A fraudulent email impersonating The Depository Trust Company (DTC) supplied fake wire instructions for JE Cleantech Holdings' declared cash dividend.
Social Engineering Examples·6 sources
JE Cleantech Holdings Limited (Nasdaq: JCSE) discovered on February 7, 2026 (Singapore time) that it had been defrauded during the payment process for a previously declared cash dividend (US$0.44/share, declared January 5, 2026, record date January 21, 2026, originally expected to be paid on or around January 28, 2026). A fraudulent email impersonating The Depository Trust Company (DTC), the real clearing intermediary through which the dividend was to be routed to street-name shareholders, contained false wire-transfer instructions.
Funds intended for DTC were instead wired to the fraudulent account, so DTC never received the money and shareholders were not paid on schedule. The company lost USD 794,934.04 (approximately S$1,009,000). JCSE reported the incident to the FBI's Internet Crime Complaint Center (IC3), the Singapore Police Force, and both the sending and receiving banks; preserved evidence; and disclosed the incident publicly via SEC Form 6-K on February 9, 2026. A follow-up Form 6-K/A filed February 25, 2026 confirmed the legitimate dividend was separately transmitted to JCSE's transfer agent on February 20, 2026 and paid by February 24, 2026, a remedial payment, not a recovery of the stolen funds.
JCSE had declared a cash dividend of US$0.44 per ordinary share (announced January 5, 2026; record date January 21, 2026; expected payment on or around January 28, 2026) to be routed through The Depository Trust Company (DTC) for distribution to street-name shareholders. At some point in this payment process, someone at JCSE (or an entity with visibility into the payment instructions) received a fraudulent email spoofing/impersonating DTC that supplied false wire-transfer instructions for where to send the dividend funds.
Believing the email to be a legitimate DTC instruction, JCSE (or its bank acting on JCSE's instruction) wired USD 794,934.04 to the account specified in the fraudulent email rather than DTC's real account. Because the destination was fraudulent, DTC never received the funds, and JCSE's street-name shareholders did not receive their dividend on the original schedule.
JCSE discovered the fraud on February 7, 2026 (Singapore time).
The lure: an email that looked like it came from The Depository Trust Company (DTC), the real, well-known clearing-house intermediary JCSE's own dividend was already routed through, supplying "official" wire instructions for the dividend payment. Because DTC was already the expected counterparty in this exact transaction, the impersonation exploited legitimate context and urgency (a live, scheduled dividend payment with a real deadline) rather than a cold, out-of-context request.
The tell in hindsight: genuine payment-routing instructions from a regulated clearing entity like DTC would not normally change via an unsolicited or altered email; any change to wire/ACH instructions for a financial intermediary should always be verified out-of-band via a known phone number or established account portal, never by replying to or trusting the instructions embedded in the email itself.
JCSE lost USD 794,934.04 to the fraudulent wire. The dividend was not paid to street-name shareholders on the original January 28, 2026 target date. The company reported the fraud to the FBI's IC3, the Singapore Police Force, and both the sending and receiving banks; preserved evidence; and conducted an internal review, stating no significant impact on business operations.
In a follow-up Form 6-K/A (filed February 25, 2026), JCSE disclosed it transmitted the dividend to its transfer agent on February 20, 2026, and confirmed on February 24, 2026 that the dividend payment had been "duly made", meaning shareholders were ultimately paid, but as a separate remedial payment, not a recovery of the stolen funds. No recovery of the misappropriated USD 794,934.04, and no insurance reimbursement, is disclosed in the reviewed filings.
This case is a clean, publicly documented example of BEC targeting the corporate-actions/dividend-payment workflow rather than the more commonly discussed vendor-invoice or CEO-fraud variants. It shows that even a routine, well-established payment relationship with a trusted, regulated financial-market utility (DTC) is exploitable if wire instructions arriving by email are trusted without independent, out-of-band verification.
The near-USD-800K loss, the double payment burden (paying the fraud plus separately paying the real dividend), and the SEC 6-K disclosure trail make it a strong, well-sourced teaching example for treasury/finance teams handling any bulk or scheduled outbound payment (dividends, payroll, supplier payments, M&A escrow) where "the instructions look official" is not sufficient verification.
JCSE's own filing frames the fix as procedural: it reported the incident to the FBI's IC3, the Singapore Police Force, and both the sending and receiving banks; engaged its internal IT security team to document the breach and preserve evidence; and launched an internal review of the cybersecurity incident. No public disclosure of specific control changes (e.g., callback-verification policy, dual-authorization thresholds, or verified-contact registries for DTC/transfer-agent wires) has been made in the filings reviewed.
The generalizable defense this case illustrates: any change to wire instructions for a financial intermediary (DTC, a bank, a transfer agent), however official the sender name looks, must be verified through an independent, previously-established channel (a phone call to a known number, not one in the email) before funds move, and dual sign-off/maker-checker controls should apply to all dividend and large outbound wire payments regardless of counterparty prestige.
Social Engineering Examples. “JE Cleantech Holdings Dividend-Payment BEC via Fake DTC Impersonation (2026)”. Accessed 19 September 2026. https://socialengineeringexamples.com/je-cleantech-dtc-dividend-bec-2026
A dividend payment routed through a well-known, regulated intermediary like DTC is typically visible or inferable from public dividend-declaration disclosures (JCSE's own January 5, 2026 press release named the record date and expected payment date), letting an attacker plan the timing of a fraudulent instruction to arrive during a live, real payment window rather than cold.
Public dividend-declaration filings are a legal disclosure requirement and cannot practically be hidden, so the realistic control is not suppressing this information but tightening verification on the payment-execution steps (Stages 3 and 5) that an attacker would exploit once they know the payment window.
Impersonating a specific, real financial-market utility like DTC typically requires the attacker to stand up supporting infrastructure consistent with that persona, such as a look-alike sending domain or spoofed display name and a document or email format designed to resemble genuine DTC correspondence, though the specific mechanics were not disclosed in JCSE's filings.
Look-alike domains and spoofed sender identities are hard to block universally at the inbound-email layer; DMARC/DKIM/SPF enforcement and brand-impersonation email filtering reduce but do not eliminate this risk, making out-of-band verification of any new instruction (Stage 5) the more reliable backstop.
A fraudulent email purporting to be from DTC, containing false wire-transfer instructions, was delivered to JCSE or an entity with visibility into the dividend payment process, timed to coincide with the real, scheduled dividend payment.
Email-security controls such as external-sender banners, attachment/link sandboxing, and impersonation-detection filters tuned to flag messages purporting to be from known financial-market utilities can catch some fraudulent DTC-branded email before it reaches a decision-maker.
Rather than a novel or suspicious request, the email was consistent with an expected step in a routine, already-underway payment workflow, lowering scrutiny because DTC was already the legitimate counterparty for this exact transaction.
Staff handling payment instructions should be trained that a request arriving through the expected, familiar channel is not itself evidence of legitimacy, and that live/urgent payment context is precisely when fraud is most often timed to land.
JCSE (or its bank acting on JCSE's instruction) accepted the fraudulent wire details as genuine and sent USD 794,934.04 to the attacker-controlled account instead of DTC's real account.
Any change to or first receipt of wire instructions for a financial intermediary should be verified through an independent, previously-established channel, such as a phone call to a known number, not one contained in the email, before funds move; dual sign-off/maker-checker approval should be mandatory for dividend and other large outbound wires regardless of counterparty prestige.
The fraudulent account received the funds while DTC never did, delaying the dividend to street-name shareholders; JCSE discovered the fraud on February 7, 2026, after which it reported the incident to law enforcement and disclosed it via SEC Form 6-K.
Rapid post-incident actions, such as JCSE's reporting to the FBI's IC3, Singapore Police Force, and both sending and receiving banks within days of discovery, improve the odds of fund recovery or account freezing and support law-enforcement action, even though no recovery of the stolen funds was disclosed in this case.
Browse by what this case has in common with others in the library.
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438.
A small Columbus, Ohio manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an imposter scam…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
A Singaporean finance professional in her 50s lost S$1.2 million.
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
Advance Machine Company's West Coast sales manager repeatedly rifled Tennant Company's sealed, covered dumpster in California to steal sales leads.
Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.
A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to…
A Singaporean finance professional in her 50s lost S$1.2 million.
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…