A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M to attacker-controlled accounts, with no system or data breach involved.
Reviewed by the Social Engineering Examples team.
On August 10, 2024, Orion S.A. determined that one of its employees, explicitly noted as not a Named Executive Officer, had been the target of a criminal scheme that induced them to send multiple outbound wire transfers to accounts controlled by unknown third parties. Orion disclosed the incident in a Form 8-K filed with the SEC on August 12, 2024, and expected a one-time pre-tax charge of roughly $60 million if the funds were not recovered. The company found no evidence of unauthorized access to its data or systems and said business operations were unaffected. In its Q3 2024 earnings release (November 7, 2024), Orion reported the loss plus related professional fees aggregated to $60.7 million, stated the independent investigation was complete, and said remediation measures had been implemented. This is a real, SEC-documented incident. The specific mechanism (BEC via impersonation of a supplier, customer, or executive) was characterized as the likely method by outside security experts and press; Orion itself declined to detail the method beyond the filing, so the exact impersonation vector is inferred, not company-confirmed.
The loss was driven by social engineering of a single human decision-maker in the payments process rather than any technical intrusion. In fraudulently induced wire transfer / BEC schemes of this shape, criminals impersonate a trusted party such as a senior executive, a known vendor, or a customer, and use plausible, authoritative, time-pressured requests to convince an employee that a large money movement is legitimate. Because the employee, not an attacker, actually authorized and executed the wires, existing perimeter and system controls were never triggered, which is consistent with Orion finding no unauthorized data or system access. The recurrence across multiple transfers points to a sustained, convincing pretext that maintained the target's belief the payments were routine and authorized.
Lure: an urgent, authoritative-sounding payment request from what appeared to be a trusted executive, vendor, or customer, convincing enough to be repeated across multiple wires. Tells: pressure to move unusually large sums quickly, changed or unfamiliar beneficiary bank details, requests routed to a single employee outside normal dual-approval workflows, and reluctance to verify through a known, independent channel. The absence of any system breach is itself a tell that the attack targeted human judgment, not technology.
Multiple wires totaling about $60 million left the company to attacker-controlled accounts. Orion recorded the loss (net $42.5M after tax benefit) driving a Q3 2024 net loss, said it was cooperating with law enforcement, and stated it would pursue recovery through all legal means including potentially available insurance. As of the Q3 earnings release the independent investigation was complete and remediation had been implemented. No public disclosure of arrests, full recovery, or attribution.
A single employee's payment authorization cost a $1.9B-revenue public company roughly a third of its annual profit, with no malware, no breached systems, and no stolen data. It shows that fraudulently induced wire transfers bypass technical defenses entirely by exploiting trust and authority, that any employee with payment authority is a high-value target (not just executives), and that the loss materially affected reported earnings and required SEC disclosure. It underscores why out-of-band verification and strict payment controls matter more than perimeter security for this threat class.
Enforce out-of-band verification (call a known, pre-verified number, never contact details in the request) for any new or changed payee and for large or urgent transfers. Require dual authorization and segregation of duties so no single employee can complete a high-value wire. Lock and independently confirm any change to vendor bank account details. Set transfer thresholds that trigger escalation. Train payment and finance staff specifically on executive/vendor impersonation and urgency pressure, and empower them to pause and verify without fear of reprisal. Maintain crime/social-engineering fraud insurance and rehearse rapid law-enforcement and bank recall procedures to maximize recovery windows.
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into…
Impersonators posing as two School District of Philadelphia vendors switched payments from paper check to ACH and diverted nearly $700,000…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…