Real Case: How We Proved an Online Fraud Worth €80,000

By Juan Jesús Merino Carretero, chartered computer engineer no. 89 (CPIIEX) online fraud · real case · phishing · computer forensics

Real Case: How We Proved an Online Fraud Worth €80,000

A small industrial company received an email apparently from its financial director requesting an urgent transfer of €80,000 to a “regular” supplier. The email carried the corporate signature, the tone matched that of the executive and it mentioned a project the company really had under way. The transfer was made. Three hours later it was discovered that the email was fake and the money was already out of the account.

This article tells how Forenlab —with the client’s consent and the data anonymized— investigated the case, which forensic evidence was decisive and how the expert report became the basis for the criminal complaint and the subsequent claim against the bank.

The initial situation

The client contacted us 48 hours after the fraud. The destination account had already been partly emptied and the bank refused to accept liability, alleging “client negligence for failing to verify”. The lawyer asked us for an expert report that would demonstrate two things:

  1. That the fraud was highly sophisticated — not a basic negligence by the employee.
  2. That there were security failures reasonably attributable to the bank in detecting suspicious patterns.

Phase 1 — Securing the evidence

The first step was to stop any alteration of the system’s state. Our team traveled to the offices with chain-of-custody equipment and proceeded to:

  • Bit-for-bit cloning of the hard drives of the two people involved (the assistant who made the transfer and the impersonated financial director).
  • Acquisition of the corporate mail server logs (Microsoft 365) for the date range of the incident.
  • Capture of the network and firewall state: connections, NAT, filtering policies.
  • Signing of a chain-of-custody record with the MD5 and SHA-256 hashes of each piece of evidence.

To go deeper into this step, see: digital chain of custody.

Phase 2 — Analysis of the fraudulent email

The email received had the sender [email protected]. However, when analyzing the headers we found:

Received: from mail.servidor-falso.ru ([195.X.X.X])
    by smtp.cliente.com with ESMTPS
    via Microsoft 365 inbound relay;
    Mon, 14 Apr 2026 09:12:38 +0200
From: "Director Financiero" <[email protected]>
Reply-To: [email protected]

Three key elements:

  1. The real Received pointed to a server in Russia, not the company’s corporate server.
  2. The From header was spoofed (a common email spoofing technique).
  3. The Reply-To (a field invisible to the user) redirected to a different domain — one that had been registered 17 days before the fraud.

This last piece of data is decisive. An attacker registered a domain similar to the corporate one, set up email infrastructure and waited three weeks before launching the attack. It is not opportunistic phishing — it is targeted phishing (spear phishing) prepared against the specific company.

If you want to go deeper into how an email is analyzed, read: how to identify the author of an anonymous email.

Phase 3 — The destination account

The bank provided (by court order) the details of the destination account. It was an account opened 22 days before the fraud, at a branch located in a city far from the account holder’s home address, with documentation that the subsequent notarial expert examination showed to have been tampered with.

The transactions were revealing:

  • €80,000 comes in on the day of the fraud.
  • 4 hours later, the account starts a cascade of transfers to 7 different accounts (3 domestic + 4 foreign).
  • Each transaction is below the anti-money-laundering detection threshold (the famous €9,999).
  • Within 18 hours the account is left with a zero balance.

This pattern is so typical of organized laundering networks that the expert report was able to state, with bibliographic support, that the pattern of movements was incompatible with a legitimate account holder.

Phase 4 — The bank’s security failures

This is where the expert report proved decisive for the claim. We documented:

  • The bank did not validate SPF/DMARC on the email’s originating domain (the attacker’s domain had no DMARC and that should have triggered an anti-fraud alert).
  • The transfer pattern (large amount, new beneficiary, recently created account) met three of the five criteria in the bank’s own anti-fraud manual — and yet no alert was generated.
  • The subsequent transfers were processed without any human intervention despite matching a textbook laundering pattern.

Phase 5 — Expert report and outcome

The expert report delivered to the court was 74 pages long, with 12 annexes of technical evidence and a clear conclusion:

The fraud was not the result of basic negligence by the employee, but of a spear phishing attack planned over weeks. There are technical indications, documented with chain of custody, that the bank omitted anti-fraud controls that its own internal manual establishes as mandatory for transactions of this profile.

Outcome of the case

  • Criminal complaint: admitted for processing for computer fraud and forgery of documents. The judicial police are investigating the laundering network in cooperation with Europol.
  • Bank claim: the bank agreed to refund 70% of the amount (€56,000) in out-of-court mediation after reading the expert report. The court claim continues for the remaining 30%.
  • Internal improvements: the company implemented a double-validation protocol for transfers above €5,000.

Lessons learned

This case, far from being exceptional, is increasingly frequent among Spanish small businesses. What sets it apart from similar ones is not the attack itself —which is textbook— but the speed of response:

  • The 48 hours between the fraud and our contact were key: had 7 days passed, several of the bank’s logs would no longer have been available under its retention policy.
  • The immediate cloning of the devices preserved the browser files and DNS cache that helped reconstruct the timeline.
  • Filing the criminal complaint at the same time as the civil claim multiplied the pressure on the bank to reach an agreement.

If your company wants to prevent it

Three measures, in order of impact:

  1. Double human validation for transfers above a threshold (recommended: €3,000 for small businesses).
  2. DMARC with a reject policy on your corporate domain. This physically blocks your own domain from being spoofed in emails.
  3. Quarterly training for staff with real targeted-phishing drills — not generic ones, but using your company’s own data.

If you want us to assess your company’s risk before anything happens, we can carry out a preliminary audit that includes analysis of your DMARC status, staff exposure on social media (the classic vector for spear phishing) and a review of the financial protocol. See more under expert witness services or contact us directly for an initial assessment with no obligation.