Office desk lit by warm lamp with a laptop, old-style phone, and papers including a large $37,000 amount; window shows palm trees at dusk, creating a blue, moody atmosphere.

Welcome to Cyber Horror Stories, our new series (just in time for spooky season). Four true disasters, told campfire-style, each one ending with the fix that would have stopped it cold. First up: the email that looked exactly right.


Picture this: it’s August 2019, inside the European finance office of Toyota Boshoku, one of Toyota’s own auto parts suppliers. An email lands from someone the finance team trusts, a business partner they’ve corresponded with before, referencing a payment that needs to move. Nothing about it feels wrong. The tone is right, the request is routine, and the numbers on the wire form match exactly what’s been asked for.

The transfer goes through. Roughly 4 billion yen, more than $37 million, leaves the company and lands in an account that belongs to no one Toyota has ever done business with.

By the time anyone realized what happened, the money was gone.

The Ghost in the Wire Transfer

No malware, no breach, no alarm anyone could have caught, just an email that looked like it came from someone real, at the exact moment a large transfer was already expected. Toyota Boshoku’s own statement called it “fraudulent payment directions from a malicious third party,” a polite way of saying someone convincing asked for money, and someone trusted the ask. The company built a legal and investigative team within days and reported the loss to authorities, but recovering wired international funds after the fact is close to a lost cause. The loss was large enough that Toyota flagged it might affect the subsidiary’s earnings forecast for the year.

This Nightmare Never Ended

This is not a 2019 problem. BEC cost U.S. businesses more than $3 billion in reported losses in 2025 alone, the FBI’s second-highest fraud category behind only investment scams. The average complaint involved over $122,000, and 86% of that money moved by wire or ACH before anyone caught it. The FBI’s most recent case list includes a Florida woman who pleaded guilty to her role in a BEC scheme this year. Smaller companies are not spared either, and they are often the easier target, since fewer of them require a second person to sign off before money moves.

If you are not sure whether your own team would catch this, that is exactly the kind of gap a free IT audit turns up, before it becomes a story like this one.

What Would Have Stopped It

  • A callback, not a reply. Any request to change payment details or send a large wire gets verified by phone, using a number pulled from an existing file, never one included in the email itself.
  • Dual approval on wires. No single employee, however senior, should be able to move a large sum alone. A second set of eyes is the whole point.
  • MFA on every email account. It will not stop a well-written scam email, but it closes off the version of this where an attacker is inside a real inbox, not just imitating one.
  • A standing policy on vendor changes. New bank details for an existing vendor should always trigger verification, no exceptions, no matter how legitimate the request looks or how long the relationship has been on file.

The Moral of the Story

Toyota Boshoku did not get hacked. Somebody just asked nicely, at the right moment, in the right tone, and nobody picked up the phone to check. That is still the easiest version of this to prevent.


Where GiaSpace Fits

Email security is not just spam filtering. It is the verification habits that catch a request like this before the wire goes out. If your team does not have a callback policy or dual approval on payments, that is worth fixing before it becomes the subject of your own October post.

→ Schedule a Fit Call with Rob Giannini
→ Learn More About Our Email Security Services

Struggling To Find A Great IT Company?

Fill in Below. We Get Back to You in Minutes

Want content like this delivered straight to your inbox?

IT insights, cybersecurity alerts, and tech tips for business leaders. No fluff, no spam.
Get IT Help Now