Case Library / Phishing / Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls
Phishing Confirmed

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series of conference calls about a fake confidential China acquisition to talk the Indian subsidiary's head into wiring $18.6 million to Hong Kong accounts in November 2018.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In November 2018, fraudsters sent the head of Tecnimont Pvt Ltd (Tecnimont SpA's Indian subsidiary) emails from an address closely mimicking that of Maire Tecnimont group CEO Pierroberto Folgiero, raising a "secretive" and "highly confidential" acquisition opportunity in China. To make the pretext credible, the attackers then staged a series of live conference calls in which different conspirators played the roles of the group CEO, other senior Tecnimont executives, and a supposed Swiss/Switzerland-based lawyer named "Luigi Corradi." The India head was told the acquisition funds could not be transferred directly from the Italian parent because of regulatory issues, and that his unit needed to wire the money instead. Over the course of about a week he authorized three transfers, $5.6 million, $9.4 million, and $3.6 million, totaling roughly $18.6 million, to bank accounts in Hong Kong. Each tranche was withdrawn within minutes of arrival. The fraudsters attempted a fourth transfer but were caught before it went through. Economic Times and Reuters report the scheme unraveled in December 2018 when Maire Tecnimont chairman Franco Ghiringhelli visited the Indian operation and the fraud came to light (an Italian press account instead places the discovery roughly nine days after the initial email, around late November 2018). A subsequent internal/forensic investigation (with Kroll, a Mumbai law firm, and white-collar fraud specialists MZM Legal assisting) found that all participants on the conference calls had used fraudulent identities: "Luigi Corradi" turned out to be the name of a real Italian engineer and teacher who had died in 1921, and the Hong Kong receiving accounts had been opened using fake documentation. Tecnimont filed a criminal complaint with the Mumbai Police cybercrime unit naming six entities, including purported Hong Kong- and Taizhou (China)-based companies and the fictitious "Luigi Corradi." The company terminated its India CMD (chief managing director) and head of accounts and finance, and reconstituted the Indian subsidiary's board.

How the Attack Worked

The attack combined classic BEC email spoofing with an unusually elaborate live social-engineering layer. First, a look-alike email address was used to impersonate the group CEO, with wording reportedly matching his writing style: commentators speculated the attackers may have monitored internal email communications beforehand to learn tone and vocabulary. Rather than stopping at a single spoofed-email payment request (the typical BEC pattern), the attackers escalated to synchronized, scheduled conference calls with multiple conspirators simultaneously voicing the CEO, other executives, and an invented outside lawyer, creating corroborating "social proof" that a normal one-off phishing email cannot provide and that made the request far harder for a single employee to independently disconfirm. The "confidential acquisition" pretext supplied both urgency and secrecy, discouraging the India head from consulting colleagues or the parent company directly, while the claimed "regulatory issue" preventing an Italy-originated transfer redirected the actual payment obligation onto the Indian subsidiary, a classic BEC technique of moving the transaction to the path with the weakest verification controls. The receiving Hong Kong accounts were pre-established using falsified documents so funds could be withdrawn almost immediately after each transfer landed, minimizing the window for reversal.

The Lure & the Tell

Lure: a spoofed but visually convincing group-CEO email introducing a secretive, time-pressured China acquisition, reinforced by live conference calls featuring impersonated senior executives and a fabricated outside lawyer, plus a superficially plausible business reason (Italian regulatory constraints) for why the Indian unit itself had to wire the funds. Tells that should have raised suspicion in hindsight: the demand for absolute confidentiality that discouraged verification with the parent company or other executives; a named outside counsel who could not be independently verified before large sums moved; a "regulatory" excuse for why headquarters itself couldn't simply make the payment; the compressed one-week timeline across three transfers; and reliance on phone/conference-call "confirmation" of identity rather than any cryptographically or procedurally verifiable channel.

Outcome

The Indian subsidiary lost approximately $18.6 million with no confirmed recovery. Tecnimont/Maire Tecnimont fired the India CMD and the head of accounts and finance, reconstituted the Indian board, hired Kroll for forensic investigation and outside counsel (a Mumbai law firm plus MZM Legal) for the fraud response, and filed a criminal complaint with the Mumbai Police cybercrime unit naming six entities including two purported Hong Kong/Taizhou-based companies and the fictitious "Luigi Corradi." CARE Ratings' March 2019 credit note on Tecnimont Private Limited independently confirmed the ~$18.6 million fraudulent transaction and the CMD's termination while reaffirming the company's credit rating, saying the liquidity impact was only partially offset by cash reserves. No public source found documents an arrest, indictment, or conviction tied to this specific case in India, Italy, Hong Kong, or China, despite press attribution of the scheme to a "gang of Chinese fraudsters."

Why It Matters

The case is widely cited in security-industry roundups as one of the most elaborate BEC/CEO-fraud schemes on record because the attackers didn't stop at a spoofed email. They staged an entire fake M&A due-diligence process with multiple live impersonators on scheduled conference calls, an invented outside lawyer, and a plausible cross-border regulatory pretext, all engineered to make an $18.6 million wire request survive normal human skepticism. It demonstrates that email-authentication controls alone (SPF/DKIM/DMARC) are insufficient against attackers willing to invest in live, synchronized social engineering, and underscores why any large or first-time cross-border wire, however well-corroborated by phone or video, needs an out-of-band verification path that the requester cannot control or supply themselves.

Defenses

Reported industry-standard defenses that would have blunted this scheme: out-of-band verification of any wire-transfer request through a known, independently-dialed phone number (never one supplied in the suspect email/call); a callback policy to a previously verified executive contact for any "confidential/urgent" cross-border transfer; dual-authorization and maker-checker controls on large international wires with no single-executive override; treating "keep this confidential, don't loop in anyone else" and "regulatory issues prevent transfer from the parent" as red flags rather than justifications; independently verifying the identity/bar credentials of any outside lawyer introduced mid-transaction; domain-monitoring and anti-spoofing controls (SPF/DKIM/DMARC enforcement) to catch look-alike executive email addresses; and beneficiary/KYC diligence on newly introduced Hong Kong accounts before releasing large sums. Tecnimont's actual post-incident response included forensic investigation (Kroll), outside counsel (a Mumbai law firm and MZM Legal), termination of the India CMD and head of accounts/finance, board reconstitution at the Indian subsidiary, and a formal complaint to the Mumbai Police cybercrime unit: all after-the-fact remediation rather than prevention.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target mapping: The attackers likely used public corporate filings, press coverage, and org-chart/LinkedIn-style research to identify Tecnimont's group CEO Pierroberto Folgiero, the Indian subsidiary's leadership, and the reporting relationship between the Italian parent and its India unit, enough to know who could plausibly order a large cross-border wire and who would receive that order.
Countering Stage 1: Public information about corporate leadership and reporting lines (CEO names, subsidiary structure) is effectively unremovable at a listed multinational; the realistic control assumes attackers can find this and instead hardens the payment-approval process that this knowledge later gets used against, per Stage 7/8.
2
Email-account or communications monitoring: Security commentators quoted in Economic Times reporting speculated the attackers may have used malware or other unauthorized access to monitor internal email traffic beforehand, learning the group CEO's actual writing style and vocabulary so the spoofed messages would read as authentic; this is described as likely rather than confirmed by any forensic disclosure.
Countering Stage 2: Standard email-security hygiene, endpoint monitoring for unauthorized mailbox access, anomalous-login alerting, and periodic auditing of who has read or forwarded executive correspondence reduce the odds that an attacker can silently study a real executive's writing style before impersonating it.
3
Infrastructure setup: look-alike domain and account registration: The attackers registered or obtained an email address closely mimicking the group CEO's real address, and separately arranged bank accounts in Hong Kong (with some reporting of intermediate accounts in Shanghai and Taizhou, China) opened using falsified identity documents, pre-positioning a withdrawal path before the fraud began.
Countering Stage 3: Domain-monitoring and anti-spoofing controls (SPF/DKIM/DMARC enforcement, look-alike-domain registration monitoring) would flag a near-identical CEO email address before it reaches an inbox; on the banking side, beneficiary and KYC diligence by the receiving banks on newly opened Hong Kong accounts is the analogous control, though it sits outside the victim company's own reach.
4
Persona development: Multiple conspirators prepared to voice distinct fake identities for the live phase of the scheme, including the group CEO, other senior executives, and a wholly invented Swiss lawyer, "Luigi Corradi" (the real name of an Italian engineer and teacher who died in 1921), so the fraud could survive a multi-person phone conversation rather than a single written message.
Countering Stage 4: There is no practical way for a victim organization to detect that a persona has been fabricated before contact occurs; the realistic control is at Stage 6, verifying any claimed identity independently rather than trusting it once it appears.
5
Initial contact via spoofed email: A message from the look-alike CEO address reached the India head, raising a "secretive" and "highly confidential" acquisition opportunity in China and setting up confidentiality and urgency as the frame for everything that followed.
Countering Stage 5: Treating "highly confidential, don't loop in others" as a red flag rather than a legitimate instruction, and routing any large or unusual funding request through a second reviewer regardless of secrecy framing, blunts the initial email's core manipulation.
6
Live social-engineering escalation via staged conference calls: Rather than relying on the email alone, the attackers held a series of scheduled conference calls in which different conspirators impersonated the CEO, other executives, and the fictitious lawyer simultaneously, manufacturing corroborating "social proof" that a single spoofed email could not provide.
Countering Stage 6: Out-of-band verification through a phone number the company already has on file (never one supplied in the email or call), plus a policy that a live-sounding voice on a conference call is not itself proof of identity, would have exposed the fabricated participants before money moved.
7
Pretext and redirection of the payment path: The impersonators told the India head that regulatory issues prevented the acquisition funds from being sent directly from Italy, redirecting the actual payment obligation onto the Indian subsidiary, the entity with weaker verification controls for a transaction of this size.
Countering Stage 7: Dual-authorization and maker-checker controls on large international wires, with no single-executive override, and independent verification of any outside lawyer's credentials before relying on their instructions, directly counter a pretext designed to move the transaction to the weakest-verification path.
8
Execution and cash-out: The India head authorized three wire transfers over about a week ($5.6 million, $9.4 million, and $3.6 million, totaling roughly $18.6 million) to the pre-arranged Hong Kong accounts; each tranche was withdrawn within minutes of arrival, and a fourth attempted transfer was stopped only because the fraud was discovered first.
Countering Stage 8: A mandatory callback to a previously verified executive contact, plus a cooling-off or hold period on first-time large cross-border wires to newly introduced accounts, would have caught the fraud before funds were withdrawn within minutes of each transfer landing.
Quick Facts
Victim
Tecnimont Private Limited (Tecnimont Pvt Ltd), the Indian subsidiary of Tecnimont SpA, part of the Milan-headquartered, publicly traded Maire Tecnimont Group
Location
Mumbai, India (victim); funds routed to bank accounts in Hong Kong (with some reporting of intermediate accounts in Shanghai/Taizhou, China)
Date
2018-11 (three fraudulent wire transfers made over one week in November 2018. An initial spoofed email is reported by Italian press outlet Corriere della Sera to have arrived 2018-11-13. Economic Times and Reuters, drawing on the Mumbai police complaint, report the fraud was discovered when group chairman Franco Ghiringhelli visited India in December 2018; Corriere della Sera's own account instead describes the chairman learning of the scheme roughly nine days after the initial email, i.e. around late November 2018, so sources conflict on the exact discovery date. Publicly reported by Economic Times/Reuters on 2019-01-10)
Impact
$18.6 million (~Rs 130 crore) per Economic Times and CARE Ratings; Reuters reported a closely aligned figure (~$18.45-18.5 million from 1.3 billion rupees). Sent in three tranches: $5.6 million, $9.4 million, and $3.6 million, from India to Hong Kong bank accounts opened with fake documents; funds were withdrawn within minutes of each transfer. A fourth transfer attempt was stopped once the fraud was discovered. No source reviewed confirms recovery of the stolen funds; CARE Ratings' March 2019 note says the impact was only "partially mitigated" by the company's cash reserves, implying the loss was largely absorbed, not recovered.
Status
Confirmed
Case Type
Real-World Incident
Sector
Construction & Engineering, Critical Infrastructure, Energy & Utilities, Manufacturing & Industrial
Threat Actor
Organized Crime
Related

Related Cases

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…

Incident 2018Read →

Pathé €19.2M fake-CEO cinema-chain fraud (2018)

Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition,…

Incident 2018Read →

Toyota Boshoku European Subsidiary $37M BEC (2019)

A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…

Incident 2019Read →