Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition.
Social Engineering Examples·5 sources
In March 2018, criminals impersonating Marc Lacan, CEO of French parent Pathé, emailed the two-person senior management of Pathé's Dutch subsidiary (managing director Dertje Meijer and CFO Edwin Slutter). Using an address the scammers presented as Lacan's "personal" email, they claimed Pathé was carrying out a strictly confidential acquisition of a company in Dubai and needed urgent payments that would be reimbursed at month's end.
Believing they were serving a secret, board-sanctioned deal, the executives authorized a series of wire transfers to an account in the name of Towering Stars General Trading LLC in Dubai, starting at €826,521 on March 9 and escalating through payments of roughly €2.48M, €5M, €5.83M and €5.15M, totaling €19,244,304 by March 27. When the Dutch unit ran short, it drew on the French group's central "cash pool." The fraud was exposed on March 28 when the real Paris headquarters queried the cash-pool withdrawals.
Both executives were suspended, then dismissed in April. The details became public through an Amsterdam District Court ruling of October 31, 2018 in Slutter's wrongful-dismissal suit; an internal probe found no employee was knowingly involved in the fraud. This is a real, court-documented incident.
A classic CEO-fraud/BEC pattern with a twist: instead of a fake CEO pressuring a subordinate CFO, the attackers impersonated the French parent's top leadership to instruct an entire overseas subsidiary's management. Opening emails asked innocuous questions (whether KPMG had been in touch) to build a plausible business context before introducing the money request.
They leaned on authority (instructions ostensibly from the group's two most senior people), manufactured secrecy ("strictest confidentiality," reply only to the personal address, to keep a competitive edge and avoid disclosure), and legitimacy props (an invoice, a document bearing the CEO's and family shareholders' names/signatures, and claimed KPMG oversight).
Requests to phone or involve the supervisory board were deflected as against "KPMG standards," keeping victims inside a channel the attackers controlled. Amounts started small and escalated once trust was established, and the promise of repayment reframed the outflows as temporary. The subsidiary had no fraud training or verification protocol, so requests that felt "strange" were still executed.
Lure: emails from the "personal" account of the parent-company CEO announcing a secret, time-sensitive Dubai acquisition, with instructions to pay tranches to a third-party account and keep it confidential. Tells: a superior demanding payments unrelated to the local entity's business; insistence on secrecy and email-only contact while refusing phone calls or board involvement; a "personal" (non-corporate) email address; funds going to an unrelated third-party company abroad; escalating amounts; and the executives' own instincts: Meijer wrote "Strange, is it not?" and Slutter replied "Curious process.
Never experienced anything like that," instincts that were overridden rather than acted upon.
Pathé lost €19.2M. Both Dutch executives were fired in April 2018. Slutter sued for wrongful dismissal; on October 31, 2018 the Amsterdam District Court ruled his summary (on-the-spot) dismissal was not justified and ordered Pathé to pay his salary (~€13,503/month) through December 1, 2018, but still allowed the employment contract to be dissolved for culpable conduct, finding trust had irreparably broken. CEO Lacan stepped down in September 2018. No public record of fund recovery or arrests.
One of the largest publicly named CEO-fraud/BEC losses, and a rare case where the full mechanics were exposed by court proceedings rather than a company disclosure. It shows BEC can target an entire subsidiary's leadership (not just a lone clerk), that even experienced finance executives who sense something is "strange" will proceed absent hard controls, and that the human cost extends to careers and litigation.
It also underscores that the presence of red flags is meaningless without training and enforced verification procedures, since the court itself noted Pathé had never trained the CFO to detect fraud.
Enforce out-of-band verification (a known-good phone number or in-person confirmation) for any high-value or unusual wire, especially "confidential" or urgent ones, and never verify via the same email thread. Treat demands for secrecy, refusal of phone calls, and instructions to bypass the board as red flags, not proof of importance. Require dual authorization and independent finance sign-off for large or cross-entity transfers, with tighter scrutiny as amounts escalate.
Flag payments to newly introduced third-party or foreign accounts and confirm beneficiaries through trusted channels. Distinguish "personal" email addresses from verified corporate ones. Provide recurring BEC/CEO-fraud awareness training so staff can name the pattern and are empowered to pause payments.
Social Engineering Examples. “Pathé €19.2M fake-CEO cinema-chain fraud (2018)”. Accessed 19 September 2026. https://socialengineeringexamples.com/pathe-fake-ceo-bec-2018
attackers likely mapped Pathe's corporate structure before contact, learning that the Dutch subsidiary reported to a French parent, identifying the parent CEO by name (Marc Lacan) and confirming that the Dutch unit's senior management was just two people (a managing director and a CFO), consistent with research through public corporate filings, press coverage, and professional-networking profiles.
corporate-structure and executive-name exposure (who reports to whom, who the group CEO is) is very hard to eliminate since it lives in public filings and press coverage; the realistic control assumes attackers already have this and hardens the verification process it later gets used against, rather than trying to hide it.
before the first email, the group needed a look-alike or freemail address that could plausibly pass as the CEO's undisclosed personal account, and had to have a beneficiary bank account already available and ready to receive funds, the account used, in the name of Towering Stars General Trading LLC in Dubai, and typical of the shell-company accounts organized fraud rings use to receive and quickly move stolen wires.
email-authentication controls (SPF/DKIM/DMARC) and mail-flow rules that flag messages claiming to be from a senior executive but arriving from an unrecognized external or personal address, combined with beneficiary and sanctions screening on any newly introduced foreign payee, catch this stage before money moves.
the first email asked an innocuous, plausible-sounding question (whether KPMG had been in touch) rather than requesting money outright, a low-risk opener that established a reply thread and a sense of ongoing business context before the financial ask appeared.
train staff to treat any unexpected message from a senior executive's unfamiliar personal address as needing verification from the first contact, not just once a money request appears, since low-stakes opening questions are a documented way attackers establish false legitimacy.
once engaged, the attackers invoked the authority of the group's two most senior figures, framed the request as a strictly confidential Dubai acquisition that had to stay off the phone and off the board's radar to preserve a competitive advantage, and backed it with props, a signed invoice and claimed KPMG oversight, that made the story feel procedurally legitimate.
treat demands for secrecy, refusal of phone calls, and instructions to bypass the board as red flags requiring escalation, not signals of importance; legitimate corporate finance approvals do not forbid independent verification.
payments began small (10% of the claimed deal) and escalated over several tranches, with promises of prompt repayment reframing each outflow as temporary, and when the subsidiary's own cash ran low the attackers directed staff to draw on the French parent's internal cash pool, a legitimate treasury mechanism that let the fraud draw on funds well beyond the local entity's own balance.
require dual authorization and independent finance sign-off for large, urgent, or cross-entity transfers, including cash-pool draws, with mandatory pause-and-verify checkpoints that get stricter as amounts escalate, closing off the mechanism the fraud relied on to fund itself beyond the subsidiary's own cash.
the final tranches were authorized and wired to the Dubai beneficiary account while the CFO was on vacation and scrutiny was lowest, completing the payout; the scheme ended only when Paris headquarters independently queried the cash-pool withdrawals, by which point the funds had already left and no public recovery has been reported.
out-of-band verification (a known-good phone number or in-person confirmation, never the same email thread) before any high-value wire goes out, plus rapid reconciliation between subsidiary and parent treasury so unexplained cash-pool activity is flagged immediately rather than discovered after the fact, is the last practical control before funds leave for good.
Browse by what this case has in common with others in the library.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…
Hackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack.
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona…
After going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP…
A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad.
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.