Orion S.A., whose principal executive offices are in Spring, Texas, disclosed multiple fraudulent outbound wire transfers in August 2024. The company estimated a one-time pre-tax charge of approximately $60 million for unrecovered funds if no further recovery occurred. That was a conditional estimate, not confirmation that $60 million was ultimately lost.
What Orion disclosed
In a Form 8-K filed with the U.S. Securities and Exchange Commission on August 12, 2024, Orion said it had determined on August 10 that an employee who was not a named executive officer had been targeted by a criminal scheme. The scheme resulted in multiple fraudulently induced outbound wire transfers to accounts controlled by unknown third parties. Orion S.A.’s Form 8-K
Orion is incorporated in Luxembourg; Spring, Texas, is the location of its principal executive offices. Calling it a Texas-based company can describe its headquarters, but it should not be confused with a Texas-incorporated business.
What the $60 million figure means
The filing described an expected one-time pre-tax charge of approximately $60 million for fraudulent wires that remained unrecovered if no further funds were recovered. The figure was a conditional estimate of the charge under that scenario. It was not a statement that the full amount was permanently unrecoverable, nor a final net-loss figure after possible recoveries or insurance.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
Orion said it was cooperating with law enforcement as appropriate and intended to pursue recovery through legally available means, potentially including insurance coverage. The filing did not report the eventual amount recovered or the outcome of an insurance claim.
How the scam worked—and what remains unknown
The filing establishes that the transfers were fraudulently induced, but it does not explain how the employee was persuaded to send them. It does not say whether an attacker compromised email, impersonated an executive or vendor, or used another method. It also does not identify the number of transfers, recipient banks, or receiving accounts.
Business email compromise (BEC) is one general type of payment fraud: criminals may impersonate or compromise someone trusted, such as a colleague, manager, or business partner, to manipulate an employee into sending money or disclosing information. TechCrunch describes those common tactics, but Orion’s filing does not establish that its incident involved BEC or any particular technique. TechCrunch’s August 2024 report on Orion
What Orion said about operations and systems
Orion stated: “The business and operations were not affected.” It also said it had found no evidence of additional fraudulent activity and, at the time, did not believe the incident had resulted in unauthorized access to company data or systems. Those statements reflect the company’s contemporaneous assessment; the filing said its investigation and internal-controls review were ongoing.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #3
How businesses can reduce the risk of fraudulent wires
The following are general safeguards for organizations that make wire payments. They are not claims about controls Orion used or findings from its investigation. TechCrunch’s guidance on protecting startups from email scams recommends careful handling of unusual requests, independent confirmation, formal payment approvals, scrutiny of changed bank details, and stronger account protections. TechCrunch’s general email-scam prevention guidance
- Verify payment instructions independently. For a new payment or changed bank details, call a known contact using a phone number already on file or obtained independently—not a number included in the request. Confirm the amount, recipient, and account details before sending.
- Require structured approvals. Use documented authorization thresholds and more than one approver for significant or unusual payments. Keep payment setup and release responsibilities appropriately separated where practical.
- Apply extra scrutiny to exceptions. Treat urgency, secrecy, changed instructions, or a request to bypass normal procedures as reasons to pause and verify through a trusted channel.
- Protect accounts used for payment workflows. Use multifactor authentication (MFA) or passwordless protections for email and financial systems. A physical FIDO2 security key is one possible account-security measure, but it does not verify wire instructions or replace payment approvals and callbacks.
- Make the process clear and repeatable. Establish written procedures for adding or changing payees, confirming instructions, escalating suspicious requests, and contacting the bank promptly if a transfer may be fraudulent.
Why the headline needs a qualification
Orion disclosed a serious wire-fraud incident and estimated an approximately $60 million pre-tax charge if it recovered no additional funds. The public filing does not establish the exact social-engineering method or the final recovery result, so the amount should not be presented as a confirmed permanent loss.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




