Case Library / Phishing / Toyota Boshoku European Subsidiary $37M BEC (2019)
Phishing Confirmed

Toyota Boshoku European Subsidiary $37M BEC (2019)

A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019 after acting on fraudulent payment-change instructions.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On 14 August 2019, a European subsidiary of Toyota Boshoku Corporation was tricked into transferring funds to an attacker-controlled bank account on the basis of what the company called "fraudulent payment directions from a malicious third party." The parent company disclosed the incident in a first-party press release on 6 September 2019, estimating a maximum expected loss of about 4 billion yen (roughly $37.5 million). Toyota Boshoku and the subsidiary recognized the payment directions were fraudulent shortly after the funds left, assembled a team of legal professionals, reported the loss to local investigating authorities, and began efforts to secure and recover the money. The company noted it might need to amend its March 2020 earnings forecast if funds were not recovered. Citing the confidentiality of the ongoing criminal investigation, Toyota Boshoku released no technical details about the attacker's entry vector, whether a mailbox was hijacked or an identity impersonated, or how much (if any) was ultimately recovered.

How the Attack Worked

This was a business email compromise (BEC): fraudsters used deceptive email to direct finance staff to send a large payment to an account the criminals controlled. Public disclosures do not specify whether the attackers hijacked a legitimate mailbox or impersonated a trusted party (e.g. an executive or supplier), but the outcome fit the classic BEC pattern: an apparently authoritative, routine-looking instruction to move or redirect funds that a staffer with payment authority accepted as genuine. The loss reportedly involved changed account details on an electronic funds transfer. No malware exploit or system takeover was reported as the cause; the leverage was social engineering of a person, not a technical breach.

The Lure & the Tell

Lure: a payment or account-change instruction that looked legitimate and routine to a finance staffer, exploiting trust in an apparently authoritative sender. Tells (general to BEC, not confirmed specifics of this case): a request to change existing bank/account details, pressure to act quickly, and instructions that bypass normal verification, any of which should trigger an out-of-band callback to a known contact before money moves.

Outcome

Up to ~4 billion yen (~$37.5M) transferred out before the fraud was caught. The company reported the loss to local authorities, opened a criminal investigation, engaged legal professionals, and pursued fund recovery; it warned of a possible earnings-forecast revision. Amount recovered and any perpetrator identification were not publicly disclosed.

Why It Matters

A ~$37M single-transfer loss at a subsidiary of a major, sophisticated multinational shows BEC succeeds through people and process gaps, not necessarily technical defenses. Large distributed enterprises are especially exposed at foreign subsidiaries where payment approval, verification norms, and reporting lines can be looser. The case is a benchmark example of BEC scale and of the value of segregation of duties and independent verification on payment changes.

Defenses

Require out-of-band verification (callback to a pre-known number) for any new payee or change to existing bank details. Enforce segregation of duties and multi-person approval for large transfers so no single employee can initiate and authorize a payment. Set escalating thresholds for wire approvals. Train finance and AP staff to treat account-change requests as high-risk regardless of apparent sender authority. Harden email against account takeover (MFA, anti-phishing at the mail gateway, external-sender and lookalike-domain flags). Pre-establish an incident playbook including immediate bank/law-enforcement notification (e.g. IC3 in the US) to maximize the chance of freezing/recovering funds.

Sources
  • Discovery of European subsidiary being subject of fraud (News Release). Toyota Boshoku Corporation Primary. First-party press release, 6 Sep 2019, confirming fraudulent payment directions, 14 Aug incident date, ~4 billion yen max expected loss, and law-enforcement referral. Verified by direct fetch: content matches exactly.
  • 当社欧州子会社における資金流出事案について (News Release, Japanese). Toyota Boshoku Corporation Primary. Japanese-language original of the same disclosure; states max ~4.0 billion yen loss, 14 Aug incident date. Verified by direct fetch: content matches.
  • Over $37 Million Lost by Toyota Boshoku Subsidiary in BEC Scam. BleepingComputer Secondary. Corroborates $37.47M / EUR33.9M figure; includes later company spokesperson statement on disclosure timing and recovery efforts. Verified by direct fetch.
  • Toyota Subsidiary Suffers $37m BEC Loss. Infosecurity Magazine Secondary. Corroborates loss and details; includes expert commentary on segregation-of-duties defenses. Verified by direct fetch.
  • Toyota Parts Supplier Loses $37 Million in Email Scam. Tripwire (State of Security) Secondary. Confirms transfer to criminal-controlled account and situates the case in broader BEC threat context. Verified by direct fetch.
  • Toyota supplier scammed out of $37 million. Automotive News Secondary. Industry-trade corroboration of the $37M loss. Direct fetch returned only site navigation (likely paywalled/JS-gated); a follow-up web search snippet confirmed genuine matching article content (correct headline, publish date 2019-09-07, and real body text referencing Toyota Boshoku's global supplier ranking), so the source is a real, on-topic, non-dead link, though the file's original claim of verified 'company statement quotes' from this specific source could not be independently confirmed from fetched text.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target and payment-flow reconnaissance: BEC operators typically research a target company's corporate structure, subsidiaries, suppliers, and finance staff using sources like LinkedIn, company websites, business registries, and prior data breaches or leaked email traffic, looking for a plausible existing payment relationship (a real vendor, a real internal approval chain) to imitate. No technical detail on this stage was disclosed in Toyota Boshoku's case, so this is inferred from how BEC schemes of this kind are typically built, not confirmed fact of this specific incident.
Countering Stage 1: Public corporate and staff information (subsidiary structure, finance-team roles on LinkedIn) is very hard to eliminate at enterprise scale; the realistic control assumes attackers can find it and hardens the payment-approval process it gets used against, rather than trying to hide it.
2
Pretext and channel setup: Attackers typically prepare the delivery mechanism, commonly a compromised or spoofed mailbox, or a look-alike domain resembling a real supplier or executive's address, so the fraudulent instruction arrives through a channel the finance team already trusts. Toyota Boshoku did not disclose whether a mailbox was hijacked or an identity was spoofed.
Countering Stage 2: Harden email against account takeover with MFA and anti-phishing controls at the mail gateway, and configure automated flags for external-sender and lookalike-domain messages so a spoofed or hijacked source is more likely to be caught before it reaches finance staff.
3
Fraudulent payment-change instruction: The European subsidiary received what the company described as fraudulent payment directions from a malicious third party, consistent with a BEC message instructing finance staff to redirect an existing payment or change bank account details for a transaction that looked routine and authoritative.
Countering Stage 3: Train finance and accounts-payable staff to treat any request to change existing bank or account details as inherently high-risk, regardless of how authoritative or routine the sender appears.
4
Verification bypass: A staffer with payment authority accepted the instruction as genuine without an independent, out-of-band check against a previously known contact or number, the single point of failure common to nearly all successful BEC losses of this scale.
Countering Stage 4: Require mandatory out-of-band verification, a callback to a pre-known, independently sourced number, for any new payee or any change to existing bank details, with no exception for apparent seniority or urgency.
5
Payout: The subsidiary wired approximately 4 billion yen (~$37.5M) to a bank account controlled by the attackers, completing the fraud before the company recognized the directions were false.
Countering Stage 5: Enforce segregation of duties and multi-person approval with escalating thresholds for large wires, so no single employee can both initiate and authorize a payment of this size.
6
Cash-out and laundering: Once received, BEC proceeds are typically moved rapidly through a chain of mule or intermediary accounts to frustrate freezing and recovery; Toyota Boshoku did not disclose how much, if any, of the transferred funds were ultimately recovered.
Countering Stage 6: Pre-establish an incident playbook with immediate bank and law-enforcement notification (e.g. IC3 in the US, or the equivalent local authority) so a bank freeze can be requested within the narrow window before funds are laundered out of reach; this was reflected in Toyota Boshoku's actual response of promptly engaging legal counsel and local investigators.
Quick Facts
Victim
Toyota Boshoku Corporation (unnamed European subsidiary), automotive seating and interior components maker, part of the Toyota Group; HQ Kariya, Japan (TSE:3116)
Location
European subsidiary (specific country not disclosed); parent HQ Kariya, Japan
Date
2019-08-14
Impact
Expected loss of up to approximately 4 billion yen (~$37.5M / EUR33.9M) as of 5 September 2019; recovery efforts underway, amount recovered not disclosed
Status
Confirmed
Case Type
Real-World Incident
Sector
Manufacturing & Industrial
Related

Related Cases

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…

Incident 2018Read →

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…

Incident 2018Read →

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money…

Incident 2020Read →