Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls about a fake confidential China acquisition to talk the Indian subsidiary's head into wiring $18.6 million to Hong Kong accounts in November 2018.
Reviewed by the Social Engineering Examples team.
In November 2018, fraudsters sent the head of Tecnimont Pvt Ltd (Tecnimont SpA's Indian subsidiary) emails from an address closely mimicking that of Maire Tecnimont group CEO Pierroberto Folgiero, raising a "secretive" and "highly confidential" acquisition opportunity in China. To make the pretext credible, the attackers then staged a series of live conference calls in which different conspirators played the roles of the group CEO, other senior Tecnimont executives, and a supposed Swiss/Switzerland-based lawyer named "Luigi Corradi." The India head was told the acquisition funds could not be transferred directly from the Italian parent because of regulatory issues, and that his unit needed to wire the money instead. Over the course of about a week he authorized three transfers, $5.6 million, $9.4 million, and $3.6 million, totaling roughly $18.6 million, to bank accounts in Hong Kong. Each tranche was withdrawn within minutes of arrival. The fraudsters attempted a fourth transfer but were caught before it went through. Economic Times and Reuters report the scheme unraveled in December 2018 when Maire Tecnimont chairman Franco Ghiringhelli visited the Indian operation and the fraud came to light (an Italian press account instead places the discovery roughly nine days after the initial email, around late November 2018). A subsequent internal/forensic investigation (with Kroll, a Mumbai law firm, and white-collar fraud specialists MZM Legal assisting) found that all participants on the conference calls had used fraudulent identities: "Luigi Corradi" turned out to be the name of a real Italian engineer and teacher who had died in 1921, and the Hong Kong receiving accounts had been opened using fake documentation. Tecnimont filed a criminal complaint with the Mumbai Police cybercrime unit naming six entities, including purported Hong Kong- and Taizhou (China)-based companies and the fictitious "Luigi Corradi." The company terminated its India CMD (chief managing director) and head of accounts and finance, and reconstituted the Indian subsidiary's board.
The attack combined classic BEC email spoofing with an unusually elaborate live social-engineering layer. First, a look-alike email address was used to impersonate the group CEO, with wording reportedly matching his writing style: commentators speculated the attackers may have monitored internal email communications beforehand to learn tone and vocabulary. Rather than stopping at a single spoofed-email payment request (the typical BEC pattern), the attackers escalated to synchronized, scheduled conference calls with multiple conspirators simultaneously voicing the CEO, other executives, and an invented outside lawyer, creating corroborating "social proof" that a normal one-off phishing email cannot provide and that made the request far harder for a single employee to independently disconfirm. The "confidential acquisition" pretext supplied both urgency and secrecy, discouraging the India head from consulting colleagues or the parent company directly, while the claimed "regulatory issue" preventing an Italy-originated transfer redirected the actual payment obligation onto the Indian subsidiary, a classic BEC technique of moving the transaction to the path with the weakest verification controls. The receiving Hong Kong accounts were pre-established using falsified documents so funds could be withdrawn almost immediately after each transfer landed, minimizing the window for reversal.
Lure: a spoofed but visually convincing group-CEO email introducing a secretive, time-pressured China acquisition, reinforced by live conference calls featuring impersonated senior executives and a fabricated outside lawyer, plus a superficially plausible business reason (Italian regulatory constraints) for why the Indian unit itself had to wire the funds. Tells that should have raised suspicion in hindsight: the demand for absolute confidentiality that discouraged verification with the parent company or other executives; a named outside counsel who could not be independently verified before large sums moved; a "regulatory" excuse for why headquarters itself couldn't simply make the payment; the compressed one-week timeline across three transfers; and reliance on phone/conference-call "confirmation" of identity rather than any cryptographically or procedurally verifiable channel.
The Indian subsidiary lost approximately $18.6 million with no confirmed recovery. Tecnimont/Maire Tecnimont fired the India CMD and the head of accounts and finance, reconstituted the Indian board, hired Kroll for forensic investigation and outside counsel (a Mumbai law firm plus MZM Legal) for the fraud response, and filed a criminal complaint with the Mumbai Police cybercrime unit naming six entities including two purported Hong Kong/Taizhou-based companies and the fictitious "Luigi Corradi." CARE Ratings' March 2019 credit note on Tecnimont Private Limited independently confirmed the ~$18.6 million fraudulent transaction and the CMD's termination while reaffirming the company's credit rating, saying the liquidity impact was only partially offset by cash reserves. No public source found documents an arrest, indictment, or conviction tied to this specific case in India, Italy, Hong Kong, or China, despite press attribution of the scheme to a "gang of Chinese fraudsters."
The case is widely cited in security-industry roundups as one of the most elaborate BEC/CEO-fraud schemes on record because the attackers didn't stop at a spoofed email. They staged an entire fake M&A due-diligence process with multiple live impersonators on scheduled conference calls, an invented outside lawyer, and a plausible cross-border regulatory pretext, all engineered to make an $18.6 million wire request survive normal human skepticism. It demonstrates that email-authentication controls alone (SPF/DKIM/DMARC) are insufficient against attackers willing to invest in live, synchronized social engineering, and underscores why any large or first-time cross-border wire, however well-corroborated by phone or video, needs an out-of-band verification path that the requester cannot control or supply themselves.
Reported industry-standard defenses that would have blunted this scheme: out-of-band verification of any wire-transfer request through a known, independently-dialed phone number (never one supplied in the suspect email/call); a callback policy to a previously verified executive contact for any "confidential/urgent" cross-border transfer; dual-authorization and maker-checker controls on large international wires with no single-executive override; treating "keep this confidential, don't loop in anyone else" and "regulatory issues prevent transfer from the parent" as red flags rather than justifications; independently verifying the identity/bar credentials of any outside lawyer introduced mid-transaction; domain-monitoring and anti-spoofing controls (SPF/DKIM/DMARC enforcement) to catch look-alike executive email addresses; and beneficiary/KYC diligence on newly introduced Hong Kong accounts before releasing large sums. Tecnimont's actual post-incident response included forensic investigation (Kroll), outside counsel (a Mumbai law firm and MZM Legal), termination of the India CMD and head of accounts/finance, board reconstitution at the Indian subsidiary, and a formal complaint to the Mumbai Police cybercrime unit: all after-the-fact remediation rather than prevention.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…
Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition,…
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…