← Weitere Blogs

MFA stopped account takeover. It didn't stop a $60 million wire transfer

MFA adoption sharply cut how often BEC attacks hit accounts without it in place, real, measurable progress. But the money kept moving anyway, and BEC losses rose again in 2025. We think that gap exists because BEC never really depended on breaking into an account. It depended on a person believing the message came from someone they trust, and no authentication protocol was built to test that.
Security awareness
Human risk management
GenAI and security
Phishing
Zepo Intelligence

In August 2024, Orion S.A., a Luxembourg-based chemical company that supplies carbon black to tire and rubber manufacturers worldwide, told the US Securities and Exchange Commission that an employee, not a senior executive, had been deceived into authorizing multiple wire transfers over several weeks, totaling roughly 60 million dollars, to accounts controlled by attackers (Orion S.A. Form 8-K, sec.gov, August 12, 2024). No account was breached. No malware was involved. Someone believed a sequence of messages came from a source they trusted, and acted on each one.

Orion's filing states the company found no evidence of unauthorized access to its systems or data. That detail matters more than it looks. Most companies build their defenses around the assumption that a big loss means something broke: a firewall failed, a password leaked, a system had a hole in it. Here, nothing broke. A person made a normal decision, approving a payment that looked like every other payment they had approved before, and did it several times before anyone questioned it.

That is worth sitting with for a second, because it is not a hard trick to pull off. Attackers researching a target do not need to breach anything to learn who approves payments and how. A company's own website, LinkedIn profiles, and press releases usually spell out who runs finance, who reports to whom, and what a normal request looks like. Impersonating that pattern convincingly is closer to writing a good cover letter than hacking a system, which is exactly why it scales so well.

MFA worked exactly as designed

The share of BEC attacks hitting organizations without MFA in place fell from 58% in 2023 to 25% by early 2024 (ArcticWolf, State of Cybersecurity 2024 Trends Report UK, arcticwolf.com). That is a real security win. Account takeover, an attacker logging into a real mailbox with stolen credentials, became meaningfully harder to pull off.

If BEC depended mainly on breaking into accounts, cases like Orion's should be getting rarer as MFA adoption climbs. They are not. Orion is not an isolated filing, and it is not even the only one this year: a UK energy company and a US workers' union both lost comparable sums to the same pattern, no breach, no malware, just a convincing message that arrived through the right channel at the right moment.

The money did not stop moving

The FBI's 2025 Internet Crime Report logged 24,768 BEC complaints and 3.05 billion dollars in reported losses, up from 21,442 complaints and 2.77 billion dollars in 2024 (FBI IC3 2025 Annual Report, ic3.gov). Complaints rose roughly 16%, losses roughly 10%, in the same window MFA adoption was closing the account takeover gap.

The Association for Financial Professionals found BEC affected 74% of organizations in 2025, a significant increase over 2023 and 2024 (AFP 2026 Payments Fraud and Control Survey, financialprofessionals.org). Microsoft's 2025 Digital Defense Report found BEC responsible for 21% of attack outcomes with a clear result, ahead of ransomware at 16% (Microsoft Digital Defense Report 2025, microsoft.com). The defense got better at stopping one specific mechanism. The category of attack it was meant to stop did not shrink, it just moved past the door MFA was guarding.

Impersonation does not need a broken door

Classic executive impersonation BEC was still reported by 49% of organizations in 2024, even as vendor and third-party impersonation became more common, reported by 45% and 24% of organizations respectively (AFP 2025 Payments Fraud and Control Survey, financialprofessionals.org).

None of that requires a compromised account, and increasingly it does not stop at email either. A live phone call added after the message lands does something an email alone cannot: it lets the target ask a question and get a reassuring answer in real time. That single exchange, a voice that sounds right, confirming exactly what the email said, is often enough to override whatever hesitation was starting to form, the same reinforcement pattern that likely sustained multiple transfers out of Orion over several weeks.

The defense that stopped account takeover cannot stop a message that never needed one

MFA protects an asset, the account. Impersonation attacks a relationship, the trust someone places in a name they recognize, and authentication protocols were never built to evaluate that.

This is the reframe worth sitting with: a CISO looking at MFA adoption numbers has a real, defensible reason to feel progress is being made, while the financial exposure quietly shifts into a category no authentication metric was ever tracking, and Orion's 60 million dollar filing shows exactly how far that exposure can reach before anyone notices.

What a test built for this actually looks like

Testing for this failure mode means recreating the sequence itself, not just the first message. That means training the response to a phishing email followed by a vishing call, inside a single campaign that pivots based on how each employee actually responds, not two separate tests with no connection between them. That is what Multiattack Simulations makes possible. If someone opens the simulated email, the call triggers next, the same follow-up reinforcement that makes the real version so effective. If someone reports the email instead, a different path activates, so the exercise never scores the two channels in isolation.

The resulting report shows the exact point in the sequence where verification held and the point where it broke, information a single-channel phishing test simply cannot produce, and the same information that would have told Orion, before the second wire went out, that the first one had already gotten through.

What this means in practice

Security leaders should stop reading MFA adoption as a proxy for BEC risk reduction. It closes the account takeover subset of BEC and leaves the impersonation subset, now the larger and more expensive one, largely untested.

It also means the fix does not sit only with security. AFP's survey found treasury discovers 83% of attempted fraud and 55% of actual fraud, more than any other function, because treasury is where the payment actually happens (AFP 2026 Payments Fraud and Control Survey, financialprofessionals.org). Any program aimed at reducing BEC exposure has to reach that function directly, not stop at a phishing report button finance never uses.

MFA solved a real problem, and the data shows it. It did not solve business email compromise, and Orion's filing shows that too. The organizations that reduce their exposure next will be the ones that stop crediting account security for a risk that moved somewhere account security cannot see. 

Newsletter abonnieren
Blog-Inhalt:
Jetzt handeln bevor es Angreifer tun
Vereinen Sie Deepfake-Simulationen, personalisierte Schulungen und Risikoanalysen auf einer einzigen Plattform, die messbare Sicherheit schafft.
Mit einem Experten sprechen

Wie Zepo Unternehmen unterstützt

Wenn alles vernetzt ist, folgen die Ergebnisse

Paula Pereira

Manager für digitale Informationssicherheit

Ich würde Zepo jederzeit an Kollegen in anderen Unternehmen weiterempfehlen, da das Tool all unsere Anforderungen erfüllt. Wir konnten damit drei Kampagnentypen umsetzen, an denen andere Lösungen, die wir zuvor getestet haben, gescheitert sind. Und über das Produkt hinaus hat uns der Support des gesamten Teams dabei geholfen, das Beste aus der Plattform herauszuholen.”

+9K

Mitarbeiterschutz

–10%

Klickrate bei Angriffen

+18%

Abschlussquote der Schulung

Ramon Fernandez Blanco

Cybersecurity & Digital Product Manager

Seit der Einführung von Zepo ist das Sicherheitsbewusstsein unserer Mitarbeiter deutlich gestiegen. Das Thema Cybersicherheit und Phishing-Kampagnen wird nun aktiv im Team diskutiert, und verdächtige E-Mails werden umgehend gemeldet, anstatt sie zu ignorieren.”

+600

Mitarbeiterschutz

–15%

Anmeldedaten übermittelt

+26%

Abschlussquote der Schulung

Jonathan Nelson

Leiter Risikointelligenz

Die Vision von Zepo für eine echtzeitbasierte, hyper-personalisierte und plattformübergreifende Cybersicherheitslösung ist absolut einzigartig und hebt sich deutlich vom Wettbewerb ab.”

+100

Mitarbeiterschutz

Handeln Sie klüger Bevor Angreifer zuschlagen.