€4 million BEC fraud against Greek shipping company – two foreign nationals charged

The Cybercrime Prosecution Directorate has identified two foreign nationals for BEC fraud against a Greek shipping company. The €4 million was fully recovered.

€4 million BEC fraud against Greek shipping company – two foreign nationals charged

Electronic fraud of €4 million: two defendants, full capital recovery

Two foreign nationals are charged with Business Email Compromise (BEC) fraud totalling €4,000,000 against a Greek shipping company, according to Naftemporiki. The Cybercrime Prosecution Directorate identified the legal representative of the company to which the funds were transferred, as well as the individual involved in managing the relevant bank account.

A case file was prepared against the two defendants for fraud by computer of particularly high value and for illegal access to an information system or data. The case file was forwarded to the competent prosecutorial authority.

How the fraud was executed

The case began in August 2025, when a representative of a Greek shipping company filed a report with the police. According to the Hellenic Police, unknown perpetrators obtained illegal access to electronic correspondence between the company and a cooperating banking institution abroad.

Using a deceptive email address that resembled the corporate address, as well as forged payment orders, the perpetrators succeeded in transferring €4,000,000 to a bank account of a company based in Bulgaria.

Coordinated recovery operation

Staff from the Cybercrime Prosecution Directorate, in cooperation with the Authority for Combating Money Laundering from Criminal Activities, the Directorate of International Police Cooperation (Europol Division) and the involved banking institutions, initially achieved temporary seizure of the funds. Full recovery was subsequently achieved, preventing fragmentation and distribution to third-party accounts.

What BEC fraud is

Business Email Compromise fraud is internationally recognised as one of the most widespread forms of targeted electronic fraud against businesses. Perpetrators obtain access to or impersonate corporate email accounts, monitor business-to-business communication for an extended period and intervene at a critical stage of financial transactions. Their aim is to modify bank account details so that monetary amounts are transferred to accounts under their control.

The police emphasise that this particular case highlights the importance of prompt recognition and reporting of such incidents. According to the Hellenic Police, timely notification of the competent authorities and banking institutions was a decisive factor in the successful recovery of all the funds.

Source: Naftemporiki

Read this article in the original language