Fraudsters Use Fake NDAs to Extract Over €600,000 from European Firm
A coordinated cyber‑crime operation succeeded in siphoning €626,735.45 from a European corporation after scammers forged non‑disclosure agreements and pretended to be senior executives from both the target company and a well‑known consulting firm.
The attackers conducted a classic business‑email‑compromise (BEC) campaign, first gaining access to internal email threads before impersonating high‑level personnel. By sending a seemingly authentic NDA that referenced ongoing negotiations, they isolated a legal department employee who was responsible for contract review. The forged document demanded confidentiality about a “confidential partnership,” creating a sense of urgency and authority that compelled the employee to comply with the scammers' instructions.
Following the employee’s confirmation, the fraudsters directed the finance team to transfer the sum to a bank account registered in Hong Kong. The payment request was framed as a final settlement for the alleged partnership, with the scammers providing counterfeit invoices and a fabricated corporate seal to reinforce legitimacy. The transaction was completed before the company’s internal controls flagged the irregularity, allowing the funds to leave the corporate account and disappear into the offshore account.
This incident mirrors a growing trend in which cybercriminals blend social engineering with forged legal paperwork to bypass traditional verification steps. According to recent industry reports, BEC scams have risen sharply in Europe, with attackers increasingly leveraging seemingly benign documents such as NDAs, service agreements, and board resolutions to create a veneer of legitimacy. The use of a Hong Kong‑based beneficiary is also notable, as the jurisdiction is frequently exploited for its relatively opaque banking environment, making traceability and recovery of stolen assets more difficult.
Law enforcement agencies and cybersecurity firms are urging companies to reinforce verification protocols, especially for requests involving large sums or changes to payment details. Recommendations include multi‑factor authentication for email accounts, mandatory secondary approvals for any financial transfer, and direct phone verification with known executives. The affected firm has reported the breach to the relevant authorities and is cooperating with investigators to trace the funds, while also reviewing its internal controls to prevent similar attacks in the future.
Comments (0)
Be the first to comment.
Join the discussion