31 July 2026
Ruling [DEU] ¦ From Fake Executives to Suspicious Transfers: Anatomy of a Treasury Scam
When a CEO impersonation scam becomes an employment-law crisis
A sophisticated business email compromise can move rapidly from social engineering to substantial corporate loss. The case described here shows how an impersonation scheme exploited corporate hierarchy, confidentiality expectations and the authority of a senior treasury executive to generate dozens of high-value payments.
The fraudsters posed as senior executives of an international industrial group and as a genuine lawyer from a well-known law firm. They used apparently authentic telephone numbers, WhatsApp messages, private email accounts, corporate names and fabricated transaction documents. The stated purpose was the creation of a new holding company and the payment of initial capital contributions, acquisition-related expenses and other transaction costs.
The target was the group’s Head of Global Treasury. He was told that the project was highly confidential and that communication had to take place through private channels. He was then instructed to arrange payments to accounts in several jurisdictions, including Hungary, China and other locations in Asia.
The first transfer amounted to EUR 1.77 million. Further payments followed despite the absence of complete supporting documentation, proper transaction files or a conventional approval process. The total exposure eventually reached many tens of millions of euros in euro and US dollar payments.
This is a classic business email compromise structure, but with an important variation: the fraud did not rely solely on email. It combined telephone impersonation, caller-ID manipulation, messaging applications, private email, fabricated legal documentation and the misuse of genuine professional identities.
The predicate offense: fraud before laundering
The primary predicate offense is fraud. Under German criminal law, a scheme of this kind may fall within the scope of fraud under section 263 of the German Criminal Code if the perpetrators intentionally create or reinforce an error, induce a disposition of assets and cause financial loss with an intent to obtain an unlawful benefit.
The alleged impersonation of the group’s CFO, CEO and external counsel was central to the deception. The victim was not asked to make a personal payment. He was induced to use his professional authority and access to corporate payment infrastructure to cause the company to transfer funds to accounts controlled or selected by the perpetrators.
The fraudulent conduct appears to have involved several distinct representations:
- that a new group holding company was being established;
- that the transaction had been approved at senior management level;
- that confidentiality was required for regulatory or insider-trading reasons;
- that the payments represented legitimate capital contributions or transaction expenses;
- that payment instructions had been confirmed by executives, a lawyer and a notary; and
- that repeated transfers, recalls and reissued payments were part of a valid transaction process.
The use of a real lawyer’s name and a genuine law firm’s identity increased credibility, but it did not make the communications authentic. The relevant issue is whether the perpetrators knowingly used those identities to induce payments and obtain control of corporate funds.
The employee’s conduct, by contrast, was considered in the employment proceedings primarily as negligence rather than as participation in the fraud. The court concluded that the employee was deceived, but that his conduct became grossly negligent as the warning signs accumulated.
The laundering risk begins with the payment flow
Fraud explains how the money was obtained. Money laundering analysis begins with what happened to the proceeds after the transfers left the company.
The payment pattern presents several indicators associated with laundering and organised financial crime. Funds were sent to numerous recipients, often involving newly introduced or unfamiliar entities and accounts in different jurisdictions. Payment instructions changed repeatedly. Some payments were recalled and replaced before the original funds had returned. Other payments were made without invoices or complete transaction documentation.
This type of movement can serve several laundering purposes. It may disperse the proceeds across multiple accounts, move funds through different jurisdictions, create distance between the victim and the ultimate beneficiaries, and complicate recovery efforts. Repeated transfers and rapid onward movement can also obscure the origin of the funds and make it harder for banks, investigators and courts to reconstruct the transaction chain.
The laundering analysis does not require proof that every recipient knowingly participated in the fraud. Some recipients may have been money mules, nominee companies, compromised accounts or innocent intermediaries. Others may have knowingly received, transferred or converted criminal property. Those distinctions must be established through evidence concerning account control, communications, incorporation records, transaction history, beneficial ownership and the movement of funds after receipt.
Under German law, handling property derived from a criminal offense may engage section 261 of the German Criminal Code. Depending on the facts, potential conduct could include concealing or disguising the origin of criminal property, acquiring or possessing it, transferring it or assisting another person in obtaining it. The applicable offense and mental element would depend on what each recipient knew or accepted and when.
Why the transaction should have triggered immediate escalation
The case illustrates the importance of treating transaction context as a control issue rather than assessing payment instructions in isolation.
Several warning signs appeared before the first payment. Communications were moved from established corporate channels to private WhatsApp and private email. The supposed executive used a number that did not match the number used for WhatsApp communication. The project was described as highly confidential, yet the employee received incomplete information and was asked to move millions of euros without conventional documentation. The supposed transaction involved a new holding company in a foreign jurisdiction, but the payment recipients and purposes were not coherently documented.
Further warning signs emerged with each subsequent payment. The employee was asked to make additional transfers without first receiving the documents needed to validate the previous ones. Payments were directed to different jurisdictions and unfamiliar entities. Funds were to be recalled and re-sent before the recalls had been completed. The employee was told to conceal information from colleagues and to provide a misleading explanation to a police officer investigating suspicious transfers.
These facts are relevant not only to employment liability but also to financial crime controls. A treasury function should be designed to prevent a single individual from converting an unverified instruction into a series of irreversible cross-border payments. A request to bypass ordinary approval channels is itself a high-risk event, particularly where the payment is justified by urgency, confidentiality or senior executive authority.
The failure of the four-eyes principle
The company had a formal four-eyes requirement. Its treasury guidance also required financial institutions to be approved before transactions were conducted with them. The employee nevertheless involved only one subordinate colleague to process the payments and acknowledged that the procedure created a SOX deficiency.
The significance of this point extends beyond internal policy compliance. Segregation of duties is a core anti-fraud control because it separates transaction initiation, verification, approval and execution. It is not merely an administrative formality. Its purpose is to ensure that a plausible but fraudulent request is independently challenged before funds leave the organisation.
A second employee participating in the mechanical processing of a payment does not necessarily provide genuine independent verification. If the second person is given limited information, is told that the matter is confidential and is not authorised to challenge the underlying transaction, the control may exist on paper while failing in practice.
Effective segregation requires independence, access to relevant information and a clear duty to stop the transaction where required documentation or approval is missing.
The role of private channels and identity verification
The use of private communication channels was a decisive feature of the scheme. Corporate systems often contain authentication, retention, monitoring and access controls that are absent from private devices and consumer messaging platforms. Moving a transaction outside those systems can impair forensic reconstruction and remove opportunities for automated detection.
Senior executives should never be treated as self-authenticating sources of payment instructions. A known telephone number, a familiar writing style or a convincing voice does not establish authenticity. Caller-ID spoofing can cause a call to display a trusted number, while generative tools and publicly available information can make impersonation highly persuasive.
The appropriate response is independent verification through a trusted channel. The recipient should call the executive using a number retrieved from the corporate directory, contact the executive’s assistant or use an established internal collaboration system. Replying to the message, calling the number supplied by the sender or continuing the same private chat does not provide independent confirmation.
The training video referred to in the judgment reportedly conveyed precisely this principle: contact the person directly rather than acting solely on the instruction. The court treated that training as relevant because the employee had participated in it and had been shown how executive impersonation could be used to demand an urgent payment.
The point at which negligence became gross negligence
The appellate court distinguished between the first payment and the later transfers. It did not find that gross negligence had necessarily been established at the moment of the initial EUR 1.77 million payment. It concluded, however, that by 18 July 2024 the accumulated warning signs made the employee’s conduct grossly negligent.
That distinction is important. Gross negligence is generally assessed by reference to the circumstances known, or that should have been known, at the relevant time. The question is not simply whether the employee was deceived. It is whether the employee ignored a level of risk that should have been obvious to a reasonable person performing the same role.
By the later stage, the employee had encountered multiple inconsistencies: private communications, conflicting numbers, incomplete information, unusual secrecy, repeated payment instructions, missing invoices, unexplained foreign recipients and requests to transfer further funds before previous transfers had been returned. At that point, continuing to execute the instructions without independent verification was treated as a serious departure from the required standard of care.
The progression also matters for investigations. A person who initially falls victim to fraud may later become a source of loss if the person receives new information that should cause the transaction to stop. The relevant assessment must therefore be chronological rather than based on the final loss alone.
Concealment instructions and possible obstruction risks
The scheme escalated when the employee was instructed to keep the matter from colleagues and management, to withdraw an email before it could be read and to provide a misleading explanation concerning payments under police inquiry.
These actions have significance beyond internal disciplinary rules. Instructions to conceal suspicious payments, delete communications or mislead investigators are classic indicators that the underlying transaction may involve criminal proceeds or an attempt to obstruct detection. They also increase the risk that the organisation will fail to meet its obligations concerning internal escalation, suspicious activity reporting and cooperation with law enforcement.
The employee’s conduct was assessed in the employment case as part of the factual basis for termination and liability. Whether any individual act also satisfies a criminal offense would require a separate analysis of intent, knowledge, the exact content of the communication and the applicable jurisdiction.
Recovery, freezing and tracing
Once suspicious transfers are identified, speed is critical. The company in this case attempted to recover funds through civil proceedings, and some amounts were subsequently returned. The remaining claims were adjusted to reflect recoveries.
A recovery strategy should combine several measures. The organisation should immediately contact the sending and receiving banks, request recall or freezing measures, preserve all relevant evidence and notify law enforcement. It should identify the receiving institutions, beneficiary names, account numbers, payment references, intermediary banks and time of transfer. It should also trace onward movements wherever possible.
Civil recovery against recipients may proceed in parallel with criminal investigations. The relevant claims can include restitution, unjust enrichment, damages, tracing-based relief and other remedies depending on the jurisdiction and the recipient’s involvement. Recovery can become more difficult where funds have been converted into cryptoassets, withdrawn in cash, layered through several accounts or transferred into jurisdictions with limited cooperation.
The company’s claim for future losses also reflects an important procedural issue. Fraud-related expenses may continue after the initial loss, including investigation costs, bank charges, legal expenses, enforcement costs and costs associated with tracing and recovery. Whether those costs are recoverable depends on applicable law and the particular claim.
The limits of insurance as a control
The employee was covered by a directors’ and officers’ liability policy. The existence of insurance did not prevent termination, eliminate the finding of gross negligence or remove the need to investigate the underlying fraud.
Insurance can support recovery, but it is not a substitute for payment controls. Coverage may depend on the insured status of the individual, the policy wording, exclusions for dishonesty or deliberate misconduct, notification requirements, allocation provisions, retentions and the interaction with other insurance policies. Coverage disputes may also affect timing and the practical ability to recover funds.
From a governance perspective, insurance should be treated as a risk-transfer mechanism, not as evidence that a control environment is adequate. A company that relies on insurance while permitting unverified executive instructions and single-person payment execution remains exposed to operational, regulatory and reputational consequences.
Lessons for financial crime compliance
The case provides a clear warning for treasury departments, financial institutions and corporate investigators. Executive impersonation schemes should be treated as financial crime events from the first indication of an unauthorised or anomalous payment, not merely as isolated processing errors.
Controls should require independent verification for payment instructions received through private channels, especially where the instruction involves urgency, secrecy, a new beneficiary, a foreign jurisdiction or a significant amount. New counterparties and banks should be subject to documented approval. Invoices, contracts, corporate records and transaction rationales should be available before payment, not promised for later delivery.
Monitoring should also focus on behavioural and transactional combinations. A single large transfer may appear explainable. A sequence of payments to newly introduced entities, combined with recalls, changed beneficiaries, multiple jurisdictions and unusual communication channels, should trigger immediate review.
Finally, training must reflect current attack methods. Employees should understand caller-ID spoofing, deepfake audio and video, compromised accounts, business email compromise and the manipulation of trusted professional identities. Training should not end with awareness. Staff need a simple escalation route, authority to stop payments and protection from pressure when they challenge a senior executive’s instruction.
The central lesson: a convincing identity is not proof of authority, and a plausible business purpose is not proof of legitimacy. Where large transfers are supported by secrecy, urgency and incomplete documentation, the correct response is to stop, verify independently and escalate.
Dive deeper
- Landesarbeitsgericht Cologne ¦ Decision Database, Judgment dated July 31, 2026, Case 8 SLa 603/25, ECLI:DE:LAGK:2026:0731.8SLA603.25.00 ¦ Link