Case Library / Phishing / Pathé €19.2M fake-CEO cinema-chain fraud (2018)
Phishing Confirmed

Pathé €19.2M fake-CEO cinema-chain fraud (2018)

Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition, costing two executives their jobs.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In March 2018, criminals impersonating Marc Lacan, CEO of French parent Pathé, emailed the two-person senior management of Pathé's Dutch subsidiary (managing director Dertje Meijer and CFO Edwin Slutter). Using an address the scammers presented as Lacan's "personal" email, they claimed Pathé was carrying out a strictly confidential acquisition of a company in Dubai and needed urgent payments that would be reimbursed at month's end. Believing they were serving a secret, board-sanctioned deal, the executives authorized a series of wire transfers to an account in the name of Towering Stars General Trading LLC in Dubai, starting at €826,521 on March 9 and escalating through payments of roughly €2.48M, €5M, €5.83M and €5.15M, totaling €19,244,304 by March 27. When the Dutch unit ran short, it drew on the French group's central "cash pool." The fraud was exposed on March 28 when the real Paris headquarters queried the cash-pool withdrawals. Both executives were suspended, then dismissed in April. The details became public through an Amsterdam District Court ruling of October 31, 2018 in Slutter's wrongful-dismissal suit; an internal probe found no employee was knowingly involved in the fraud. This is a real, court-documented incident.

How the Attack Worked

A classic CEO-fraud/BEC pattern with a twist: instead of a fake CEO pressuring a subordinate CFO, the attackers impersonated the French parent's top leadership to instruct an entire overseas subsidiary's management. Opening emails asked innocuous questions (whether KPMG had been in touch) to build a plausible business context before introducing the money request. They leaned on authority (instructions ostensibly from the group's two most senior people), manufactured secrecy ("strictest confidentiality," reply only to the personal address, to keep a competitive edge and avoid disclosure), and legitimacy props (an invoice, a document bearing the CEO's and family shareholders' names/signatures, and claimed KPMG oversight). Requests to phone or involve the supervisory board were deflected as against "KPMG standards," keeping victims inside a channel the attackers controlled. Amounts started small and escalated once trust was established, and the promise of repayment reframed the outflows as temporary. The subsidiary had no fraud training or verification protocol, so requests that felt "strange" were still executed.

The Lure & the Tell

Lure: emails from the "personal" account of the parent-company CEO announcing a secret, time-sensitive Dubai acquisition, with instructions to pay tranches to a third-party account and keep it confidential. Tells: a superior demanding payments unrelated to the local entity's business; insistence on secrecy and email-only contact while refusing phone calls or board involvement; a "personal" (non-corporate) email address; funds going to an unrelated third-party company abroad; escalating amounts; and the executives' own instincts: Meijer wrote "Strange, is it not?" and Slutter replied "Curious process. Never experienced anything like that," instincts that were overridden rather than acted upon.

Outcome

Pathé lost €19.2M. Both Dutch executives were fired in April 2018. Slutter sued for wrongful dismissal; on October 31, 2018 the Amsterdam District Court ruled his summary (on-the-spot) dismissal was not justified and ordered Pathé to pay his salary (~€13,503/month) through December 1, 2018, but still allowed the employment contract to be dissolved for culpable conduct, finding trust had irreparably broken. CEO Lacan stepped down in September 2018. No public record of fund recovery or arrests.

Why It Matters

One of the largest publicly named CEO-fraud/BEC losses, and a rare case where the full mechanics were exposed by court proceedings rather than a company disclosure. It shows BEC can target an entire subsidiary's leadership (not just a lone clerk), that even experienced finance executives who sense something is "strange" will proceed absent hard controls, and that the human cost extends to careers and litigation. It also underscores that the presence of red flags is meaningless without training and enforced verification procedures, since the court itself noted Pathé had never trained the CFO to detect fraud.

Defenses

Enforce out-of-band verification (a known-good phone number or in-person confirmation) for any high-value or unusual wire, especially "confidential" or urgent ones, and never verify via the same email thread. Treat demands for secrecy, refusal of phone calls, and instructions to bypass the board as red flags, not proof of importance. Require dual authorization and independent finance sign-off for large or cross-entity transfers, with tighter scrutiny as amounts escalate. Flag payments to newly introduced third-party or foreign accounts and confirm beneficiaries through trusted channels. Distinguish "personal" email addresses from verified corporate ones. Provide recurring BEC/CEO-fraud awareness training so staff can name the pattern and are empowered to pause payments.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: attackers likely mapped Pathe's corporate structure before contact, learning that the Dutch subsidiary reported to a French parent, identifying the parent CEO by name (Marc Lacan) and confirming that the Dutch unit's senior management was just two people (a managing director and a CFO), consistent with research through public corporate filings, press coverage, and professional-networking profiles.
Countering Stage 1: corporate-structure and executive-name exposure (who reports to whom, who the group CEO is) is very hard to eliminate since it lives in public filings and press coverage; the realistic control assumes attackers already have this and hardens the verification process it later gets used against, rather than trying to hide it.
2
Infrastructure setup: before the first email, the group needed a look-alike or freemail address that could plausibly pass as the CEO's undisclosed personal account, and had to have a beneficiary bank account already available and ready to receive funds, the account used, in the name of Towering Stars General Trading LLC in Dubai, and typical of the shell-company accounts organized fraud rings use to receive and quickly move stolen wires.
Countering Stage 2: email-authentication controls (SPF/DKIM/DMARC) and mail-flow rules that flag messages claiming to be from a senior executive but arriving from an unrecognized external or personal address, combined with beneficiary and sanctions screening on any newly introduced foreign payee, catch this stage before money moves.
3
Pretext opening: the first email asked an innocuous, plausible-sounding question (whether KPMG had been in touch) rather than requesting money outright, a low-risk opener that established a reply thread and a sense of ongoing business context before the financial ask appeared.
Countering Stage 3: train staff to treat any unexpected message from a senior executive's unfamiliar personal address as needing verification from the first contact, not just once a money request appears, since low-stakes opening questions are a documented way attackers establish false legitimacy.
4
Authority, secrecy, and legitimacy props: once engaged, the attackers invoked the authority of the group's two most senior figures, framed the request as a strictly confidential Dubai acquisition that had to stay off the phone and off the board's radar to preserve a competitive advantage, and backed it with props, a signed invoice and claimed KPMG oversight, that made the story feel procedurally legitimate.
Countering Stage 4: treat demands for secrecy, refusal of phone calls, and instructions to bypass the board as red flags requiring escalation, not signals of importance; legitimate corporate finance approvals do not forbid independent verification.
5
Escalating payment requests and internal channel exploitation: payments began small (10% of the claimed deal) and escalated over several tranches, with promises of prompt repayment reframing each outflow as temporary, and when the subsidiary's own cash ran low the attackers directed staff to draw on the French parent's internal cash pool, a legitimate treasury mechanism that let the fraud draw on funds well beyond the local entity's own balance.
Countering Stage 5: require dual authorization and independent finance sign-off for large, urgent, or cross-entity transfers, including cash-pool draws, with mandatory pause-and-verify checkpoints that get stricter as amounts escalate, closing off the mechanism the fraud relied on to fund itself beyond the subsidiary's own cash.
6
Fund extraction and exit: the final tranches were authorized and wired to the Dubai beneficiary account while the CFO was on vacation and scrutiny was lowest, completing the payout; the scheme ended only when Paris headquarters independently queried the cash-pool withdrawals, by which point the funds had already left and no public recovery has been reported.
Countering Stage 6: out-of-band verification (a known-good phone number or in-person confirmation, never the same email thread) before any high-value wire goes out, plus rapid reconciliation between subsidiary and parent treasury so unexplained cash-pool activity is flagged immediately rather than discovered after the fact, is the last practical control before funds leave for good.
Quick Facts
Victim
Pathé Theatres B.V. (Pathé Nederland), the Dutch subsidiary of French film group Pathé; ~1,900 employees, €209M 2017 revenue. Two executives, managing director/CEO Dertje Meijer and financial director/CFO Edwin Slutter, were suspended and fired.
Location
Netherlands (Amsterdam); parent company France; funds routed to Dubai, UAE
Date
2018-03 (fraud executed March 8-27, 2018; disclosed via Amsterdam District Court ruling dated 2018-10-31, reported November 2018)
Impact
€19,244,304 transferred in four-plus tranches (approx. US$21.5M), roughly 10% of the Dutch unit's annual revenue. No public confirmation any funds were recovered.
Status
Confirmed
Case Type
Real-World Incident
Sector
Media & Entertainment
Threat Actor
Organized Crime
Related

Related Cases

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…

Incident 2018Read →

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…

Incident 2018Read →

Toyota Boshoku European Subsidiary $37M BEC (2019)

A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…

Incident 2019Read →