A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019 after acting on fraudulent payment-change instructions.
Reviewed by the Social Engineering Examples team.
On 14 August 2019, a European subsidiary of Toyota Boshoku Corporation was tricked into transferring funds to an attacker-controlled bank account on the basis of what the company called "fraudulent payment directions from a malicious third party." The parent company disclosed the incident in a first-party press release on 6 September 2019, estimating a maximum expected loss of about 4 billion yen (roughly $37.5 million). Toyota Boshoku and the subsidiary recognized the payment directions were fraudulent shortly after the funds left, assembled a team of legal professionals, reported the loss to local investigating authorities, and began efforts to secure and recover the money. The company noted it might need to amend its March 2020 earnings forecast if funds were not recovered. Citing the confidentiality of the ongoing criminal investigation, Toyota Boshoku released no technical details about the attacker's entry vector, whether a mailbox was hijacked or an identity impersonated, or how much (if any) was ultimately recovered.
This was a business email compromise (BEC): fraudsters used deceptive email to direct finance staff to send a large payment to an account the criminals controlled. Public disclosures do not specify whether the attackers hijacked a legitimate mailbox or impersonated a trusted party (e.g. an executive or supplier), but the outcome fit the classic BEC pattern: an apparently authoritative, routine-looking instruction to move or redirect funds that a staffer with payment authority accepted as genuine. The loss reportedly involved changed account details on an electronic funds transfer. No malware exploit or system takeover was reported as the cause; the leverage was social engineering of a person, not a technical breach.
Lure: a payment or account-change instruction that looked legitimate and routine to a finance staffer, exploiting trust in an apparently authoritative sender. Tells (general to BEC, not confirmed specifics of this case): a request to change existing bank/account details, pressure to act quickly, and instructions that bypass normal verification, any of which should trigger an out-of-band callback to a known contact before money moves.
Up to ~4 billion yen (~$37.5M) transferred out before the fraud was caught. The company reported the loss to local authorities, opened a criminal investigation, engaged legal professionals, and pursued fund recovery; it warned of a possible earnings-forecast revision. Amount recovered and any perpetrator identification were not publicly disclosed.
A ~$37M single-transfer loss at a subsidiary of a major, sophisticated multinational shows BEC succeeds through people and process gaps, not necessarily technical defenses. Large distributed enterprises are especially exposed at foreign subsidiaries where payment approval, verification norms, and reporting lines can be looser. The case is a benchmark example of BEC scale and of the value of segregation of duties and independent verification on payment changes.
Require out-of-band verification (callback to a pre-known number) for any new payee or change to existing bank details. Enforce segregation of duties and multi-person approval for large transfers so no single employee can initiate and authorize a payment. Set escalating thresholds for wire approvals. Train finance and AP staff to treat account-change requests as high-risk regardless of apparent sender authority. Harden email against account takeover (MFA, anti-phishing at the mail gateway, external-sender and lookalike-domain flags). Pre-establish an incident playbook including immediate bank/law-enforcement notification (e.g. IC3 in the US) to maximize the chance of freezing/recovering funds.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money…