulent Wire Instruction: The email instructed staff to transfer funds to an external account controlled by the attackers, with no independent, out-of-band confirmation requested from Stephan himself.
Countering Stage 5: Require dual authorization and segregation of duties for any wire above a defined threshold, so no single deceived employee can complete a large transfer alone.
6
Transfer Execution: FACC Operations GmbH staff wired approximately EUR 50M based on the emailed instruction alone; FACC confirmed no malware or IT-system breach was involved, meaning the money moved through legitimate banking channels on the strength of the impersonation alone.
Countering Stage 6: Mandate out-of-band verification, a callback to a known phone number, not one supplied in the email, for any executive-initiated or unusual wire before funds leave the company.
7
Fund Dispersal Across Recipient Accounts: The stolen funds were moved into multiple recipient bank accounts, typical of business-email-compromise cash-out schemes that layer funds quickly across accounts to frustrate recall attempts.
Countering Stage 7: Bank-side automated monitoring for sudden, high-value transfers to unfamiliar beneficiary accounts can flag movement of stolen funds, and rapid internal fraud reporting maximizes the window in which a bank can act before funds are dispersed further.
8
Detection, Freeze, and Objective Completion: FACC discovered the fraud, filed a criminal complaint, and worked with banks to block EUR 10.9M still sitting in recipient accounts before it could be withdrawn. The remainder, a net EUR 41.9M after accounting adjustments, was successfully extracted by the attackers, who were never publicly identified or arrested.
Countering Stage 8: Maintain a rehearsed fraud-response and bank-recall playbook. FACC's ability to freeze EUR 10.9M shows that fast reporting to banks and law enforcement after discovery can claw back a meaningful share of stolen funds even after a transfer has already gone out.
Quick Facts
Victim
FACC AG / FACC Operations GmbH, an Austrian aerospace parts manufacturer (Ried im Innkreis) and Tier-1 supplier to Airbus, Boeing and Rolls-Royce; majority-owned by Aviation Industry Corp. of China. The finance/accounting department was the direct target.
Location
Ried im Innkreis, Austria
Date
2016-01-19
Impact
Approx. EUR 50M initially transferred out; EUR 10.9M was frozen/blocked in recipient accounts and later partially recovered, leaving a one-time charge of EUR 41.9M (~$47-50M) on the 2015/16 results. The loss pushed FACC to an EBIT of EUR -23.4M for the year.
Status
Confirmed
Case Type
Real-World Incident
Sector
Defense & Aerospace, Transportation & Logistics
Related

Related Cases

Seagate CEO-Spoof W-2 Phishing Breach (2016)

A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…

Incident 2016Read →

Snapchat W-2 Payroll Phishing Breach (2016)

A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…

Incident 2016Read →

Pivotal Labs W-2 Phishing (CEO-Spoof), 2016

A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…

Incident 2016Read →