Case Library / Phishing / Save the Children Federation $1M Charity BEC via Employee Email Compromise (2017)
Phishing Confirmed

Save the Children Federation $1M Charity BEC via Employee Email Compromise (2017)

Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to Japan; insurance covered all but roughly $112,000.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Save the Children Federation, the US arm of the well-known children's charity, disclosed in its IRS Form 990 for fiscal year 2017 that it had been defrauded of nearly $1 million in a business email compromise (BEC) scheme. An unknown attacker gained access to an employee's email account, posed as that staff member, and created false invoices and supporting documents claiming the charity needed to pay for solar panels for health centers in Pakistan, a country where Save the Children has operated for over 30 years. Believing the request was a legitimate internal transaction, the organization wired $997,400 to a fraudulent entity in Japan. By the time the fraud was discovered in May 2017, the transfer could not be recalled. The charity worked with the FBI and Japanese authorities, but no arrests were reported. Insurance reimbursed $885,784, leaving a net loss of roughly $112,000. The Form 990 also disclosed a separate, smaller vendor-impersonation incident: after a vendor's email account was hacked, the charity was given fraudulent bank details and sent $9,210 to an account in Benin, West Africa, recovering all but $120. The incident was uncovered by Boston Globe reporter Todd Wallack, who used a script to scan electronic Form 990 filings for "significant diversion of assets" disclosures.

How the Attack Worked

This was an email account compromise (EAC) flavor of BEC: rather than merely spoofing an address, the attacker took control of a real employee mailbox and sent fraudulent documents from inside the organization. Requests and invoices that originate internally are commonly assumed legitimate and rarely challenged, so the fake solar-panel invoices sailed through. The pretext was carefully chosen to match the charity's genuine, decades-long operations in Pakistan, making the payment request look routine and mission-consistent rather than suspicious. The scheme exploited a large organization that processes dozens of high-value wire transfers per year, and the lack of an out-of-band verification step (a phone call to confirm new vendors or new bank instructions) meant nothing caught the fraud before the money left. The separate vendor incident followed the classic invoice-redirection pattern: a compromised supplier mailbox supplied new "updated" banking details that diverted a legitimate payment.

The Lure & the Tell

Lure: internal-looking emails from a genuine, hijacked employee account carrying false invoices and documents for a plausible, mission-aligned expense (solar panels for Pakistan health centers). Tells and safeguards that would have caught it: new or changed vendor and bank-account instructions that were never independently verified by phone, payment destination (Japan) inconsistent with the stated purpose (Pakistan project), and reliance on trust in an internal sender without out-of-band confirmation for a near-$1M transfer.

Outcome

The primary $997,400 transfer could not be reversed; insurance recovered $885,784, leaving about $112,000 in net loss. The $9,210 vendor-redirection loss was recovered except for $120. No arrests were reported despite FBI and Japanese law-enforcement involvement. Afterward the charity strengthened its technology systems and adopted new controls, including phone confirmation of all new vendors and bank-account changes, and said no further incidents had occurred.

Why It Matters

A globally trusted charity with hundreds of millions in revenue was defrauded through a single compromised mailbox and a plausible invoice, showing that BEC/EAC targets any organization that moves money, not just corporations. It illustrates how attackers research a victim to craft mission-consistent pretexts, and how internal-origin email bypasses normal skepticism. Because it surfaced only through a mandatory IRS Form 990 "diversion of assets" disclosure, it is also a reminder that many such losses become public only through regulatory filings. The remediation, mandatory out-of-band verification of new payees and bank-detail changes, is the single most effective control against this attack class.

Defenses

Require out-of-band (phone or in-person) verification of any new vendor and any new or changed bank-account instructions, using contact details on file rather than those in the email. Enforce dual authorization and callback thresholds for high-value wires. Enable MFA and monitor for anomalous mailbox access, forwarding rules, and login locations to detect account takeover. Train staff that internally originated emails and invoices are not automatically trustworthy. Cross-check that payment destinations are consistent with the stated purpose (e.g., a Pakistan project paying into Japan). Maintain crime/cyber insurance and report promptly to the bank and FBI IC3 to maximize recovery windows.

Sources
  • Save The Children Federation Inc. Full Form 990 Filing (FY ending Dec. 2017). ProPublica Nonprofit Explorer Primary. First-party disclosure: the charity's IRS Form 990 reported the fraud under 'significant diversion of assets,' including the $997,400 transfer to Japan and $885,784 insurance recovery. ProPublica reconstructs the IRS filing from raw XML/PDF. Fetched and verified: page confirms organization name, Fairfield CT location, and EIN 06-0726487.
  • Hackers fooled Save the Children into sending $1 million to a phony account. The Boston Globe Secondary. Original investigative report (by Todd Wallack) that surfaced the Form 990 disclosure; source of the solar-panel/Pakistan pretext, Japan destination, $112,000 net loss, and $9,210 vendor incident. Fetched and verified: confirms all named facts including CFO Stacy Brandom's quote and May 2017 discovery date.
  • Hackers stole nearly $1M from Save the Children charity. Associated Press Secondary. Corroborates victim, method, Japan destination, and $112,000 unreimbursed loss. Fetched and verified: content matches, citing the Boston Globe report.
  • Save the Children Hacked Twice In 2017. The NonProfit Times Secondary. Quotes the Form 990 language ('$997,400 to an entity in Japan'), $885,784 insurance figure, CFO statement, and the second incident ($9,210 to Benin, all but $120 recovered). Fetched and verified: all quoted figures and language present in the fetched content.
  • Save the Children Federation Duped in $1M Scam. Threatpost Secondary. Security-press corroboration: BEC framing, FBI and Japanese law-enforcement involvement, $111,616 net loss, and April 2017 timing of the fraudulent transfer. Fetched and verified.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and pretext selection: the attacker likely researched Save the Children's public profile, including its well-documented, multi-decade health and infrastructure programs in Pakistan, using the charity's own website, annual reports, and press coverage, to identify a spending pretext (solar panels for health centers) that would look mission-consistent rather than suspicious to internal reviewers.
Countering Stage 1: a charity's program locations and history are intentionally public for fundraising and transparency purposes, so this reconnaissance surface cannot realistically be closed off; the effective control sits downstream, at the payment-verification stage (Stage 6), where any pretext, however well-researched, still has to pass before money moves.
2
Initial access, email account compromise: the attacker gained control of a real Save the Children employee's mailbox. The Form 990 attributes this to an unnamed criminal hacker or hackers, and no public source discloses the specific access vector, but this pattern is consistent with credential phishing, credential stuffing, or malware, the typical routes into a corporate mailbox in EAC-style BEC.
Countering Stage 2: reduce the odds and blast radius of a mailbox takeover with phishing-resistant MFA on email accounts, email security gateways with anomaly detection, and regular staff training on credential-phishing recognition.
3
Post-compromise mailbox reconnaissance: once inside the account, the attacker plausibly reviewed sent mail, contacts, and prior invoices to learn the employee's writing style, internal approval chain, and vendor/payment conventions, so a fabricated request would read as an ordinary internal transaction rather than an anomaly.
Countering Stage 3: monitor for and alert on the signals of a compromised mailbox being used for reconnaissance, such as new inbox or forwarding rules, logins from unusual locations or times, and unusual searching or exporting of old messages, so a takeover is caught before it is weaponized.
4
Document fabrication: the attacker created false invoices and supporting paperwork requesting payment for solar panels at Pakistan health centers, a request specifically tailored to match the charity's genuine, decades-long Pakistan operations so it would not draw scrutiny.
Countering Stage 4: require that any new or unusual project expenditure, however plausible, be checked against existing budgets, grant documentation, or program staff who would know whether such a purchase had actually been approved.
5
Delivery via the hijacked internal account: the fraudulent invoice and instructions were sent from inside the organization using the compromised mailbox, exploiting staff's default trust in internally originated requests and bypassing the skepticism normally reserved for external emails.
Countering Stage 5: train finance and procurement staff that an email appearing to originate from an internal colleague is not, by itself, proof of legitimacy, particularly for first-time or high-value payment requests.
6
Bypassing payment verification: Save the Children processed the nearly $1,000,000 payment without independently verifying the destination bank details by phone or another out-of-band channel, the single control gap that let the fraud proceed to a completed wire.
Countering Stage 6: mandate out-of-band verification, a phone call to a contact number already on file rather than one supplied in the email, for any new vendor or any change to existing bank-account instructions, plus dual authorization above a set wire-value threshold. This is the control Save the Children adopted afterward and the single highest-leverage defense against this attack class.
7
Fund transfer and cash-out (objective completion): $997,400 was wired to a fraudulent entity in Japan, a destination unconnected to the stated Pakistan project, consistent with a money-mule or layering account used to move and withdraw the funds before the fraud was discovered in May 2017, by which point the transfer could not be recalled.
Countering Stage 7: once money clears to an overseas account, recovery depends on speed, reporting immediately to the originating bank and FBI IC3 to try to freeze funds before they are laundered further, and maintaining crime/cyber insurance as the financial backstop for whatever cannot be recovered.
Quick Facts
Victim
Save the Children Federation, Inc. (Save the Children US), the Fairfield, Connecticut-based US affiliate of the international charity (EIN 06-0726487).
Location
United States (Fairfield, Connecticut); funds routed to an account in Japan
Date
2017 (fraud committed ~April to May 2017; discovered May 2017; disclosed in IRS Form 990 filed August 2018, first reported December 2018)
Impact
Primary incident: $997,400 wired to a fraudulent entity in Japan; insurance reimbursed $885,784, leaving a net loss of about $111,616 (~$112,000). Second incident: $9,210 diverted to a hacked vendor's fraudulent account in Benin, West Africa; all but $120 recovered.
Status
Confirmed
Case Type
Real-World Incident
Sector
Nonprofit & NGO
Related

Related Cases

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…

Incident 2018Read →

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…

Incident 2018Read →

Seagate CEO-Spoof W-2 Phishing Breach (2016)

A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…

Incident 2016Read →