Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls.
Social Engineering Examples·6 sources
In November 2018, fraudsters sent the head of Tecnimont Pvt Ltd (Tecnimont SpA's Indian subsidiary) emails from an address closely mimicking that of Maire Tecnimont group CEO Pierroberto Folgiero, raising a "secretive" and "highly confidential" acquisition opportunity in China. To make the pretext credible, the attackers then staged a series of live conference calls in which different conspirators played the roles of the group CEO, other senior Tecnimont executives, and a supposed Swiss/Switzerland-based lawyer named "Luigi Corradi." The India head was told the acquisition funds could not be transferred directly from the Italian parent because of regulatory issues, and that his unit needed to wire the money instead.
Over the course of about a week he authorized three transfers, $5.6 million, $9.4 million, and $3.6 million, totaling roughly $18.6 million, to bank accounts in Hong Kong. Each tranche was withdrawn within minutes of arrival. The fraudsters attempted a fourth transfer but were caught before it went through. Economic Times and Reuters report the scheme unraveled in December 2018 when Maire Tecnimont chairman Franco Ghiringhelli visited the Indian operation and the fraud came to light (an Italian press account instead places the discovery roughly nine days after the initial email, around late November 2018).
A subsequent internal/forensic investigation (with Kroll, a Mumbai law firm, and white-collar fraud specialists MZM Legal assisting) found that all participants on the conference calls had used fraudulent identities: "Luigi Corradi" turned out to be the name of a real Italian engineer and teacher who had died in 1921, and the Hong Kong receiving accounts had been opened using fake documentation.
Tecnimont filed a criminal complaint with the Mumbai Police cybercrime unit naming six entities, including purported Hong Kong- and Taizhou (China)-based companies and the fictitious "Luigi Corradi." The company terminated its India CMD (chief managing director) and head of accounts and finance, and reconstituted the Indian subsidiary's board.
The attack combined classic BEC email spoofing with an unusually elaborate live social-engineering layer. First, a look-alike email address was used to impersonate the group CEO, with wording reportedly matching his writing style: commentators speculated the attackers may have monitored internal email communications beforehand to learn tone and vocabulary.
Rather than stopping at a single spoofed-email payment request (the typical BEC pattern), the attackers escalated to synchronized, scheduled conference calls with multiple conspirators simultaneously voicing the CEO, other executives, and an invented outside lawyer, creating corroborating "social proof" that a normal one-off phishing email cannot provide and that made the request far harder for a single employee to independently disconfirm.
The "confidential acquisition" pretext supplied both urgency and secrecy, discouraging the India head from consulting colleagues or the parent company directly, while the claimed "regulatory issue" preventing an Italy-originated transfer redirected the actual payment obligation onto the Indian subsidiary, a classic BEC technique of moving the transaction to the path with the weakest verification controls.
The receiving Hong Kong accounts were pre-established using falsified documents so funds could be withdrawn almost immediately after each transfer landed, minimizing the window for reversal.
Lure: a spoofed but visually convincing group-CEO email introducing a secretive, time-pressured China acquisition, reinforced by live conference calls featuring impersonated senior executives and a fabricated outside lawyer, plus a superficially plausible business reason (Italian regulatory constraints) for why the Indian unit itself had to wire the funds.
Tells that should have raised suspicion in hindsight: the demand for absolute confidentiality that discouraged verification with the parent company or other executives; a named outside counsel who could not be independently verified before large sums moved; a "regulatory" excuse for why headquarters itself couldn't simply make the payment; the compressed one-week timeline across three transfers; and reliance on phone/conference-call "confirmation" of identity rather than any cryptographically or procedurally verifiable channel.
The Indian subsidiary lost approximately $18.6 million with no confirmed recovery. Tecnimont/Maire Tecnimont fired the India CMD and the head of accounts and finance, reconstituted the Indian board, hired Kroll for forensic investigation and outside counsel (a Mumbai law firm plus MZM Legal) for the fraud response, and filed a criminal complaint with the Mumbai Police cybercrime unit naming six entities including two purported Hong Kong/Taizhou-based companies and the fictitious "Luigi Corradi." CARE Ratings' March 2019 credit note on Tecnimont Private Limited independently confirmed the ~$18.6 million fraudulent transaction and the CMD's termination while reaffirming the company's credit rating, saying the liquidity impact was only partially offset by cash reserves.
No public source found documents an arrest, indictment, or conviction tied to this specific case in India, Italy, Hong Kong, or China, despite press attribution of the scheme to a "gang of Chinese fraudsters."
The case is widely cited in security-industry roundups as one of the most elaborate BEC/CEO-fraud schemes on record because the attackers didn't stop at a spoofed email. They staged an entire fake M&A due-diligence process with multiple live impersonators on scheduled conference calls, an invented outside lawyer, and a plausible cross-border regulatory pretext, all engineered to make an $18.6 million wire request survive normal human skepticism.
It demonstrates that email-authentication controls alone (SPF/DKIM/DMARC) are insufficient against attackers willing to invest in live, synchronized social engineering, and underscores why any large or first-time cross-border wire, however well-corroborated by phone or video, needs an out-of-band verification path that the requester cannot control or supply themselves.
Reported industry-standard defenses that would have blunted this scheme: out-of-band verification of any wire-transfer request through a known, independently-dialed phone number (never one supplied in the suspect email/call); a callback policy to a previously verified executive contact for any "confidential/urgent" cross-border transfer; dual-authorization and maker-checker controls on large international wires with no single-executive override; treating "keep this confidential, don't loop in anyone else" and "regulatory issues prevent transfer from the parent" as red flags rather than justifications; independently verifying the identity/bar credentials of any outside lawyer introduced mid-transaction; domain-monitoring and anti-spoofing controls (SPF/DKIM/DMARC enforcement) to catch look-alike executive email addresses; and beneficiary/KYC diligence on newly introduced Hong Kong accounts before releasing large sums.
Tecnimont's actual post-incident response included forensic investigation (Kroll), outside counsel (a Mumbai law firm and MZM Legal), termination of the India CMD and head of accounts/finance, board reconstitution at the Indian subsidiary, and a formal complaint to the Mumbai Police cybercrime unit: all after-the-fact remediation rather than prevention.
Social Engineering Examples. “Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls”. Accessed 16 September 2026. https://socialengineeringexamples.com/tecnimont-spa-bec-fake-conference-call-fraud-2018
The attackers likely used public corporate filings, press coverage, and org-chart/LinkedIn-style research to identify Tecnimont's group CEO Pierroberto Folgiero, the Indian subsidiary's leadership, and the reporting relationship between the Italian parent and its India unit, enough to know who could plausibly order a large cross-border wire and who would receive that order.
Public information about corporate leadership and reporting lines (CEO names, subsidiary structure) is effectively unremovable at a listed multinational; the realistic control assumes attackers can find this and instead hardens the payment-approval process that this knowledge later gets used against, per Stage 7/8.
Security commentators quoted in Economic Times reporting speculated the attackers may have used malware or other unauthorized access to monitor internal email traffic beforehand, learning the group CEO's actual writing style and vocabulary so the spoofed messages would read as authentic; this is described as likely rather than confirmed by any forensic disclosure.
Standard email-security hygiene, endpoint monitoring for unauthorized mailbox access, anomalous-login alerting, and periodic auditing of who has read or forwarded executive correspondence reduce the odds that an attacker can silently study a real executive's writing style before impersonating it.
look-alike domain and account registration: The attackers registered or obtained an email address closely mimicking the group CEO's real address, and separately arranged bank accounts in Hong Kong (with some reporting of intermediate accounts in Shanghai and Taizhou, China) opened using falsified identity documents, pre-positioning a withdrawal path before the fraud began.
Domain-monitoring and anti-spoofing controls (SPF/DKIM/DMARC enforcement, look-alike-domain registration monitoring) would flag a near-identical CEO email address before it reaches an inbox; on the banking side, beneficiary and KYC diligence by the receiving banks on newly opened Hong Kong accounts is the analogous control, though it sits outside the victim company's own reach.
Multiple conspirators prepared to voice distinct fake identities for the live phase of the scheme, including the group CEO, other senior executives, and a wholly invented Swiss lawyer, "Luigi Corradi" (the real name of an Italian engineer and teacher who died in 1921), so the fraud could survive a multi-person phone conversation rather than a single written message.
There is no practical way for a victim organization to detect that a persona has been fabricated before contact occurs; the realistic control is at Stage 6, verifying any claimed identity independently rather than trusting it once it appears.
A message from the look-alike CEO address reached the India head, raising a "secretive" and "highly confidential" acquisition opportunity in China and setting up confidentiality and urgency as the frame for everything that followed.
Treating "highly confidential, don't loop in others" as a red flag rather than a legitimate instruction, and routing any large or unusual funding request through a second reviewer regardless of secrecy framing, blunts the initial email's core manipulation.
Rather than relying on the email alone, the attackers held a series of scheduled conference calls in which different conspirators impersonated the CEO, other executives, and the fictitious lawyer simultaneously, manufacturing corroborating "social proof" that a single spoofed email could not provide.
Out-of-band verification through a phone number the company already has on file (never one supplied in the email or call), plus a policy that a live-sounding voice on a conference call is not itself proof of identity, would have exposed the fabricated participants before money moved.
The impersonators told the India head that regulatory issues prevented the acquisition funds from being sent directly from Italy, redirecting the actual payment obligation onto the Indian subsidiary, the entity with weaker verification controls for a transaction of this size.
Dual-authorization and maker-checker controls on large international wires, with no single-executive override, and independent verification of any outside lawyer's credentials before relying on their instructions, directly counter a pretext designed to move the transaction to the weakest-verification path.
The India head authorized three wire transfers over about a week ($5.6 million, $9.4 million, and $3.6 million, totaling roughly $18.6 million) to the pre-arranged Hong Kong accounts; each tranche was withdrawn within minutes of arrival, and a fourth attempted transfer was stopped only because the fraud was discovered first.
A mandatory callback to a previously verified executive contact, plus a cooling-off or hold period on first-time large cross-border wires to newly introduced accounts, would have caught the fraud before funds were withdrawn within minutes of each transfer landing.
Browse by what this case has in common with others in the library.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition.
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.
A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO demanded an urgent transfer.
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling…
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO demanded an urgent transfer.
Hours before Maharashtra's 2024 assembly election polling, BJP-amplified audio clips purporting to catch opposition leaders Supriya Sule and Nana Patole.
A Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing…
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.