A fraudulent email impersonating The Depository Trust Company (DTC) supplied fake wire instructions for JE Cleantech Holdings' declared cash dividend, diverting USD 794,934.04 away from DTC and delaying payment to shareholders.
Reviewed by the Social Engineering Examples team.
JE Cleantech Holdings Limited (Nasdaq: JCSE) discovered on February 7, 2026 (Singapore time) that it had been defrauded during the payment process for a previously declared cash dividend (US$0.44/share, declared January 5, 2026, record date January 21, 2026, originally expected to be paid on or around January 28, 2026). A fraudulent email impersonating The Depository Trust Company (DTC), the real clearing intermediary through which the dividend was to be routed to street-name shareholders, contained false wire-transfer instructions. Funds intended for DTC were instead wired to the fraudulent account, so DTC never received the money and shareholders were not paid on schedule. The company lost USD 794,934.04 (approximately S$1,009,000). JCSE reported the incident to the FBI's Internet Crime Complaint Center (IC3), the Singapore Police Force, and both the sending and receiving banks; preserved evidence; and disclosed the incident publicly via SEC Form 6-K on February 9, 2026. A follow-up Form 6-K/A filed February 25, 2026 confirmed the legitimate dividend was separately transmitted to JCSE's transfer agent on February 20, 2026 and paid by February 24, 2026, a remedial payment, not a recovery of the stolen funds.
JCSE had declared a cash dividend of US$0.44 per ordinary share (announced January 5, 2026; record date January 21, 2026; expected payment on or around January 28, 2026) to be routed through The Depository Trust Company (DTC) for distribution to street-name shareholders. At some point in this payment process, someone at JCSE (or an entity with visibility into the payment instructions) received a fraudulent email spoofing/impersonating DTC that supplied false wire-transfer instructions for where to send the dividend funds. Believing the email to be a legitimate DTC instruction, JCSE (or its bank acting on JCSE's instruction) wired USD 794,934.04 to the account specified in the fraudulent email rather than DTC's real account. Because the destination was fraudulent, DTC never received the funds, and JCSE's street-name shareholders did not receive their dividend on the original schedule. JCSE discovered the fraud on February 7, 2026 (Singapore time).
The lure: an email that looked like it came from The Depository Trust Company (DTC), the real, well-known clearing-house intermediary JCSE's own dividend was already routed through, supplying "official" wire instructions for the dividend payment. Because DTC was already the expected counterparty in this exact transaction, the impersonation exploited legitimate context and urgency (a live, scheduled dividend payment with a real deadline) rather than a cold, out-of-context request. The tell in hindsight: genuine payment-routing instructions from a regulated clearing entity like DTC would not normally change via an unsolicited or altered email; any change to wire/ACH instructions for a financial intermediary should always be verified out-of-band via a known phone number or established account portal, never by replying to or trusting the instructions embedded in the email itself.
JCSE lost USD 794,934.04 to the fraudulent wire. The dividend was not paid to street-name shareholders on the original January 28, 2026 target date. The company reported the fraud to the FBI's IC3, the Singapore Police Force, and both the sending and receiving banks; preserved evidence; and conducted an internal review, stating no significant impact on business operations. In a follow-up Form 6-K/A (filed February 25, 2026), JCSE disclosed it transmitted the dividend to its transfer agent on February 20, 2026, and confirmed on February 24, 2026 that the dividend payment had been "duly made", meaning shareholders were ultimately paid, but as a separate remedial payment, not a recovery of the stolen funds. No recovery of the misappropriated USD 794,934.04, and no insurance reimbursement, is disclosed in the reviewed filings.
This case is a clean, publicly documented example of BEC targeting the corporate-actions/dividend-payment workflow rather than the more commonly discussed vendor-invoice or CEO-fraud variants. It shows that even a routine, well-established payment relationship with a trusted, regulated financial-market utility (DTC) is exploitable if wire instructions arriving by email are trusted without independent, out-of-band verification. The near-USD-800K loss, the double payment burden (paying the fraud plus separately paying the real dividend), and the SEC 6-K disclosure trail make it a strong, well-sourced teaching example for treasury/finance teams handling any bulk or scheduled outbound payment (dividends, payroll, supplier payments, M&A escrow) where "the instructions look official" is not sufficient verification.
JCSE's own filing frames the fix as procedural: it reported the incident to the FBI's IC3, the Singapore Police Force, and both the sending and receiving banks; engaged its internal IT security team to document the breach and preserve evidence; and launched an internal review of the cybersecurity incident. No public disclosure of specific control changes (e.g., callback-verification policy, dual-authorization thresholds, or verified-contact registries for DTC/transfer-agent wires) has been made in the filings reviewed. The generalizable defense this case illustrates: any change to wire instructions for a financial intermediary (DTC, a bank, a transfer agent), however official the sender name looks, must be verified through an independent, previously-established channel (a phone call to a known number, not one in the email) before funds move, and dual sign-off/maker-checker controls should apply to all dividend and large outbound wire payments regardless of counterparty prestige.
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…
A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…