Fraudsters impersonating FACC's CEO by email convinced finance staff to wire roughly EUR 50M for a fake acquisition project.
Social Engineering Examples·6 sources
On January 19, 2016, FACC AG disclosed via an ad-hoc regulatory statement (it is listed on the Vienna Stock Exchange) that it had become the victim of "fraudulent activities involving communication and information technologies." The financial accounting department of subsidiary FACC Operations GmbH was the target of what FACC itself later termed the "Fake President Incident." Attackers impersonating CEO Walter Stephan sent email instructions requesting a large transfer of funds for a purported acquisition/project.
Staff wired approximately EUR 50M (nearly 10% of annual revenue). FACC stressed that its IT infrastructure, data security, IP rights and operational business were not compromised, and that no malware was involved: this was a social-engineering/deception fraud, not a system breach. FACC filed a criminal complaint and launched a forensic investigation.
It managed to block EUR 10.9M in recipient accounts, resulting in a net one-time charge of EUR 41.9M. The company fired its CFO (Minfen Gu) in February 2016 and dismissed CEO Walter Stephan, a 17-year veteran, with immediate effect on May 24, 2016, concluding he had "severely violated his duties, in particular in relation to the Fake President Incident." Facts are drawn from FACC's own ad-hoc disclosures and corroborated by Reuters, Bloomberg and trade press.
This was a Business Email Compromise / CEO fraud (also called "fake president," "bogus boss," or whaling). Rather than exploiting a technical vulnerability, the fraudsters exploited organizational trust: they crafted email(s) appearing to come from the CEO instructing finance staff to transfer money for a confidential, time-sensitive acquisition project.
FACC confirmed no malware and no IT-system breach was found, underscoring that the attack succeeded through impersonation and manipulation of authority rather than hacking. The request routed around normal scrutiny because it appeared to carry executive authority and framed the transfer as an urgent, legitimate business deal.
Lure: an email purporting to be from the CEO directing accounting staff to wire funds for a fake acquisition/project, leveraging executive authority, urgency and confidentiality. Tells (in hindsight): a payment request that bypasses standard authorization and dual-control procedures; unusually large, out-of-pattern transfer to a new/external account; a "confidential deal" framing that discourages verification; and instructions arriving only by email without independent, out-of-band confirmation from the named executive.
Net loss of EUR 41.9M after EUR 10.9M was frozen. FACC's share price fell sharply (roughly 17% on disclosure). The CFO was fired in February 2016 and the CEO on May 24, 2016; Robert Machtlinger was appointed interim CEO. FACC pursued insurance claims and civil recovery. No public confirmation of arrests or full recovery of the remaining funds in the company disclosures reviewed.
FACC is one of the most-cited, best-documented BEC/CEO-fraud cases because the victim publicly disclosed it as a listed company, quantified the loss, and took the rare step of firing both its long-serving CEO and its CFO. It shows that a pure social-engineering attack, with no malware and no system breach, can inflict eight-figure damage on a sophisticated global manufacturer, and that finance controls (payment authorization, dual approval, out-of-band verification) matter more than perimeter security against this threat.
It also illustrates board-level accountability for wire-fraud controls.
Require out-of-band verification (a call-back to a known number, not one supplied in the email) for any executive-initiated or large/unusual wire. Enforce dual authorization and segregation of duties for payments above a threshold. Treat "confidential, urgent" transfer requests as a red flag and empower staff to pause and verify without fear of contradicting an executive.
Deploy email authentication (SPF/DKIM/DMARC) and flag external/look-alike senders. Train finance teams specifically on CEO-fraud/BEC patterns and run simulations. Maintain fraud-response and recovery playbooks (rapid bank recall requests can freeze funds, as FACC's EUR 10.9M block showed).
Social Engineering Examples. “FACC "Fake President" CEO fraud drains ~EUR 42M from Austrian aerospace supplier”. Accessed 19 September 2026. https://socialengineeringexamples.com/facc-fake-president-ceo-fraud-2016
CEO-fraud actors typically research a target's public filings, press releases, and executive bios before making contact. FACC's status as a Vienna Stock Exchange listed company with detailed ad-hoc disclosures and public executive bios would have given attackers the CEO's name (Walter Stephan), his tenure and standing, and the fact that FACC was mid-ramp on major Airbus and Boeing programs, consistent with the "acquisition/project" pretext later used.
Public-company disclosure obligations and executive visibility are structurally very hard to hide. The realistic control assumes attackers already know the CEO's name and business context, and instead hardens the payment-approval process that this knowledge gets weaponized against.
Consistent with known fake-president schemes, the actors likely spoofed or closely mimicked the CEO's email identity and identified the financial accounting department of subsidiary FACC Operations GmbH, rather than the parent company, as the specific team holding wire authority.
Enforce email authentication (SPF/DKIM/DMARC) and monitor for look-alike domain registrations or spoofed sender infrastructure targeting the corporate domain, so impersonation attempts are flagged before reaching an inbox.
An email purporting to come from CEO Walter Stephan was sent directly to finance staff, invoking his authority as chairman of the management board rather than routing through normal procurement or treasury channels.
Train finance staff that a payment instruction leaning on the sender's title or authority, rather than on standard documentation and approval workflow, is a red flag requiring escalation regardless of who appears to have sent it.
The message framed the request as a confidential, time-sensitive acquisition or project, a standard fake-president lever meant to discourage staff from consulting colleagues or verifying through ordinary channels.
Institutionalize a rule that "confidential" or "urgent" framing is never a valid reason to skip verification, paired with a no-blame culture so staff can pause and question an apparent executive without fear of career consequences.
The email instructed staff to transfer funds to an external account controlled by the attackers, with no independent, out-of-band confirmation requested from Stephan himself.
Require dual authorization and segregation of duties for any wire above a defined threshold, so no single deceived employee can complete a large transfer alone.
FACC Operations GmbH staff wired approximately EUR 50M based on the emailed instruction alone; FACC confirmed no malware or IT-system breach was involved, meaning the money moved through legitimate banking channels on the strength of the impersonation alone.
Mandate out-of-band verification, a callback to a known phone number, not one supplied in the email, for any executive-initiated or unusual wire before funds leave the company.
The stolen funds were moved into multiple recipient bank accounts, typical of business-email-compromise cash-out schemes that layer funds quickly across accounts to frustrate recall attempts.
Bank-side automated monitoring for sudden, high-value transfers to unfamiliar beneficiary accounts can flag movement of stolen funds, and rapid internal fraud reporting maximizes the window in which a bank can act before funds are dispersed further.
FACC discovered the fraud, filed a criminal complaint, and worked with banks to block EUR 10.9M still sitting in recipient accounts before it could be withdrawn. The remainder, a net EUR 41.9M after accounting adjustments, was successfully extracted by the attackers, who were never publicly identified or arrested.
Maintain a rehearsed fraud-response and bank-recall playbook. FACC's ability to freeze EUR 10.9M shows that fast reporting to banks and law enforcement after discovery can claw back a meaningful share of stolen funds even after a transfer has already gone out.
Browse by what this case has in common with others in the library.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer.
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A small Columbus, Ohio manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an imposter scam…
A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment.
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
Treasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China.
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).