Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

How Nikkei America Lost About $29 Million in a Reported BEC Scam

Nikkei America reported that an employee transferred approximately $29 million after receiving instructions from someone posing as a management executive. The public account does not establish whether an email account was compromised.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Nikkei America, Inc. reported that an employee transferred approximately US$29 million (about ¥3.2 billion) in late September 2019 after receiving fraudulent instructions from someone posing as a Nikkei management executive. The public account does not say whether the employee’s email was hacked or explain how the instructions were delivered. It does show why businesses should verify unusual payment requests through a known, independent channel—and move quickly if a transfer is unauthorized.

How did the Nikkei BEC scam work?

According to BleepingComputer’s November 1, 2019 report quoting Nikkei’s disclosure, an employee of Nikkei America, Inc., a New York-based subsidiary of Nikkei Inc., received fraudulent instructions from a third party purporting to be a Nikkei management executive. The employee transferred the money in late September 2019.

This fits the broad pattern known as business email compromise (BEC), also called email account compromise (EAC): a criminal uses a message that appears to come from a familiar person or organization to prompt a seemingly legitimate action. In a payment-diversion scam, that action may be sending money to an account controlled by the criminal. The FBI says such schemes can involve a spoofed email account or website, spear-phishing to steal credentials, or malware that exposes real email threads. Those are possible BEC methods, not established details of the Nikkei incident.

How much money did Nikkei lose?

The amount reported was approximately US$29 million, equivalent at the time to approximately ¥3.2 billion. The company’s disclosure, as quoted by BleepingComputer, said it had notified authorities in the United States and Hong Kong, retained lawyers to confirm the facts, and was cooperating with investigations. It declined to provide further details at the time to preserve confidentiality of the authorities’ investigation. The contemporaneous report described recovery efforts as ongoing; it did not establish whether any funds were ultimately recovered.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was Nikkei’s email hacked?

The public account does not establish that. It says a third party sent instructions while purporting to be a Nikkei management executive, but does not explain whether the sender spoofed an address, took over a genuine account, used another communication channel, or relied on some other method. Impersonation alone is not proof of mailbox compromise, so claims that a particular employee account was hacked or that a particular phishing technique was used go beyond what the report supports.

How can a company prevent business email compromise?

No single control guarantees that a company will avoid BEC. The most useful defenses address three separate risks: confirming who is making a request, independently validating the payment, and detecting suspicious email activity. FBI and IC3 recommendations include the following:

Verify payment instructions outside the message thread

  • Confirm a new bank-account number, changed payment procedure, or urgent payment request using a phone number or other contact method already on file—not details supplied in the suspicious message.
  • For high-value payments or sensitive changes, require a second authorized person to approve the transaction under a documented process. This adds an organizational check alongside the independent verification recommended by the FBI.
  • Train staff to pause when a request is unexpected, urgent, or asks them to bypass normal procedures, even if it appears to come from a senior executive or familiar business partner.

Protect accounts and monitor email settings

  • Enable multi-factor authentication (MFA) wherever available. MFA can make a stolen password less useful, though it does not replace payment verification.
  • Apply anti-phishing and anti-spoofing protections, including SPF, DKIM, and DMARC, and make outside-sender messages visible to employees.
  • Prohibit automatic forwarding of company email to external addresses, log mailbox-setting changes, and alert on suspicious account activity.

These account and email-administration measures are among the recommendations in IC3’s April 2020 cloud-email advisory. They are general safeguards, not evidence that any one control would have prevented the Nikkei transfer. If implementing MFA with a hardware security key, check that the company’s identity or email provider supports the chosen key and authentication method.

What should you do after a fraudulent wire transfer?

  1. Call the sending financial institution immediately. Ask it to contact the receiving institution and request a recall or other action to try to stop or recover the transfer. The FBI’s BEC guidance says: “You should also contact your financial institution immediately and request that they contact the financial institution where any transfer was sent.”
  2. Report the incident promptly. File a report with the FBI Internet Crime Complaint Center (IC3) or contact the local FBI field office. Preserve messages, payment instructions, account details, and transaction records that may help investigators.
  3. Secure affected accounts and processes. If there are signs of account access or changed mailbox settings, involve the organization’s IT or security team to investigate, revoke unauthorized access, and review forwarding rules and credentials. Keep payment staff informed so that any related requests can be independently checked.

Fast reporting may give financial institutions and investigators a chance to act, but it does not guarantee that a transfer will be recovered.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How common was BEC in the FBI’s 2019 figures?

In a 2019 public service announcement, IC3 reported 166,349 domestic and international BEC/EAC complaints and $26,201,775,589 in exposed dollar losses for complaints filed from June 2016 through July 2019. IC3’s exposed-loss figure includes both actual and attempted losses, so it should not be read as money confirmed stolen. The same announcement said the complaints involved all 50 U.S. states and 177 countries, and that fraudulent transfers were sent to at least 140 countries. These are historical figures for that reporting period, not a measure of current prevalence.

Japan-focused context also appears in JPCERT/CC’s 2020 English-language survey. It describes BEC examples including forged partner invoices, business-manager impersonation, and fraudulent use of compromised email accounts. The survey notes that suspicious cases were often detected during email exchanges and describes checking with the counterparty by a channel other than email, such as telephone or messaging, as a way losses were avoided. Those findings are examples from that survey, not a universal rate or guarantee.

Quick Recap

SaleBestseller No. 2
SaleBestseller No. 4
Bestseller No. 5
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
Lightweight, Classic fit, Double-needle sleeve and bottom hem
$17.99
Best Value
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
  • This fun, nerdy, geeky, retro Cybersecurity Awareness Month design is perfect to wear this October. Great for cyber security professionals and experts who keep people safe on the internet, safe online, and safe online.
  • Wear this for October National Cyber Security Awareness Month this October, raise awareness about cyber security on smartphones, laptops at your school, in the classroom or on your college or university campus. Be safe online and make sure others are too!
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.