Fraudsters impersonating Leoni AG executives tricked its Romanian subsidiary into wiring roughly EUR 40 million ($44.6M) to attackers.
Social Engineering Examples·10 sources
On Friday, 12 August 2016, Leoni AG, a German MDAX-listed manufacturer of cables and wiring systems for the automotive and other industries, discovered it had been defrauded of approximately EUR 40 million. Attackers had impersonated senior Leoni executives using spoofed email identities and falsified documents/communications, directing the finance/accounting department of Leoni's Romanian subsidiary operation in Bistrița, the only one of Leoni's four Romanian plants authorized to make international wire transfers, to wire the funds to accounts the attackers controlled.
Leoni publicly disclosed the fraud in a German ad hoc (inside-information) announcement on 16 August 2016, stating its IT infrastructure and data security had not been compromised, that it had filed a police report, and that it was assessing insurance claims and the impact on results. A follow-up ad hoc disclosure on 14 September 2016 confirmed the roughly EUR 40 million loss would be fully absorbed in Q3/FY2016 earnings, cutting Leoni's FY2016 EBIT guidance from EUR 105 million to EUR 65 million.
Attackers impersonated senior Leoni AG executives (headquartered in Nuremberg, Germany) via spoofed or cloned email accounts/identities and falsified documents, sending instructions that appeared to originate from company leadership to the finance/accounting department of Leoni's Romanian subsidiary operation in Bistrița, the only one of Leoni's four Romanian plants authorized to execute international wire transfers, which is reportedly why attackers targeted it specifically.
Romanian press reporting names the head of that finance department as Carmen Marica, who was dismissed following the fraud. The local finance staff, believing the instructions were genuine, urgent, and confidential executive directives, authorized and executed wire transfers totaling approximately EUR 40 million (see Financial impact for the more precise prosecutorial figure) to accounts controlled by the attackers.
Most contemporaneous reporting says the money was routed to an account at a Czech-registered company, though one later, anonymously-sourced 2017 Romanian account instead names a China-based destination account; the funds' ultimate onward destination was never publicly confirmed. Leoni stated publicly that its IT systems and data security were not breached, framing this as pure social engineering of people and process rather than a network intrusion, so that the fraud succeeded entirely through impersonation and exploitation of the subsidiary's payment-authorization workflow rather than any technical compromise.
A minority, anonymously-sourced account (Evenimentul Zilei, citing DIICOT-Cluj judicial sources) directly disputes this: it claims attackers first breached Leoni's internal servers to study its payment-approval protocol, then compromised the actual email account of a Leoni Germany director, and that when Carmen Marica sought to confirm the transfer by replying to that same address, per company protocol, the attacker who controlled it simply reconfirmed the request.
This breach account is not corroborated by Leoni's own disclosures, by any other outlet, or by the DGAP-Adhoc filings; see Defenses for how the two conflicting accounts are weighed.
The lure was authority impersonation: emails crafted to look like they came from genuine senior Leoni AG executives in Germany, instructing the Romanian subsidiary's finance staff to execute an urgent, high-value wire transfer. The classic tells present in this style of attack, reconstructed from the reporting since Leoni never published the exact email text, are hallmarks of CEO fraud: urgency and confidentiality framing that discourages the recipient from verifying through normal channels, a request crafted to mimic Leoni's actual internal wire-approval habits closely enough to pass a casual check (per Softpedia, the email was crafted to take Leoni's internal approval procedures into account), targeting of a remote subsidiary finance team less likely to have direct personal relationships with headquarters executives to sanity-check an unusual request, and reliance on the recipient's assumption that a message "from the CEO" carries binding authority without independent out-of-band callback verification.
Per the minority, uncorroborated Evenimentul Zilei account, even the one verification step the finance director did take, replying to ask the German director to confirm, was defeated because the reply went back to the same compromised or attacker-controlled address.
Leoni AG publicly confirmed the approximately EUR 40 million loss via a German ad hoc (Wertpapierhandelsgesetz/MAR Article 17) disclosure on 16 August 2016, and confirmed on 14 September 2016 that the loss would fully weigh on Q3 and full-year 2016 EBIT, cutting its FY2016 EBIT forecast from EUR 105 million to EUR 65 million. Leoni stated its IT infrastructure and data security were unaffected, filed a police report, and referred the case to Romanian prosecutors (escalated to DIICOT, Romania's organized-crime/terrorism directorate, given the sum involved).
By late 2017, Romanian judicial-source reporting indicated investigators had run out of solid leads and the perpetrators remained unidentified; no arrests or criminal indictments of the fraudsters were found in public reporting. Leoni recovered approximately EUR 5 million from insurers (reported March 2017), leaving the bulk of the loss unrecovered.
Separately, Leoni pursued civil litigation against the former Bistrița subsidiary general director, Marius Cotor (dismissed by Leoni in January/February 2017), and against the former head of the local finance department, Carmen Marica, over internal-control failures. In October 2021 the Cluj Specialized Tribunal ordered Cotor to pay Leoni approximately EUR 33.6 million in damages (roughly 80% of the loss), a first-instance ruling both sides could appeal.
By November 2023, per Romanian press (Gazeta de Bistrița), the Cluj Court of Appeal had upheld that damages ruling (while separately ordering Leoni to refund Cotor's court filing fee), with at least one related Leoni-vs-Cotor suit still pending and a further hearing set for 2024. Per a June 2024 Gazeta de Bistrița report, Leoni subsequently withdrew both of its remaining civil suits against Cotor, closing out the litigation on top of the EUR 33.6 million already awarded.
This civil litigation over internal-control accountability at the local subsidiary is distinct from the criminal fraud investigation, which as of the last reporting found had not identified or charged the actual perpetrators.
This is one of the largest publicly confirmed CEO-fraud/BEC losses on record and a textbook case for the "fake-executive wire fraud" variant of whaling: per Leoni's own official account, no network was breached, no malware was used, and no credentials were stolen (though one uncorroborated Romanian minority account disputes this). A determined attacker succeeded largely by impersonating authority and exploiting the payment-authorization gap at a remote subsidiary finance function, extracting a sum large enough to force a public earnings-guidance cut at a MDAX-listed company.
It demonstrates that BEC/CEO-fraud risk scales with organizational complexity (multinational subsidiaries, cross-border finance operations) and that technical security posture can be irrelevant if human verification processes for high-value wire instructions can be bypassed by a sufficiently convincing impersonation.
Leoni's own remediation framing (per its ad hoc disclosures) centered on: (1) confirming IT infrastructure and data security were NOT compromised, framing this as a pure social-engineering/process failure rather than a hack, meaning technical controls could not have caught it; (2) launching an internal investigation and reporting to police/prosecutors same day; (3) assessing insurance claims (later recovering roughly EUR 5 million from insurers, reported March 2017).
Note: one Romanian outlet (Evenimentul Zilei, September 2016, citing anonymous DIICOT-Cluj judicial sources) published a conflicting minority account claiming attackers first breached Leoni's internal servers and cracked/took over the German general director's actual email account before requesting the transfer, meaning a real intrusion rather than pure impersonation.
This directly contradicts Leoni's official "IT infrastructure and data security were not affected" statement. It was not corroborated by any other outlet, by Leoni's own disclosures, or by the DGAP-Adhoc filings, so this record follows Leoni's official framing as the more authoritative, better-corroborated account, while flagging the minority claim here.
The incident is widely cited in industry training as the canonical argument for: mandatory dual-authorization / four-eyes callback verification on any wire transfer above a threshold, using a pre-agreed out-of-band channel (phone to a known number, not one in the email) to verbally confirm any executive-originated payment instruction, extra scrutiny on last-minute urgent/confidential transfer requests that bypass normal approval chains, and centralizing or capping the authority of remote subsidiary finance staff to move large sums without independent sign-off from headquarters treasury.
Leoni's subsequent civil damages litigation against the former general director of the Bistrița subsidiary (and separately against the former head of the local finance department) underscores that internal control/oversight gaps at the local finance function were treated as a contributing failure alongside the external fraud.
Social Engineering Examples. “Leoni AG CEO Fraud (2016)”. Accessed 19 September 2026. https://socialengineeringexamples.com/leoni-ag-ceo-fraud-2016
Attackers likely researched Leoni AG's Nuremberg leadership team and organizational structure, consistent with public sources such as corporate press releases, MDAX regulatory filings, and professional-networking sites, to identify which executive names would carry unquestioned authority with a subsidiary finance team.
Executive names, org charts, and MDAX disclosures are public by design and cannot realistically be suppressed; the practical control is downstream, verifying any instruction that leans on that authority rather than hiding who holds it.
Per Softpedia's reporting, attackers appear to have separately learned that Leoni's Bistrița, Romania plant was the only one of its four Romanian factories authorized to execute international wire transfers, and identified Carmen Marica, the local head of finance, as the specific employee able to approve a transfer of that size.
Centralizing or capping the authority of remote subsidiary finance staff, so no single local site can move sums above a set threshold without independent headquarters treasury sign-off, would have removed Bistrița's unilateral ability to execute a transfer of this size.
Attackers built spoofed or cloned email identities and falsified supporting documents to impersonate senior Leoni Germany executives; the minority Evenimentul Zilei account instead describes this stage as compromise of an actual Leoni Germany director's real email account after a server breach, rather than a look-alike identity.
Email-authentication controls such as SPF, DKIM, and DMARC, plus monitoring for newly registered look-alike domains, reduce the odds a spoofed identity reaches a finance inbox convincingly; they would not have helped against the minority account's alleged real account compromise, which instead argues for strong executive-account credential hygiene and multi-factor authentication.
An email appearing to come from Leoni AG leadership in Germany instructed Carmen Marica to execute an urgent, confidential wire transfer, per Leoni's own ad hoc disclosure citing falsified documents and identities.
Train finance staff to treat any urgent, confidential, executive-originated wire instruction as inherently suspicious, since urgency and secrecy framing that discourages normal review is itself close to a canonical business email compromise signature.
Per the minority Evenimentul Zilei account, when Carmen Marica sought to confirm the instruction by replying, as internal protocol required, the reply reached the same compromised or attacker-controlled address, which reconfirmed the transfer and defeated the one internal check available to her.
This is the single highest-leverage control gap in the case. Mandatory out-of-band verification through a pre-agreed phone number, never a number or address supplied in the suspect email itself, would have caught that the confirmation was going back to the attacker rather than to the real German director.
Believing the instructions genuine, Carmen Marica authorized and executed wire transfers of approximately EUR 37 to 40 million from the Bistrița subsidiary's accounts to attacker-designated accounts abroad, reportedly a Czech-registered company per Gazeta de Cluj's account, with one later Romanian report instead naming a China-based destination.
Mandatory dual-authorization or four-eyes sign-off on any wire transfer above a defined threshold ensures no single employee, however senior locally, can complete a transfer of this size alone.
Attackers moved the stolen funds onward from the initial receiving account before Leoni or investigators could freeze them, consistent with typical business email compromise money-mule layering; only about EUR 5 million was ever recovered, via insurance rather than asset seizure, and the perpetrators were never publicly identified.
Once funds leave to a foreign account, recovery depends on how quickly banks and law enforcement can freeze the receiving accounts, largely outside the victim's own control; the realistic defense sits upstream, at Stages 5 and 6, rather than at recovery after the transfer clears.
Browse by what this case has in common with others in the library.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer.
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer.
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
Advance Machine Company's West Coast sales manager repeatedly rifled Tennant Company's sealed, covered dumpster in California to steal sales leads.
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…