Fraudsters impersonating FACC's CEO by email convinced finance staff to wire roughly EUR 50M for a fake acquisition project; EUR 41.9M was lost and both the CEO and CFO were later fired.
Reviewed by the Social Engineering Examples team.
On January 19, 2016, FACC AG disclosed via an ad-hoc regulatory statement (it is listed on the Vienna Stock Exchange) that it had become the victim of "fraudulent activities involving communication and information technologies." The financial accounting department of subsidiary FACC Operations GmbH was the target of what FACC itself later termed the "Fake President Incident." Attackers impersonating CEO Walter Stephan sent email instructions requesting a large transfer of funds for a purported acquisition/project. Staff wired approximately EUR 50M (nearly 10% of annual revenue). FACC stressed that its IT infrastructure, data security, IP rights and operational business were not compromised, and that no malware was involved: this was a social-engineering/deception fraud, not a system breach. FACC filed a criminal complaint and launched a forensic investigation. It managed to block EUR 10.9M in recipient accounts, resulting in a net one-time charge of EUR 41.9M. The company fired its CFO (Minfen Gu) in February 2016 and dismissed CEO Walter Stephan, a 17-year veteran, with immediate effect on May 24, 2016, concluding he had "severely violated his duties, in particular in relation to the Fake President Incident." Facts are drawn from FACC's own ad-hoc disclosures and corroborated by Reuters, Bloomberg and trade press.
This was a Business Email Compromise / CEO fraud (also called "fake president," "bogus boss," or whaling). Rather than exploiting a technical vulnerability, the fraudsters exploited organizational trust: they crafted email(s) appearing to come from the CEO instructing finance staff to transfer money for a confidential, time-sensitive acquisition project. FACC confirmed no malware and no IT-system breach was found, underscoring that the attack succeeded through impersonation and manipulation of authority rather than hacking. The request routed around normal scrutiny because it appeared to carry executive authority and framed the transfer as an urgent, legitimate business deal.
Lure: an email purporting to be from the CEO directing accounting staff to wire funds for a fake acquisition/project, leveraging executive authority, urgency and confidentiality. Tells (in hindsight): a payment request that bypasses standard authorization and dual-control procedures; unusually large, out-of-pattern transfer to a new/external account; a "confidential deal" framing that discourages verification; and instructions arriving only by email without independent, out-of-band confirmation from the named executive.
Net loss of EUR 41.9M after EUR 10.9M was frozen. FACC's share price fell sharply (roughly 17% on disclosure). The CFO was fired in February 2016 and the CEO on May 24, 2016; Robert Machtlinger was appointed interim CEO. FACC pursued insurance claims and civil recovery. No public confirmation of arrests or full recovery of the remaining funds in the company disclosures reviewed.
FACC is one of the most-cited, best-documented BEC/CEO-fraud cases because the victim publicly disclosed it as a listed company, quantified the loss, and took the rare step of firing both its long-serving CEO and its CFO. It shows that a pure social-engineering attack, with no malware and no system breach, can inflict eight-figure damage on a sophisticated global manufacturer, and that finance controls (payment authorization, dual approval, out-of-band verification) matter more than perimeter security against this threat. It also illustrates board-level accountability for wire-fraud controls.
Require out-of-band verification (a call-back to a known number, not one supplied in the email) for any executive-initiated or large/unusual wire. Enforce dual authorization and segregation of duties for payments above a threshold. Treat "confidential, urgent" transfer requests as a red flag and empower staff to pause and verify without fear of contradicting an executive. Deploy email authentication (SPF/DKIM/DMARC) and flag external/look-alike senders. Train finance teams specifically on CEO-fraud/BEC patterns and run simulations. Maintain fraud-response and recovery playbooks (rapid bank recall requests can freeze funds, as FACC's EUR 10.9M block showed).
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…