Case Library / Phishing / Leoni AG CEO Fraud (2016)

Leoni AG CEO Fraud (2016)

Fraudsters impersonating Leoni AG's senior executives tricked the German cable manufacturer's Romanian subsidiary finance team into wiring roughly EUR 40 million (about US$44.6 million) to attacker-controlled accounts in August 2016.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On Friday, 12 August 2016, Leoni AG, a German MDAX-listed manufacturer of cables and wiring systems for the automotive and other industries, discovered it had been defrauded of approximately EUR 40 million. Attackers had impersonated senior Leoni executives using spoofed email identities and falsified documents/communications, directing the finance/accounting department of Leoni's Romanian subsidiary operation in Bistrița, the only one of Leoni's four Romanian plants authorized to make international wire transfers, to wire the funds to accounts the attackers controlled. Leoni publicly disclosed the fraud in a German ad hoc (inside-information) announcement on 16 August 2016, stating its IT infrastructure and data security had not been compromised, that it had filed a police report, and that it was assessing insurance claims and the impact on results. A follow-up ad hoc disclosure on 14 September 2016 confirmed the roughly EUR 40 million loss would be fully absorbed in Q3/FY2016 earnings, cutting Leoni's FY2016 EBIT guidance from EUR 105 million to EUR 65 million.

How the Attack Worked

Attackers impersonated senior Leoni AG executives (headquartered in Nuremberg, Germany) via spoofed or cloned email accounts/identities and falsified documents, sending instructions that appeared to originate from company leadership to the finance/accounting department of Leoni's Romanian subsidiary operation in Bistrița, the only one of Leoni's four Romanian plants authorized to execute international wire transfers, which is reportedly why attackers targeted it specifically. Romanian press reporting names the head of that finance department as Carmen Marica, who was dismissed following the fraud. The local finance staff, believing the instructions were genuine, urgent, and confidential executive directives, authorized and executed wire transfers totaling approximately EUR 40 million (see Financial impact for the more precise prosecutorial figure) to accounts controlled by the attackers. Most contemporaneous reporting says the money was routed to an account at a Czech-registered company, though one later, anonymously-sourced 2017 Romanian account instead names a China-based destination account; the funds' ultimate onward destination was never publicly confirmed. Leoni stated publicly that its IT systems and data security were not breached, framing this as pure social engineering of people and process rather than a network intrusion, so that the fraud succeeded entirely through impersonation and exploitation of the subsidiary's payment-authorization workflow rather than any technical compromise. A minority, anonymously-sourced account (Evenimentul Zilei, citing DIICOT-Cluj judicial sources) directly disputes this: it claims attackers first breached Leoni's internal servers to study its payment-approval protocol, then compromised the actual email account of a Leoni Germany director, and that when Carmen Marica sought to confirm the transfer by replying to that same address, per company protocol, the attacker who controlled it simply reconfirmed the request. This breach account is not corroborated by Leoni's own disclosures, by any other outlet, or by the DGAP-Adhoc filings; see Defenses for how the two conflicting accounts are weighed.

The Lure & the Tell

The lure was authority impersonation: emails crafted to look like they came from genuine senior Leoni AG executives in Germany, instructing the Romanian subsidiary's finance staff to execute an urgent, high-value wire transfer. The classic tells present in this style of attack, reconstructed from the reporting since Leoni never published the exact email text, are hallmarks of CEO fraud: urgency and confidentiality framing that discourages the recipient from verifying through normal channels, a request crafted to mimic Leoni's actual internal wire-approval habits closely enough to pass a casual check (per Softpedia, the email was crafted to take Leoni's internal approval procedures into account), targeting of a remote subsidiary finance team less likely to have direct personal relationships with headquarters executives to sanity-check an unusual request, and reliance on the recipient's assumption that a message "from the CEO" carries binding authority without independent out-of-band callback verification. Per the minority, uncorroborated Evenimentul Zilei account, even the one verification step the finance director did take, replying to ask the German director to confirm, was defeated because the reply went back to the same compromised or attacker-controlled address.

Outcome

Leoni AG publicly confirmed the approximately EUR 40 million loss via a German ad hoc (Wertpapierhandelsgesetz/MAR Article 17) disclosure on 16 August 2016, and confirmed on 14 September 2016 that the loss would fully weigh on Q3 and full-year 2016 EBIT, cutting its FY2016 EBIT forecast from EUR 105 million to EUR 65 million. Leoni stated its IT infrastructure and data security were unaffected, filed a police report, and referred the case to Romanian prosecutors (escalated to DIICOT, Romania's organized-crime/terrorism directorate, given the sum involved). By late 2017, Romanian judicial-source reporting indicated investigators had run out of solid leads and the perpetrators remained unidentified; no arrests or criminal indictments of the fraudsters were found in public reporting. Leoni recovered approximately EUR 5 million from insurers (reported March 2017), leaving the bulk of the loss unrecovered. Separately, Leoni pursued civil litigation against the former Bistrița subsidiary general director, Marius Cotor (dismissed by Leoni in January/February 2017), and against the former head of the local finance department, Carmen Marica, over internal-control failures. In October 2021 the Cluj Specialized Tribunal ordered Cotor to pay Leoni approximately EUR 33.6 million in damages (roughly 80% of the loss), a first-instance ruling both sides could appeal. By November 2023, per Romanian press (Gazeta de Bistrița), the Cluj Court of Appeal had upheld that damages ruling (while separately ordering Leoni to refund Cotor's court filing fee), with at least one related Leoni-vs-Cotor suit still pending and a further hearing set for 2024. Per a June 2024 Gazeta de Bistrița report, Leoni subsequently withdrew both of its remaining civil suits against Cotor, closing out the litigation on top of the EUR 33.6 million already awarded. This civil litigation over internal-control accountability at the local subsidiary is distinct from the criminal fraud investigation, which as of the last reporting found had not identified or charged the actual perpetrators.

Why It Matters

This is one of the largest publicly confirmed CEO-fraud/BEC losses on record and a textbook case for the "fake-executive wire fraud" variant of whaling: per Leoni's own official account, no network was breached, no malware was used, and no credentials were stolen (though one uncorroborated Romanian minority account disputes this). A determined attacker succeeded largely by impersonating authority and exploiting the payment-authorization gap at a remote subsidiary finance function, extracting a sum large enough to force a public earnings-guidance cut at a MDAX-listed company. It demonstrates that BEC/CEO-fraud risk scales with organizational complexity (multinational subsidiaries, cross-border finance operations) and that technical security posture can be irrelevant if human verification processes for high-value wire instructions can be bypassed by a sufficiently convincing impersonation.

Defenses

Leoni's own remediation framing (per its ad hoc disclosures) centered on: (1) confirming IT infrastructure and data security were NOT compromised, framing this as a pure social-engineering/process failure rather than a hack, meaning technical controls could not have caught it; (2) launching an internal investigation and reporting to police/prosecutors same day; (3) assessing insurance claims (later recovering roughly EUR 5 million from insurers, reported March 2017). Note: one Romanian outlet (Evenimentul Zilei, September 2016, citing anonymous DIICOT-Cluj judicial sources) published a conflicting minority account claiming attackers first breached Leoni's internal servers and cracked/took over the German general director's actual email account before requesting the transfer, meaning a real intrusion rather than pure impersonation. This directly contradicts Leoni's official "IT infrastructure and data security were not affected" statement. It was not corroborated by any other outlet, by Leoni's own disclosures, or by the DGAP-Adhoc filings, so this record follows Leoni's official framing as the more authoritative, better-corroborated account, while flagging the minority claim here. The incident is widely cited in industry training as the canonical argument for: mandatory dual-authorization / four-eyes callback verification on any wire transfer above a threshold, using a pre-agreed out-of-band channel (phone to a known number, not one in the email) to verbally confirm any executive-originated payment instruction, extra scrutiny on last-minute urgent/confidential transfer requests that bypass normal approval chains, and centralizing or capping the authority of remote subsidiary finance staff to move large sums without independent sign-off from headquarters treasury. Leoni's subsequent civil damages litigation against the former general director of the Bistrița subsidiary (and separately against the former head of the local finance department) underscores that internal control/oversight gaps at the local finance function were treated as a contributing failure alongside the external fraud.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and executive profiling: Attackers likely researched Leoni AG's Nuremberg leadership team and organizational structure, consistent with public sources such as corporate press releases, MDAX regulatory filings, and professional-networking sites, to identify which executive names would carry unquestioned authority with a subsidiary finance team.
Countering Stage 1: Executive names, org charts, and MDAX disclosures are public by design and cannot realistically be suppressed; the practical control is downstream, verifying any instruction that leans on that authority rather than hiding who holds it.
2
Subsidiary and workflow targeting: Per Softpedia's reporting, attackers appear to have separately learned that Leoni's Bistrița, Romania plant was the only one of its four Romanian factories authorized to execute international wire transfers, and identified Carmen Marica, the local head of finance, as the specific employee able to approve a transfer of that size.
Countering Stage 2: Centralizing or capping the authority of remote subsidiary finance staff, so no single local site can move sums above a set threshold without independent headquarters treasury sign-off, would have removed Bistrița's unilateral ability to execute a transfer of this size.
3
Impersonation infrastructure setup: Attackers built spoofed or cloned email identities and falsified supporting documents to impersonate senior Leoni Germany executives; the minority Evenimentul Zilei account instead describes this stage as compromise of an actual Leoni Germany director's real email account after a server breach, rather than a look-alike identity.
Countering Stage 3: Email-authentication controls such as SPF, DKIM, and DMARC, plus monitoring for newly registered look-alike domains, reduce the odds a spoofed identity reaches a finance inbox convincingly; they would not have helped against the minority account's alleged real account compromise, which instead argues for strong executive-account credential hygiene and multi-factor authentication.
4
Initial contact and urgent pretext: An email appearing to come from Leoni AG leadership in Germany instructed Carmen Marica to execute an urgent, confidential wire transfer, per Leoni's own ad hoc disclosure citing falsified documents and identities.
Countering Stage 4: Train finance staff to treat any urgent, confidential, executive-originated wire instruction as inherently suspicious, since urgency and secrecy framing that discourages normal review is itself close to a canonical business email compromise signature.
5
Confirmation-channel interception: Per the minority Evenimentul Zilei account, when Carmen Marica sought to confirm the instruction by replying, as internal protocol required, the reply reached the same compromised or attacker-controlled address, which reconfirmed the transfer and defeated the one internal check available to her.
Countering Stage 5: This is the single highest-leverage control gap in the case. Mandatory out-of-band verification through a pre-agreed phone number, never a number or address supplied in the suspect email itself, would have caught that the confirmation was going back to the attacker rather than to the real German director.
6
Payment execution: Believing the instructions genuine, Carmen Marica authorized and executed wire transfers of approximately EUR 37 to 40 million from the Bistrița subsidiary's accounts to attacker-designated accounts abroad, reportedly a Czech-registered company per Gazeta de Cluj's account, with one later Romanian report instead naming a China-based destination.
Countering Stage 6: Mandatory dual-authorization or four-eyes sign-off on any wire transfer above a defined threshold ensures no single employee, however senior locally, can complete a transfer of this size alone.
7
Fund dispersal and objective completion: Attackers moved the stolen funds onward from the initial receiving account before Leoni or investigators could freeze them, consistent with typical business email compromise money-mule layering; only about EUR 5 million was ever recovered, via insurance rather than asset seizure, and the perpetrators were never publicly identified.
Countering Stage 7: Once funds leave to a foreign account, recovery depends on how quickly banks and law enforcement can freeze the receiving accounts, largely outside the victim's own control; the realistic defense sits upstream, at Stages 5 and 6, rather than at recovery after the transfer clears.
Quick Facts
Victim
Leoni AG (German cable and wiring-systems manufacturer, MDAX-listed, headquartered in Nuremberg), via its Romanian subsidiary's finance/accounting department in Bistrița
Location
Bistrița, Romania (targeted subsidiary's finance/accounting department); Nuremberg, Germany (Leoni AG headquarters, impersonated executives)
Date
2016-08-12 (fraud realized/discovered); 2016-08-16 (public ad hoc disclosure); 2016-09-14 (follow-up ad hoc disclosure confirming EUR 40m impact on FY2016 earnings)
Impact
Approximately EUR 40 million (~US$44.6-45.1 million at contemporaneous exchange rates) wired out and lost, per Leoni's own ad hoc disclosures. Leoni's Q3/FY2016 EBIT forecast was cut from EUR 105 million to EUR 65 million specifically to absorb this loss (per the 14 September 2016 ad hoc disclosure). Note: the criminal complaint filed with the Bistrița-Năsăud prosecutor's office reportedly cited a more precise figure of EUR 37,380,250 (~EUR 37.38 million), per Evenimentul Zilei's anonymously-sourced account of the actual transfer request, versus Leoni's own rounder public disclosure of "approximately EUR 40 million." This record uses Leoni's own ad hoc figure (~EUR 40m) as the primary, most authoritative source, but the ~37m/~40m variance across sources should be treated as a minor open discrepancy rather than a settled precise figure. Approximately EUR 5 million was later recovered from insurers (reported March 2017), leaving the large majority of the loss unrecovered as of the last public reporting found.
Status
Confirmed
Case Type
Real-World Incident
Sector
Manufacturing & Industrial
Related

Related Cases

Seagate CEO-Spoof W-2 Phishing Breach (2016)

A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…

Incident 2016Read →

Snapchat W-2 Payroll Phishing Breach (2016)

A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…

Incident 2016Read →

Ubiquiti Networks $46.7M business email compromise (2015)

Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…

Incident 2015Read →