Dutch Online Retailer Wehkamp Loses 144,000 Euros in Bankruptcy Business Email Compromise

Distributiecentrum van webwinkel Wehkamp, die werd beroofd door hackers. Image copyright and courtesy © ANPCyber criminals successfully gained access to email traffic between bankruptcy trustees and Wehkamp – one of the biggest online retailers in The Netherlands – writes RTL Z. Employees of the company unknowingly transferred 144,000 euros to cyber criminals who pretended to be the trustees of a clothing brand the retailer sells on its website.

The clothing brand, called Didi, filed for bankruptcy under Dutch law in January. However, Wehkamp is still selling current collections and sale items of the brand. Proceeds go to Didi’s bankruptcy trustees who will then settle with creditors.

Scammers managed to infiltrate email communications between Wehkamp and the trustees Mid-February, probably using a password previously exposed in a data breach. Upon reading about the large payments the online retailer was making to the trustees, the bad guys spoofed both parties’ email addresses and took over conversation sending very similar emails to the ones that were sent before.

The cyber criminals then introduced a new bank account for paying the instalments, which was verified by Wehkamp using the fraudulent email address. The bad guys were quick to claim the bank account was indeed correct…

Didi’s trustees now hold Wehkamp at least partly responsible for the money that went missing. The online retailer claims it is not responsible, because their systems were ‘not technically hacked’. According to Tweakers, the trustees have already subpoenaed the Dutch retailer.

Will your users respond to phishing emails?

KnowBe4's Phishing Reply Test (PRT) is a complimentary IT security tool that makes it easy for you to check to see if key users in your organization will reply to a highly targeted phishing attack without clicking on a link. PRT will give you quick insights into how many users will take the bait so you can take action to train your users and better protect your organization from these fraudulent attacks!

PRT-imageHere's how it works:

  • Immediately start your test with your choice of three phishing email reply scenarios
  • Spoof a Sender’s name and email address your users know and trust
  • Phishes for user replies and returns the results to you within minutes
  • Get a PDF emailed to you within 24 hours with the percentage of users that replied

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:


Subscribe To Our Blog

Anti-Phishing Guide ebook

Get the latest about social engineering

Subscribe to CyberheistNews