
The situation
A mid-sized manufacturing company fell victim to a business email compromise (BEC). Fraudsters monitored the company’s email for weeks, then sent a convincing invoice that appeared to come from a long-standing supplier, with updated “new bank details.” The accounts team paid two invoices totalling $118,000 before the genuine supplier asked why it hadn’t been paid.
What ALTHEON did
In wire-fraud cases the first 24 to 72 hours are decisive. We moved immediately on parallel tracks.
- Helped the company trigger a SWIFT recall and a bank-to-bank fraud notification the same day the loss was discovered.
- Coordinated with the receiving bank’s fraud department to flag and freeze the beneficiary account.
- Reconstructed the BEC timeline from email headers to prove the payments were induced by fraud, strengthening the recall claim.
- Advised on immediate security hardening so the compromise could not be used to redirect further payments.
The outcome
The first payment, made nine days earlier, had largely been moved on — but the second payment of $71,000 was still sitting in the beneficiary account. The receiving bank froze it on the strength of our documented fraud claim, and the funds were returned to the company. A partial recovery of the first payment followed through the bank’s indemnity process.
Prevention going forward
We helped the firm introduce a call-back verification policy for any change of supplier bank details. The single most effective control against BEC is a mandatory phone confirmation — using a number you already hold on file, never one from the suspicious email.
Think you have a recoverable case?
Speak with an ALTHEON recovery specialist. We assess your case confidentially and explain your realistic options for getting your money back — no obligation.
Book a Free Consultation Contact Us