Dutch Online Retailer Wehkamp Loses 144,000 Euros in Bankruptcy Business Email Compromise

Stu Sjouwerman | May 15, 2020

Distributiecentrum van webwinkel Wehkamp, die werd beroofd door hackers. Image copyright and courtesy © ANPCyber criminals successfully gained access to email traffic between bankruptcy trustees and Wehkamp – one of the biggest online retailers in The Netherlands – writes RTL Z. Employees of the company unknowingly transferred 144,000 euros to cyber criminals who pretended to be the trustees of a clothing brand the retailer sells on its website.

The clothing brand, called Didi, filed for bankruptcy under Dutch law in January. However, Wehkamp is still selling current collections and sale items of the brand. Proceeds go to Didi’s bankruptcy trustees who will then settle with creditors.

Scammers managed to infiltrate email communications between Wehkamp and the trustees Mid-February, probably using a password previously exposed in a data breach. Upon reading about the large payments the online retailer was making to the trustees, the bad guys spoofed both parties’ email addresses and took over conversation sending very similar emails to the ones that were sent before.

The cyber criminals then introduced a new bank account for paying the instalments, which was verified by Wehkamp using the fraudulent email address. The bad guys were quick to claim the bank account was indeed correct…

Didi’s trustees now hold Wehkamp at least partly responsible for the money that went missing. The online retailer claims it is not responsible, because their systems were ‘not technically hacked’. According to Tweakers, the trustees have already subpoenaed the Dutch retailer.

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.