A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
Social Engineering Examples·4 sources
On August 10, 2024, Orion S.A. determined that one of its employees, explicitly noted as not a Named Executive Officer, had been the target of a criminal scheme that induced them to send multiple outbound wire transfers to accounts controlled by unknown third parties. Orion disclosed the incident in a Form 8-K filed with the SEC on August 12, 2024, and expected a one-time pre-tax charge of roughly $60 million if the funds were not recovered.
The company found no evidence of unauthorized access to its data or systems and said business operations were unaffected. In its Q3 2024 earnings release (November 7, 2024), Orion reported the loss plus related professional fees aggregated to $60.7 million, stated the independent investigation was complete, and said remediation measures had been implemented.
This is a real, SEC-documented incident. The specific mechanism (BEC via impersonation of a supplier, customer, or executive) was characterized as the likely method by outside security experts and press; Orion itself declined to detail the method beyond the filing, so the exact impersonation vector is inferred, not company-confirmed.
The loss was driven by social engineering of a single human decision-maker in the payments process rather than any technical intrusion. In fraudulently induced wire transfer / BEC schemes of this shape, criminals impersonate a trusted party such as a senior executive, a known vendor, or a customer, and use plausible, authoritative, time-pressured requests to convince an employee that a large money movement is legitimate.
Because the employee, not an attacker, actually authorized and executed the wires, existing perimeter and system controls were never triggered, which is consistent with Orion finding no unauthorized data or system access. The recurrence across multiple transfers points to a sustained, convincing pretext that maintained the target's belief the payments were routine and authorized.
Lure: an urgent, authoritative-sounding payment request from what appeared to be a trusted executive, vendor, or customer, convincing enough to be repeated across multiple wires. Tells: pressure to move unusually large sums quickly, changed or unfamiliar beneficiary bank details, requests routed to a single employee outside normal dual-approval workflows, and reluctance to verify through a known, independent channel.
The absence of any system breach is itself a tell that the attack targeted human judgment, not technology.
Multiple wires totaling about $60 million left the company to attacker-controlled accounts. Orion recorded the loss (net $42.5M after tax benefit) driving a Q3 2024 net loss, said it was cooperating with law enforcement, and stated it would pursue recovery through all legal means including potentially available insurance. As of the Q3 earnings release the independent investigation was complete and remediation had been implemented. No public disclosure of arrests, full recovery, or attribution.
A single employee's payment authorization cost a $1.9B-revenue public company roughly a third of its annual profit, with no malware, no breached systems, and no stolen data. It shows that fraudulently induced wire transfers bypass technical defenses entirely by exploiting trust and authority, that any employee with payment authority is a high-value target (not just executives), and that the loss materially affected reported earnings and required SEC disclosure.
It underscores why out-of-band verification and strict payment controls matter more than perimeter security for this threat class.
Enforce out-of-band verification (call a known, pre-verified number, never contact details in the request) for any new or changed payee and for large or urgent transfers. Require dual authorization and segregation of duties so no single employee can complete a high-value wire. Lock and independently confirm any change to vendor bank account details. Set transfer thresholds that trigger escalation.
Train payment and finance staff specifically on executive/vendor impersonation and urgency pressure, and empower them to pause and verify without fear of reprisal. Maintain crime/social-engineering fraud insurance and rehearse rapid law-enforcement and bank recall procedures to maximize recovery windows.
Social Engineering Examples. “Orion S.A. $60M fraudulently induced wire transfers (2024)”. Accessed 19 September 2026. https://socialengineeringexamples.com/orion-sa-60m-bec-wire-fraud-2024
BEC operators targeting a public, SEC-reporting industrial company like Orion typically research the target's org chart, finance-team staff, and vendor or customer relationships using corporate websites, LinkedIn, press releases, and public filings, in order to identify a non-executive employee with wire-payment authority and to learn the names and communication style of the executives or vendors they could impersonate.
Employee names, roles, and org structure are typically public by design, through investor relations pages, LinkedIn, and press coverage. This exposure is very hard to eliminate at enterprise scale, so the realistic control is hardening the payment process downstream, so that knowing who holds a finance role is not enough on its own to move money.
Consistent with typical BEC tradecraft, attackers likely registered look-alike domains or used spoofed or compromised email accounts resembling a trusted executive, vendor, or customer, and may have drawn on prior legitimate business correspondence, such as a compromised mailbox or an intercepted invoice, to make the impersonation and payment details more convincing.
Email-authentication controls (SPF, DKIM, DMARC), monitoring for newly registered look-alike domains, and mailbox-compromise detection reduce the odds that a spoofed or look-alike sender ever reaches the target's inbox with a credible from-address.
The attacker or attackers contacted the targeted non-executive finance employee posing as a senior executive, known vendor, or customer, using the urgent, authoritative tone consistent with classic BEC social engineering (per Proofpoint researcher Selena Larson's characterization of this case) to request a large, time-sensitive wire transfer.
Security-awareness training focused specifically on executive and vendor impersonation and urgency pressure, combined with visual flagging of external senders, helps employees recognize and pause on an unsolicited urgent payment request before acting on it.
Because the fraud involved multiple outbound wires rather than a single payment, the attacker or attackers likely maintained the pretext across repeated exchanges, reinforcing urgency and authority each time so the employee kept believing the payments were legitimate and routine, and avoiding anything that would trigger manual review.
Fixed escalation thresholds and mandatory review for any recurring or unusually large wire request, regardless of how routine it is made to feel, catch the sustained-pretext pattern that a one-time check would miss.
The employee personally authorized and executed the wires, meaning the scheme exploited a gap in, or absence of, dual-authorization, segregation-of-duties, and independent payee-verification controls, letting one individual's decision move company funds with no technical intrusion ever occurring.
Dual authorization and segregation of duties for high-value wires, combined with out-of-band verification through a pre-verified phone number (never contact details supplied in the request itself) for any new or changed payee, directly closes the gap this incident exploited, since no single employee could then complete the transfer alone.
Wired funds landed in accounts controlled by unknown third parties. Consistent with typical BEC money-mule patterns, proceeds in schemes like this are usually moved quickly through intermediary or exchange accounts to frustrate bank recall and law-enforcement freeze requests before the victim organization discovers the fraud, completing the attacker's financial objective; Orion has not disclosed recovery, arrests, or attribution.
Once funds leave, recovery depends on speed. Rehearsed rapid bank-recall and law-enforcement notification procedures (for example, filing promptly with the FBI's IC3 for US incidents) and dedicated crime or social-engineering fraud insurance maximize the narrow window before proceeds are dispersed, which is the last realistic point of leverage after a wire has already been sent.
Browse by what this case has in common with others in the library.
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
Impersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters.
Scammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO.
DOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used…
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…