← Other Blogs

MFA stopped account takeover. It didn't stop a $60 million wire transfer

MFA adoption sharply cut how often BEC attacks hit accounts without it in place, real, measurable progress. But the money kept moving anyway, and BEC losses rose again in 2025. We think that gap exists because BEC never really depended on breaking into an account. It depended on a person believing the message came from someone they trust, and no authentication protocol was built to test that.
Security awareness
Human risk management
GenAI and security
Phishing
Zepo Intelligence

In August 2024, Orion S.A., a Luxembourg-based chemical company that supplies carbon black to tire and rubber manufacturers worldwide, told the US Securities and Exchange Commission that an employee, not a senior executive, had been deceived into authorizing multiple wire transfers over several weeks, totaling roughly 60 million dollars, to accounts controlled by attackers (Orion S.A. Form 8-K, sec.gov, August 12, 2024). No account was breached. No malware was involved. Someone believed a sequence of messages came from a source they trusted, and acted on each one.

Orion's filing states the company found no evidence of unauthorized access to its systems or data. That detail matters more than it looks. Most companies build their defenses around the assumption that a big loss means something broke: a firewall failed, a password leaked, a system had a hole in it. Here, nothing broke. A person made a normal decision, approving a payment that looked like every other payment they had approved before, and did it several times before anyone questioned it.

That is worth sitting with for a second, because it is not a hard trick to pull off. Attackers researching a target do not need to breach anything to learn who approves payments and how. A company's own website, LinkedIn profiles, and press releases usually spell out who runs finance, who reports to whom, and what a normal request looks like. Impersonating that pattern convincingly is closer to writing a good cover letter than hacking a system, which is exactly why it scales so well.

MFA worked exactly as designed

The share of BEC attacks hitting organizations without MFA in place fell from 58% in 2023 to 25% by early 2024 (ArcticWolf, State of Cybersecurity 2024 Trends Report UK, arcticwolf.com). That is a real security win. Account takeover, an attacker logging into a real mailbox with stolen credentials, became meaningfully harder to pull off.

If BEC depended mainly on breaking into accounts, cases like Orion's should be getting rarer as MFA adoption climbs. They are not. Orion is not an isolated filing, and it is not even the only one this year: a UK energy company and a US workers' union both lost comparable sums to the same pattern, no breach, no malware, just a convincing message that arrived through the right channel at the right moment.

The money did not stop moving

The FBI's 2025 Internet Crime Report logged 24,768 BEC complaints and 3.05 billion dollars in reported losses, up from 21,442 complaints and 2.77 billion dollars in 2024 (FBI IC3 2025 Annual Report, ic3.gov). Complaints rose roughly 16%, losses roughly 10%, in the same window MFA adoption was closing the account takeover gap.

The Association for Financial Professionals found BEC affected 74% of organizations in 2025, a significant increase over 2023 and 2024 (AFP 2026 Payments Fraud and Control Survey, financialprofessionals.org). Microsoft's 2025 Digital Defense Report found BEC responsible for 21% of attack outcomes with a clear result, ahead of ransomware at 16% (Microsoft Digital Defense Report 2025, microsoft.com). The defense got better at stopping one specific mechanism. The category of attack it was meant to stop did not shrink, it just moved past the door MFA was guarding.

Impersonation does not need a broken door

Classic executive impersonation BEC was still reported by 49% of organizations in 2024, even as vendor and third-party impersonation became more common, reported by 45% and 24% of organizations respectively (AFP 2025 Payments Fraud and Control Survey, financialprofessionals.org).

None of that requires a compromised account, and increasingly it does not stop at email either. A live phone call added after the message lands does something an email alone cannot: it lets the target ask a question and get a reassuring answer in real time. That single exchange, a voice that sounds right, confirming exactly what the email said, is often enough to override whatever hesitation was starting to form, the same reinforcement pattern that likely sustained multiple transfers out of Orion over several weeks.

The defense that stopped account takeover cannot stop a message that never needed one

MFA protects an asset, the account. Impersonation attacks a relationship, the trust someone places in a name they recognize, and authentication protocols were never built to evaluate that.

This is the reframe worth sitting with: a CISO looking at MFA adoption numbers has a real, defensible reason to feel progress is being made, while the financial exposure quietly shifts into a category no authentication metric was ever tracking, and Orion's 60 million dollar filing shows exactly how far that exposure can reach before anyone notices.

What a test built for this actually looks like

Testing for this failure mode means recreating the sequence itself, not just the first message. That means training the response to a phishing email followed by a vishing call, inside a single campaign that pivots based on how each employee actually responds, not two separate tests with no connection between them. That is what Multiattack Simulations makes possible. If someone opens the simulated email, the call triggers next, the same follow-up reinforcement that makes the real version so effective. If someone reports the email instead, a different path activates, so the exercise never scores the two channels in isolation.

The resulting report shows the exact point in the sequence where verification held and the point where it broke, information a single-channel phishing test simply cannot produce, and the same information that would have told Orion, before the second wire went out, that the first one had already gotten through.

What this means in practice

Security leaders should stop reading MFA adoption as a proxy for BEC risk reduction. It closes the account takeover subset of BEC and leaves the impersonation subset, now the larger and more expensive one, largely untested.

It also means the fix does not sit only with security. AFP's survey found treasury discovers 83% of attempted fraud and 55% of actual fraud, more than any other function, because treasury is where the payment actually happens (AFP 2026 Payments Fraud and Control Survey, financialprofessionals.org). Any program aimed at reducing BEC exposure has to reach that function directly, not stop at a phishing report button finance never uses.

MFA solved a real problem, and the data shows it. It did not solve business email compromise, and Orion's filing shows that too. The organizations that reduce their exposure next will be the ones that stop crediting account security for a risk that moved somewhere account security cannot see. 

Subscribe to our newsletter
Blog content:
Act now before attackers do
Unify deepfake simulations, personalized training, and risk analytics into a single platform that builds measurable defense.
Talk to an expert

How Zepo helps companies

When everything connects, results follow

Paula Pereira

Digital Information Security Manager

I would recommend Zepo to colleagues at other companies because I believe it has met all our needs. It has allowed us to run three types of campaigns that other tools we have tried simply cannot do. And beyond the product itself, the support from the whole team has helped us get far more out of it.”

+9K

Employees Protected

–10%

Click Rate on Attacks

+18%

Training Completion Rate

Ramon Fernandez Blanco

Cybersecurity & Digital Product Manager

Since implementing Zepo, employee awareness has increased significantly. Employees now actively discuss cybersecurity and phishing campaigns, and suspicious emails are quickly reported instead of ignored.”

+600

Employees Protected

–15%

Credentials Submitted

+26%

Training Completion Rate

Jonathan Nelson

Director of Risk Intelligence

Zepo’s vision for a real-time, hyper-personalised, multi-platform cybersecurity solution is truly unique and stands head and shoulders above the competition.”

+100

Employees Protected

Get Smarter Before Attackers Strike.