How FACC lost 50 million euros to a fake CEO email, and why the real CEO was fired
An aircraft parts maker that supplies Airbus and Boeing lost about 50 million euros because an employee believed emails from the chief executive, who had never sent them.[1] Within months both the finance chief and the real CEO were out of their jobs. This case file covers how the scam worked, what it cost, and the one control that would have stopped it.
What happened
FACC is an Austrian company that began as a ski maker and grew into a supplier of aircraft parts for customers such as Airbus, Boeing and Rolls-Royce.[1] Around the end of 2015, criminals targeted its finance operation with what the company calls a fake president scheme.[2]
An employee received email instructions that appeared to come from the CEO and, following them, transferred about 50 million euros out of the company.[1] By the time anyone realized the orders were fake, the money had moved on through accounts in Slovakia and Asia.[1] The company disclosed the fraud in January 2016.[1]
In February 2016 the finance chief was dismissed over the incident. On May 25, 2016, the supervisory board removed the CEO, who had led the company for 17 years, with immediate effect, saying he had seriously breached his duties in connection with the fraud.[1][3] Neither executive was accused of taking part in the scam itself.[1]
How it worked
Fake president fraud, also called CEO fraud or business email compromise, does not need anyone to break into a computer. The criminals pose as a senior executive, usually by email, and ask a finance employee to make an urgent payment. The request often comes with a believable story, such as a confidential acquisition, and a warning to keep it quiet.
Those 2 ingredients, authority and secrecy, are what make the scheme work. An employee who thinks the CEO personally asked for a confidential transfer is unlikely to question it or tell colleagues. If the company lets one person release a large payment on the strength of a message, nothing stands between the fake request and the bank.
Once the first transfer lands, the criminals move the money quickly through a chain of accounts in different countries. Every hop makes it harder for banks and police to trace and freeze.[1]
What it cost
FACC booked a loss of 41.9 million euros from the fraud in its 2015/16 business year, after about 10.9 million euros was frozen before it could be moved on. The incident helped push the company to a pretax loss of 23.4 million euros for that year.[1] The roughly 50 million euros taken was about 10% of annual revenue.[1]
Getting the frozen money back took almost a decade. About 10.8 million euros had been frozen in Chinese accounts in early 2016, was transferred to a court in Vienna in 2019, and was finally paid to FACC at the end of March 2025. The company said the long delay came from international cooperation between several authorities and complex legal questions.[2]
The human cost was also high. The company removed its finance chief and its long-serving CEO, and later went to court seeking millions in damages from its 2 former executives.[1][4]
The missing control
The missing control: dual approval for large wires. Any transfer above a set amount should need sign-off from a second person, and a request that claims to come from an executive should be confirmed with that executive through a separate channel.
This would have stopped the fraud at the first payment. A second approver who was not under the same pressure would have asked the obvious questions: why is this payment going to an unfamiliar account abroad, and has anyone actually spoken to the CEO? A phone call to the real CEO would have ended the scheme in minutes. Instead, a single employee acting on email alone could move tens of millions of euros.
What to do in your business
- Set a 2-person rule. Pick a dollar amount, and require a second person to approve any payment above it. Make the rule apply to owners and executives too.
- Confirm executive requests by phone. If a payment request claims to come from the boss, call the boss on a known number before paying. Never use contact details from the request.
- Treat secrecy as a red flag. Tell staff plainly that no real executive will ever ask them to keep a payment secret from the finance team. That request alone should trigger a check.
- Check new bank accounts. Any payment to an account you have never paid before, especially overseas, gets extra review.
- Know your bank's fraud line. If a bad payment goes out, call the bank immediately. Speed is what lets money be frozen before it moves on.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to stop fake invoices, changed bank details and fake-boss payment requests
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How Google and Facebook were scammed: the fake supplier invoices
- The Arup deepfake scam: the $25 million video call where everyone else was fake
- The first known AI voice scam: how a fake boss's call took $243,000
- The Bitfinex hack: how 119,754 bitcoin walked out, then sat still for 5 years
- How a fake Google support call stole 4,100 bitcoin from one person
- Every payments and fraud control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- The Local Austria: Austrian firm fires CEO after 50-million-euro cyber scam
- FACC: Fake President Incident, FACC received EUR 10.8 million in frozen funds back
- FACC: EANS Adhoc, CEO was revoked from the management board with immediate effect
- Industriemagazin: FACC, Millionenklage gegen zwei eigene Ex-Vorstände