A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019 after acting on fraudulent.
Social Engineering Examples·6 sources
On 14 August 2019, a European subsidiary of Toyota Boshoku Corporation was tricked into transferring funds to an attacker-controlled bank account on the basis of what the company called "fraudulent payment directions from a malicious third party." The parent company disclosed the incident in a first-party press release on 6 September 2019, estimating a maximum expected loss of about 4 billion yen (roughly $37.5 million).
Toyota Boshoku and the subsidiary recognized the payment directions were fraudulent shortly after the funds left, assembled a team of legal professionals, reported the loss to local investigating authorities, and began efforts to secure and recover the money. The company noted it might need to amend its March 2020 earnings forecast if funds were not recovered.
Citing the confidentiality of the ongoing criminal investigation, Toyota Boshoku released no technical details about the attacker's entry vector, whether a mailbox was hijacked or an identity impersonated, or how much (if any) was ultimately recovered.
This was a business email compromise (BEC): fraudsters used deceptive email to direct finance staff to send a large payment to an account the criminals controlled. Public disclosures do not specify whether the attackers hijacked a legitimate mailbox or impersonated a trusted party (e.g. an executive or supplier), but the outcome fit the classic BEC pattern: an apparently authoritative, routine-looking instruction to move or redirect funds that a staffer with payment authority accepted as genuine.
The loss reportedly involved changed account details on an electronic funds transfer. No malware exploit or system takeover was reported as the cause; the leverage was social engineering of a person, not a technical breach.
Lure: a payment or account-change instruction that looked legitimate and routine to a finance staffer, exploiting trust in an apparently authoritative sender. Tells (general to BEC, not confirmed specifics of this case): a request to change existing bank/account details, pressure to act quickly, and instructions that bypass normal verification, any of which should trigger an out-of-band callback to a known contact before money moves.
Up to ~4 billion yen (~$37.5M) transferred out before the fraud was caught. The company reported the loss to local authorities, opened a criminal investigation, engaged legal professionals, and pursued fund recovery; it warned of a possible earnings-forecast revision. Amount recovered and any perpetrator identification were not publicly disclosed.
A ~$37M single-transfer loss at a subsidiary of a major, sophisticated multinational shows BEC succeeds through people and process gaps, not necessarily technical defenses. Large distributed enterprises are especially exposed at foreign subsidiaries where payment approval, verification norms, and reporting lines can be looser. The case is a benchmark example of BEC scale and of the value of segregation of duties and independent verification on payment changes.
Require out-of-band verification (callback to a pre-known number) for any new payee or change to existing bank details. Enforce segregation of duties and multi-person approval for large transfers so no single employee can initiate and authorize a payment. Set escalating thresholds for wire approvals. Train finance and AP staff to treat account-change requests as high-risk regardless of apparent sender authority.
Harden email against account takeover (MFA, anti-phishing at the mail gateway, external-sender and lookalike-domain flags). Pre-establish an incident playbook including immediate bank/law-enforcement notification (e.g. IC3 in the US) to maximize the chance of freezing/recovering funds.
Social Engineering Examples. “Toyota Boshoku European Subsidiary $37M BEC (2019)”. Accessed 19 September 2026. https://socialengineeringexamples.com/toyota-boshoku-europe-bec-37m-2019
BEC operators typically research a target company's corporate structure, subsidiaries, suppliers, and finance staff using sources like LinkedIn, company websites, business registries, and prior data breaches or leaked email traffic, looking for a plausible existing payment relationship (a real vendor, a real internal approval chain) to imitate. No technical detail on this stage was disclosed in Toyota Boshoku's case, so this is inferred from how BEC schemes of this kind are typically built, not confirmed fact of this specific incident.
Public corporate and staff information (subsidiary structure, finance-team roles on LinkedIn) is very hard to eliminate at enterprise scale; the realistic control assumes attackers can find it and hardens the payment-approval process it gets used against, rather than trying to hide it.
Attackers typically prepare the delivery mechanism, commonly a compromised or spoofed mailbox, or a look-alike domain resembling a real supplier or executive's address, so the fraudulent instruction arrives through a channel the finance team already trusts. Toyota Boshoku did not disclose whether a mailbox was hijacked or an identity was spoofed.
Harden email against account takeover with MFA and anti-phishing controls at the mail gateway, and configure automated flags for external-sender and lookalike-domain messages so a spoofed or hijacked source is more likely to be caught before it reaches finance staff.
The European subsidiary received what the company described as fraudulent payment directions from a malicious third party, consistent with a BEC message instructing finance staff to redirect an existing payment or change bank account details for a transaction that looked routine and authoritative.
Train finance and accounts-payable staff to treat any request to change existing bank or account details as inherently high-risk, regardless of how authoritative or routine the sender appears.
A staffer with payment authority accepted the instruction as genuine without an independent, out-of-band check against a previously known contact or number, the single point of failure common to nearly all successful BEC losses of this scale.
Require mandatory out-of-band verification, a callback to a pre-known, independently sourced number, for any new payee or any change to existing bank details, with no exception for apparent seniority or urgency.
The subsidiary wired approximately 4 billion yen (~$37.5M) to a bank account controlled by the attackers, completing the fraud before the company recognized the directions were false.
Enforce segregation of duties and multi-person approval with escalating thresholds for large wires, so no single employee can both initiate and authorize a payment of this size.
Once received, BEC proceeds are typically moved rapidly through a chain of mule or intermediary accounts to frustrate freezing and recovery; Toyota Boshoku did not disclose how much, if any, of the transferred funds were ultimately recovered.
Pre-establish an incident playbook with immediate bank and law-enforcement notification (e.g. IC3 in the US, or the equivalent local authority) so a bank freeze can be requested within the narrow window before funds are laundered out of reach; this was reflected in Toyota Boshoku's actual response of promptly engaging legal counsel and local investigators.
Browse by what this case has in common with others in the library.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
Advance Machine Company's West Coast sales manager repeatedly rifled Tennant Company's sealed, covered dumpster in California to steal sales leads.
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO demanded an urgent transfer.
Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.
A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…