Case Library / Phishing / JE Cleantech Holdings Dividend-Payment BEC via Fake DTC Impersonation (2026)
Phishing Confirmed

JE Cleantech Holdings Dividend-Payment BEC via Fake DTC Impersonation (2026)

A fraudulent email impersonating The Depository Trust Company (DTC) supplied fake wire instructions for JE Cleantech Holdings' declared cash dividend, diverting USD 794,934.04 away from DTC and delaying payment to shareholders.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

JE Cleantech Holdings Limited (Nasdaq: JCSE) discovered on February 7, 2026 (Singapore time) that it had been defrauded during the payment process for a previously declared cash dividend (US$0.44/share, declared January 5, 2026, record date January 21, 2026, originally expected to be paid on or around January 28, 2026). A fraudulent email impersonating The Depository Trust Company (DTC), the real clearing intermediary through which the dividend was to be routed to street-name shareholders, contained false wire-transfer instructions. Funds intended for DTC were instead wired to the fraudulent account, so DTC never received the money and shareholders were not paid on schedule. The company lost USD 794,934.04 (approximately S$1,009,000). JCSE reported the incident to the FBI's Internet Crime Complaint Center (IC3), the Singapore Police Force, and both the sending and receiving banks; preserved evidence; and disclosed the incident publicly via SEC Form 6-K on February 9, 2026. A follow-up Form 6-K/A filed February 25, 2026 confirmed the legitimate dividend was separately transmitted to JCSE's transfer agent on February 20, 2026 and paid by February 24, 2026, a remedial payment, not a recovery of the stolen funds.

How the Attack Worked

JCSE had declared a cash dividend of US$0.44 per ordinary share (announced January 5, 2026; record date January 21, 2026; expected payment on or around January 28, 2026) to be routed through The Depository Trust Company (DTC) for distribution to street-name shareholders. At some point in this payment process, someone at JCSE (or an entity with visibility into the payment instructions) received a fraudulent email spoofing/impersonating DTC that supplied false wire-transfer instructions for where to send the dividend funds. Believing the email to be a legitimate DTC instruction, JCSE (or its bank acting on JCSE's instruction) wired USD 794,934.04 to the account specified in the fraudulent email rather than DTC's real account. Because the destination was fraudulent, DTC never received the funds, and JCSE's street-name shareholders did not receive their dividend on the original schedule. JCSE discovered the fraud on February 7, 2026 (Singapore time).

The Lure & the Tell

The lure: an email that looked like it came from The Depository Trust Company (DTC), the real, well-known clearing-house intermediary JCSE's own dividend was already routed through, supplying "official" wire instructions for the dividend payment. Because DTC was already the expected counterparty in this exact transaction, the impersonation exploited legitimate context and urgency (a live, scheduled dividend payment with a real deadline) rather than a cold, out-of-context request. The tell in hindsight: genuine payment-routing instructions from a regulated clearing entity like DTC would not normally change via an unsolicited or altered email; any change to wire/ACH instructions for a financial intermediary should always be verified out-of-band via a known phone number or established account portal, never by replying to or trusting the instructions embedded in the email itself.

Outcome

JCSE lost USD 794,934.04 to the fraudulent wire. The dividend was not paid to street-name shareholders on the original January 28, 2026 target date. The company reported the fraud to the FBI's IC3, the Singapore Police Force, and both the sending and receiving banks; preserved evidence; and conducted an internal review, stating no significant impact on business operations. In a follow-up Form 6-K/A (filed February 25, 2026), JCSE disclosed it transmitted the dividend to its transfer agent on February 20, 2026, and confirmed on February 24, 2026 that the dividend payment had been "duly made", meaning shareholders were ultimately paid, but as a separate remedial payment, not a recovery of the stolen funds. No recovery of the misappropriated USD 794,934.04, and no insurance reimbursement, is disclosed in the reviewed filings.

Why It Matters

This case is a clean, publicly documented example of BEC targeting the corporate-actions/dividend-payment workflow rather than the more commonly discussed vendor-invoice or CEO-fraud variants. It shows that even a routine, well-established payment relationship with a trusted, regulated financial-market utility (DTC) is exploitable if wire instructions arriving by email are trusted without independent, out-of-band verification. The near-USD-800K loss, the double payment burden (paying the fraud plus separately paying the real dividend), and the SEC 6-K disclosure trail make it a strong, well-sourced teaching example for treasury/finance teams handling any bulk or scheduled outbound payment (dividends, payroll, supplier payments, M&A escrow) where "the instructions look official" is not sufficient verification.

Defenses

JCSE's own filing frames the fix as procedural: it reported the incident to the FBI's IC3, the Singapore Police Force, and both the sending and receiving banks; engaged its internal IT security team to document the breach and preserve evidence; and launched an internal review of the cybersecurity incident. No public disclosure of specific control changes (e.g., callback-verification policy, dual-authorization thresholds, or verified-contact registries for DTC/transfer-agent wires) has been made in the filings reviewed. The generalizable defense this case illustrates: any change to wire instructions for a financial intermediary (DTC, a bank, a transfer agent), however official the sender name looks, must be verified through an independent, previously-established channel (a phone call to a known number, not one in the email) before funds move, and dual sign-off/maker-checker controls should apply to all dividend and large outbound wire payments regardless of counterparty prestige.

Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target selection: A dividend payment routed through a well-known, regulated intermediary like DTC is typically visible or inferable from public dividend-declaration disclosures (JCSE's own January 5, 2026 press release named the record date and expected payment date), letting an attacker plan the timing of a fraudulent instruction to arrive during a live, real payment window rather than cold.
Countering Stage 1: Public dividend-declaration filings are a legal disclosure requirement and cannot practically be hidden, so the realistic control is not suppressing this information but tightening verification on the payment-execution steps (Stages 3 and 5) that an attacker would exploit once they know the payment window.
2
Look-alike infrastructure and pretext setup: Impersonating a specific, real financial-market utility like DTC typically requires the attacker to stand up supporting infrastructure consistent with that persona, such as a look-alike sending domain or spoofed display name and a document or email format designed to resemble genuine DTC correspondence, though the specific mechanics were not disclosed in JCSE's filings.
Countering Stage 2: Look-alike domains and spoofed sender identities are hard to block universally at the inbound-email layer; DMARC/DKIM/SPF enforcement and brand-impersonation email filtering reduce but do not eliminate this risk, making out-of-band verification of any new instruction (Stage 5) the more reliable backstop.
3
Delivery of the fraudulent payment-instruction email: A fraudulent email purporting to be from DTC, containing false wire-transfer instructions, was delivered to JCSE or an entity with visibility into the dividend payment process, timed to coincide with the real, scheduled dividend payment.
Countering Stage 3: Email-security controls such as external-sender banners, attachment/link sandboxing, and impersonation-detection filters tuned to flag messages purporting to be from known financial-market utilities can catch some fraudulent DTC-branded email before it reaches a decision-maker.
4
Social engineering via procedural trust: Rather than a novel or suspicious request, the email was consistent with an expected step in a routine, already-underway payment workflow, lowering scrutiny because DTC was already the legitimate counterparty for this exact transaction.
Countering Stage 4: Staff handling payment instructions should be trained that a request arriving through the expected, familiar channel is not itself evidence of legitimacy, and that live/urgent payment context is precisely when fraud is most often timed to land.
5
Instruction substitution and wire execution: JCSE (or its bank acting on JCSE's instruction) accepted the fraudulent wire details as genuine and sent USD 794,934.04 to the attacker-controlled account instead of DTC's real account.
Countering Stage 5: Any change to or first receipt of wire instructions for a financial intermediary should be verified through an independent, previously-established channel, such as a phone call to a known number, not one contained in the email, before funds move; dual sign-off/maker-checker approval should be mandatory for dividend and other large outbound wires regardless of counterparty prestige.
6
Objective completion, funds diversion, and discovery: The fraudulent account received the funds while DTC never did, delaying the dividend to street-name shareholders; JCSE discovered the fraud on February 7, 2026, after which it reported the incident to law enforcement and disclosed it via SEC Form 6-K.
Countering Stage 6: Rapid post-incident actions, such as JCSE's reporting to the FBI's IC3, Singapore Police Force, and both sending and receiving banks within days of discovery, improve the odds of fund recovery or account freezing and support law-enforcement action, even though no recovery of the stolen funds was disclosed in this case.
Quick Facts
Victim
JE Cleantech Holdings Limited (Nasdaq: JCSE), a Cayman Islands-incorporated, Singapore-headquartered manufacturer of cleaning systems and dishwashing equipment (subsidiaries JCS-Echigo Pte. Ltd. and Hygieia Warewashing Pte. Ltd.)
Location
Singapore (JCSE headquartered at 3 Woodlands Sector 1, Singapore 738361); company incorporated in the Cayman Islands; listed on Nasdaq (US); DTC (the impersonated counterparty) is US-based
Date
2026-02-07 (discovered, Singapore time); disclosed via SEC Form 6-K on 2026-02-09; follow-up Form 6-K/A on 2026-02-25
Impact
USD 794,934.04 (approximately S$1,009,000) lost to the fraudulent wire; funds never reached DTC. This was in addition to (not a discount off) the underlying dividend obligation; JCSE later paid the legitimate dividend separately via its transfer agent. No portion of the stolen USD 794,934.04 is disclosed as recovered or insured in the SEC filings reviewed.
Status
Confirmed
Case Type
Real-World Incident
Sector
Manufacturing & Industrial
Related

Related Cases

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…

Incident 2026Read →

SCI Engineered Materials $898,325 Imposter Scam / Bank Fraud (2026)

A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an…

Incident 2026Read →

PROMPTSTEAL/LAMEHUG: APT28's LLM-Powered Malware Against Ukraine

Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…

Incident 2025Read →