Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to Japan; insurance covered all but roughly $112,000.
Reviewed by the Social Engineering Examples team.
Save the Children Federation, the US arm of the well-known children's charity, disclosed in its IRS Form 990 for fiscal year 2017 that it had been defrauded of nearly $1 million in a business email compromise (BEC) scheme. An unknown attacker gained access to an employee's email account, posed as that staff member, and created false invoices and supporting documents claiming the charity needed to pay for solar panels for health centers in Pakistan, a country where Save the Children has operated for over 30 years. Believing the request was a legitimate internal transaction, the organization wired $997,400 to a fraudulent entity in Japan. By the time the fraud was discovered in May 2017, the transfer could not be recalled. The charity worked with the FBI and Japanese authorities, but no arrests were reported. Insurance reimbursed $885,784, leaving a net loss of roughly $112,000. The Form 990 also disclosed a separate, smaller vendor-impersonation incident: after a vendor's email account was hacked, the charity was given fraudulent bank details and sent $9,210 to an account in Benin, West Africa, recovering all but $120. The incident was uncovered by Boston Globe reporter Todd Wallack, who used a script to scan electronic Form 990 filings for "significant diversion of assets" disclosures.
This was an email account compromise (EAC) flavor of BEC: rather than merely spoofing an address, the attacker took control of a real employee mailbox and sent fraudulent documents from inside the organization. Requests and invoices that originate internally are commonly assumed legitimate and rarely challenged, so the fake solar-panel invoices sailed through. The pretext was carefully chosen to match the charity's genuine, decades-long operations in Pakistan, making the payment request look routine and mission-consistent rather than suspicious. The scheme exploited a large organization that processes dozens of high-value wire transfers per year, and the lack of an out-of-band verification step (a phone call to confirm new vendors or new bank instructions) meant nothing caught the fraud before the money left. The separate vendor incident followed the classic invoice-redirection pattern: a compromised supplier mailbox supplied new "updated" banking details that diverted a legitimate payment.
Lure: internal-looking emails from a genuine, hijacked employee account carrying false invoices and documents for a plausible, mission-aligned expense (solar panels for Pakistan health centers). Tells and safeguards that would have caught it: new or changed vendor and bank-account instructions that were never independently verified by phone, payment destination (Japan) inconsistent with the stated purpose (Pakistan project), and reliance on trust in an internal sender without out-of-band confirmation for a near-$1M transfer.
The primary $997,400 transfer could not be reversed; insurance recovered $885,784, leaving about $112,000 in net loss. The $9,210 vendor-redirection loss was recovered except for $120. No arrests were reported despite FBI and Japanese law-enforcement involvement. Afterward the charity strengthened its technology systems and adopted new controls, including phone confirmation of all new vendors and bank-account changes, and said no further incidents had occurred.
A globally trusted charity with hundreds of millions in revenue was defrauded through a single compromised mailbox and a plausible invoice, showing that BEC/EAC targets any organization that moves money, not just corporations. It illustrates how attackers research a victim to craft mission-consistent pretexts, and how internal-origin email bypasses normal skepticism. Because it surfaced only through a mandatory IRS Form 990 "diversion of assets" disclosure, it is also a reminder that many such losses become public only through regulatory filings. The remediation, mandatory out-of-band verification of new payees and bank-detail changes, is the single most effective control against this attack class.
Require out-of-band (phone or in-person) verification of any new vendor and any new or changed bank-account instructions, using contact details on file rather than those in the email. Enforce dual authorization and callback thresholds for high-value wires. Enable MFA and monitor for anomalous mailbox access, forwarding rules, and login locations to detect account takeover. Train staff that internally originated emails and invoices are not automatically trustworthy. Cross-check that payment destinations are consistent with the stated purpose (e.g., a Pakistan project paying into Japan). Maintain crime/cyber insurance and report promptly to the bank and FBI IC3 to maximize recovery windows.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…