Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to Japan.
Social Engineering Examples·5 sources
Save the Children Federation, the US arm of the well-known children's charity, disclosed in its IRS Form 990 for fiscal year 2017 that it had been defrauded of nearly $1 million in a business email compromise (BEC) scheme. An unknown attacker gained access to an employee's email account, posed as that staff member, and created false invoices and supporting documents claiming the charity needed to pay for solar panels for health centers in Pakistan, a country where Save the Children has operated for over 30 years.
Believing the request was a legitimate internal transaction, the organization wired $997,400 to a fraudulent entity in Japan. By the time the fraud was discovered in May 2017, the transfer could not be recalled. The charity worked with the FBI and Japanese authorities, but no arrests were reported. Insurance reimbursed $885,784, leaving a net loss of roughly $112,000. The Form 990 also disclosed a separate, smaller vendor-impersonation incident: after a vendor's email account was hacked, the charity was given fraudulent bank details and sent $9,210 to an account in Benin, West Africa, recovering all but $120. The incident was uncovered by Boston Globe reporter Todd Wallack, who used a script to scan electronic Form 990 filings for "significant diversion of assets" disclosures.
This was an email account compromise (EAC) flavor of BEC: rather than merely spoofing an address, the attacker took control of a real employee mailbox and sent fraudulent documents from inside the organization. Requests and invoices that originate internally are commonly assumed legitimate and rarely challenged, so the fake solar-panel invoices sailed through.
The pretext was carefully chosen to match the charity's genuine, decades-long operations in Pakistan, making the payment request look routine and mission-consistent rather than suspicious. The scheme exploited a large organization that processes dozens of high-value wire transfers per year, and the lack of an out-of-band verification step (a phone call to confirm new vendors or new bank instructions) meant nothing caught the fraud before the money left.
The separate vendor incident followed the classic invoice-redirection pattern: a compromised supplier mailbox supplied new "updated" banking details that diverted a legitimate payment.
Lure: internal-looking emails from a genuine, hijacked employee account carrying false invoices and documents for a plausible, mission-aligned expense (solar panels for Pakistan health centers). Tells and safeguards that would have caught it: new or changed vendor and bank-account instructions that were never independently verified by phone, payment destination (Japan) inconsistent with the stated purpose (Pakistan project), and reliance on trust in an internal sender without out-of-band confirmation for a near-$1M transfer.
The primary $997,400 transfer could not be reversed; insurance recovered $885,784, leaving about $112,000 in net loss. The $9,210 vendor-redirection loss was recovered except for $120. No arrests were reported despite FBI and Japanese law-enforcement involvement. Afterward the charity strengthened its technology systems and adopted new controls, including phone confirmation of all new vendors and bank-account changes, and said no further incidents had occurred.
A globally trusted charity with hundreds of millions in revenue was defrauded through a single compromised mailbox and a plausible invoice, showing that BEC/EAC targets any organization that moves money, not just corporations. It illustrates how attackers research a victim to craft mission-consistent pretexts, and how internal-origin email bypasses normal skepticism.
Because it surfaced only through a mandatory IRS Form 990 "diversion of assets" disclosure, it is also a reminder that many such losses become public only through regulatory filings. The remediation, mandatory out-of-band verification of new payees and bank-detail changes, is the single most effective control against this attack class.
Require out-of-band (phone or in-person) verification of any new vendor and any new or changed bank-account instructions, using contact details on file rather than those in the email. Enforce dual authorization and callback thresholds for high-value wires. Enable MFA and monitor for anomalous mailbox access, forwarding rules, and login locations to detect account takeover.
Train staff that internally originated emails and invoices are not automatically trustworthy. Cross-check that payment destinations are consistent with the stated purpose (e.g., a Pakistan project paying into Japan). Maintain crime/cyber insurance and report promptly to the bank and FBI IC3 to maximize recovery windows.
Social Engineering Examples. “Save the Children Federation $1M Charity BEC via Employee Email Compromise (2017)”. Accessed 19 September 2026. https://socialengineeringexamples.com/save-the-children-federation-charity-bec-2017
the attacker likely researched Save the Children's public profile, including its well-documented, multi-decade health and infrastructure programs in Pakistan, using the charity's own website, annual reports, and press coverage, to identify a spending pretext (solar panels for health centers) that would look mission-consistent rather than suspicious to internal reviewers.
a charity's program locations and history are intentionally public for fundraising and transparency purposes, so this reconnaissance surface cannot realistically be closed off; the effective control sits downstream, at the payment-verification stage (Stage 6), where any pretext, however well-researched, still has to pass before money moves.
the attacker gained control of a real Save the Children employee's mailbox. The Form 990 attributes this to an unnamed criminal hacker or hackers, and no public source discloses the specific access vector, but this pattern is consistent with credential phishing, credential stuffing, or malware, the typical routes into a corporate mailbox in EAC-style BEC.
reduce the odds and blast radius of a mailbox takeover with phishing-resistant MFA on email accounts, email security gateways with anomaly detection, and regular staff training on credential-phishing recognition.
once inside the account, the attacker plausibly reviewed sent mail, contacts, and prior invoices to learn the employee's writing style, internal approval chain, and vendor/payment conventions, so a fabricated request would read as an ordinary internal transaction rather than an anomaly.
monitor for and alert on the signals of a compromised mailbox being used for reconnaissance, such as new inbox or forwarding rules, logins from unusual locations or times, and unusual searching or exporting of old messages, so a takeover is caught before it is weaponized.
the attacker created false invoices and supporting paperwork requesting payment for solar panels at Pakistan health centers, a request specifically tailored to match the charity's genuine, decades-long Pakistan operations so it would not draw scrutiny.
require that any new or unusual project expenditure, however plausible, be checked against existing budgets, grant documentation, or program staff who would know whether such a purchase had actually been approved.
the fraudulent invoice and instructions were sent from inside the organization using the compromised mailbox, exploiting staff's default trust in internally originated requests and bypassing the skepticism normally reserved for external emails.
train finance and procurement staff that an email appearing to originate from an internal colleague is not, by itself, proof of legitimacy, particularly for first-time or high-value payment requests.
Save the Children processed the nearly $1,000,000 payment without independently verifying the destination bank details by phone or another out-of-band channel, the single control gap that let the fraud proceed to a completed wire.
mandate out-of-band verification, a phone call to a contact number already on file rather than one supplied in the email, for any new vendor or any change to existing bank-account instructions, plus dual authorization above a set wire-value threshold. This is the control Save the Children adopted afterward and the single highest-leverage defense against this attack class.
$997,400 was wired to a fraudulent entity in Japan, a destination unconnected to the stated Pakistan project, consistent with a money-mule or layering account used to move and withdraw the funds before the fraud was discovered in May 2017, by which point the transfer could not be recalled.
once money clears to an overseas account, recovery depends on speed, reporting immediately to the originating bank and FBI IC3 to try to freeze funds before they are laundered further, and maintaining crime/cyber insurance as the financial backstop for whatever cannot be recovered.
Browse by what this case has in common with others in the library.
A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam.
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
A spoofed email impersonating a company executive tricked a Main Line Health employee into emailing all ~11,000 staff W-2s to…
A compromised Constant Contact account let Russia-linked Nobelium send USAID-spoofed phishing emails to 150-350 government and NGO organizations.
Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.
Ghanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network.
A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…