Nikkei America, Inc. reported that an employee transferred approximately US$29 million (about ¥3.2 billion) in late September 2019 after receiving fraudulent instructions from someone posing as a Nikkei management executive. The public account does not say whether the employee’s email was hacked or explain how the instructions were delivered. It does show why businesses should verify unusual payment requests through a known, independent channel—and move quickly if a transfer is unauthorized.
How did the Nikkei BEC scam work?
According to BleepingComputer’s November 1, 2019 report quoting Nikkei’s disclosure, an employee of Nikkei America, Inc., a New York-based subsidiary of Nikkei Inc., received fraudulent instructions from a third party purporting to be a Nikkei management executive. The employee transferred the money in late September 2019.
This fits the broad pattern known as business email compromise (BEC), also called email account compromise (EAC): a criminal uses a message that appears to come from a familiar person or organization to prompt a seemingly legitimate action. In a payment-diversion scam, that action may be sending money to an account controlled by the criminal. The FBI says such schemes can involve a spoofed email account or website, spear-phishing to steal credentials, or malware that exposes real email threads. Those are possible BEC methods, not established details of the Nikkei incident.
How much money did Nikkei lose?
The amount reported was approximately US$29 million, equivalent at the time to approximately ¥3.2 billion. The company’s disclosure, as quoted by BleepingComputer, said it had notified authorities in the United States and Hong Kong, retained lawyers to confirm the facts, and was cooperating with investigations. It declined to provide further details at the time to preserve confidentiality of the authorities’ investigation. The contemporaneous report described recovery efforts as ongoing; it did not establish whether any funds were ultimately recovered.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Was Nikkei’s email hacked?
The public account does not establish that. It says a third party sent instructions while purporting to be a Nikkei management executive, but does not explain whether the sender spoofed an address, took over a genuine account, used another communication channel, or relied on some other method. Impersonation alone is not proof of mailbox compromise, so claims that a particular employee account was hacked or that a particular phishing technique was used go beyond what the report supports.
How can a company prevent business email compromise?
No single control guarantees that a company will avoid BEC. The most useful defenses address three separate risks: confirming who is making a request, independently validating the payment, and detecting suspicious email activity. FBI and IC3 recommendations include the following:
Rank #2
Verify payment instructions outside the message thread
- Confirm a new bank-account number, changed payment procedure, or urgent payment request using a phone number or other contact method already on file—not details supplied in the suspicious message.
- For high-value payments or sensitive changes, require a second authorized person to approve the transaction under a documented process. This adds an organizational check alongside the independent verification recommended by the FBI.
- Train staff to pause when a request is unexpected, urgent, or asks them to bypass normal procedures, even if it appears to come from a senior executive or familiar business partner.
Protect accounts and monitor email settings
- Enable multi-factor authentication (MFA) wherever available. MFA can make a stolen password less useful, though it does not replace payment verification.
- Apply anti-phishing and anti-spoofing protections, including SPF, DKIM, and DMARC, and make outside-sender messages visible to employees.
- Prohibit automatic forwarding of company email to external addresses, log mailbox-setting changes, and alert on suspicious account activity.
These account and email-administration measures are among the recommendations in IC3’s April 2020 cloud-email advisory. They are general safeguards, not evidence that any one control would have prevented the Nikkei transfer. If implementing MFA with a hardware security key, check that the company’s identity or email provider supports the chosen key and authentication method.
What should you do after a fraudulent wire transfer?
- Call the sending financial institution immediately. Ask it to contact the receiving institution and request a recall or other action to try to stop or recover the transfer. The FBI’s BEC guidance says: “You should also contact your financial institution immediately and request that they contact the financial institution where any transfer was sent.”
- Report the incident promptly. File a report with the FBI Internet Crime Complaint Center (IC3) or contact the local FBI field office. Preserve messages, payment instructions, account details, and transaction records that may help investigators.
- Secure affected accounts and processes. If there are signs of account access or changed mailbox settings, involve the organization’s IT or security team to investigate, revoke unauthorized access, and review forwarding rules and credentials. Keep payment staff informed so that any related requests can be independently checked.
Fast reporting may give financial institutions and investigators a chance to act, but it does not guarantee that a transfer will be recovered.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
How common was BEC in the FBI’s 2019 figures?
In a 2019 public service announcement, IC3 reported 166,349 domestic and international BEC/EAC complaints and $26,201,775,589 in exposed dollar losses for complaints filed from June 2016 through July 2019. IC3’s exposed-loss figure includes both actual and attempted losses, so it should not be read as money confirmed stolen. The same announcement said the complaints involved all 50 U.S. states and 177 countries, and that fraudulent transfers were sent to at least 140 countries. These are historical figures for that reporting period, not a measure of current prevalence.
Japan-focused context also appears in JPCERT/CC’s 2020 English-language survey. It describes BEC examples including forged partner invoices, business-manager impersonation, and fraudulent use of compromised email accounts. The survey notes that suspicious cases were often detected during email exchanges and describes checking with the counterparty by a channel other than email, such as telephone or messaging, as a way losses were avoided. Those findings are examples from that survey, not a universal rate or guarantee.
Quick Recap
Best Value
- This fun, nerdy, geeky, retro Cybersecurity Awareness Month design is perfect to wear this October. Great for cyber security professionals and experts who keep people safe on the internet, safe online, and safe online.
- Wear this for October National Cyber Security Awareness Month this October, raise awareness about cyber security on smartphones, laptops at your school, in the classroom or on your college or university campus. Be safe online and make sure others are too!
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




