One of the largest cases of Business Email Compromise fraud recorded on Greek soil has come to a happy end: the Cybercrime Directorate identified two foreigners who extorted 4,000,000 euros from a well-known Greek shipping company and achieved the full recovery of the funds before they were dispersed to third-party accounts. The BEC shipping criminal case highlights how critical the speed of reaction is when every minute counts.

The investigation began in August 2025, following an official complaint from a representative of the affected company. The perpetrators had managed to infiltrate the shipping company's electronic correspondence with a cooperating foreign banking institution, monitor the communication between the two parties for a long time, and choose the time of the intervention with surgical precision.
See also: The most common phishing scams in Gmail and Outlook
How the BEC shipping attack was set up
The attackers’ trick was a classic Business Email Compromise but extremely well executed. After gaining unauthorized access to corporate messages, they created a deceptive email address that looked almost identical to the real corporate one. This similarity is the key to any successful BEC attack: a character changes, a suffix is mutated, a letter is replaced with a visually similar one, and the human eye doesn’t notice anything in a quick read.
The attackers then sent fake payment orders to the bank, giving new bank account details. The €4 million was directed to a front company account based in Bulgaria, which had been set up specifically to act as the first stop in the laundering process. The next move in the plan, if the perpetrators had caught on, would have been to split the amount into dozens of smaller accounts worldwide, a practice called smurfing that makes recovery nearly impossible.

The reaction of the authorities
The BEC maritime attack case served as a real stress test for the mechanism of transnational cooperation. As soon as the complaint reached the Cybercrime Prosecution Directorate, a network of agencies was simultaneously activated: the Anti-Money Laundering Authority , the International Police Cooperation Directorate through the Europol Department, as well as the involved banking institutions in Greece and abroad.
The first step was the temporary freezing of the funds in the Bulgarian account, a move that requires a court order and was carried out within a minimum of time thanks to Europol channels. Subsequently, through legal procedures initiated in both countries, the full recovery of the 4 million was achieved and their return to the Greek company. At the same time, the legal entity that appeared as the beneficiary of the account and the person who practically managed it were identified.
See also: Arrest of alleged member of the Scattered Spider group
See also: Operation Endgame: Dismantling the SocGholish malware distribution network
What offenses are they facing?
The two foreign defendants face a very serious case for computer fraud of particularly high value and for illegal access to an information system or data. These are felonies of the Greek Penal Code and Law 4411/2016 on cybercrime, with penalties of up to imprisonment. The case file was forwarded to the competent prosecutor's office for the next phase of the legal proceedings.

Why shipping is an attractive target
Greek shipping was not targeted by chance. The industry handles high-value payment orders for charter, supply, insurance premiums and crew payments every day, with multiple parties communicating via email in different countries and time zones. This operational reality creates ideal conditions for a BEC attack: many intermediaries, time pressure, large amounts, and the justified expectation that each new email concerns a real transaction that is “in progress”.
Attackers in such cases rarely target at random. They map out the company’s routines for weeks or months, identifying who signs orders, how large payments are approved, which banks are used, and when large-value payments are expected. Only then do they intervene, often just hours before a transaction that was otherwise scheduled to take place.
See also: Microsoft warns of phishing campaign targeting hotels
What every business should do
The SecNews technical team proposes specific measures that would have prevented or detected the shipping-type BEC attack in a timely manner. First and foremost: mandatory telephone confirmation with a pre-agreed number for any change of banking details, regardless of how convincing the email seems. Second: activation of multi-factor authentication (MFA) with a hardware token or authenticator app on all email accounts involved in financial transactions, so that a stolen password is not enough.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Third measure: DMARC, SPF and DKIM in strict configuration for the corporate sector, so that misleading domains are rejected or at least marked. Fourth: train executives to recognize visually similar characters (homoglyphs) and minor changes in domain endings. Fifth and perhaps most crucial: immediately notify the authorities and the bank within a few hours of suspicion of fraud. As this case demonstrates, the window for freezing and recovering funds is small but exists, as long as one reacts quickly.
The successful outcome of this specific investigation sends a double message: on the one hand, that Business Email Compromise remains the top threat to Greek businesses with international exposure, and on the other hand, that when all mechanisms—company, banks, Greek Police, Europol—are mobilized in a coordinated and timely manner, even amounts in the order of millions of euros can be returned to the rightful beneficiary.
