Hacker stole £700,000 from U.K. energy company by redirecting payment
A UK energy company lost £700,000 (~$1M) through a business email compromise attack where hackers redirected a contractor payment to an attacker-controlled account, highlighting a critical vulnerability in payment authorization processes that the FBI identified as causing over $3 billion in losses across 2025. This incident underscores that standard security practices are insufficient against sophisticated payment fraud schemes and demonstrates the need for enhanced controls around financial transactions, particularly for organizations with distributed subsidiaries and complex payment workflows. CIOs must recognize that email and accounting system access can directly translate to material financial losses and requires multi-factor authentication, payment verification protocols, and transaction monitoring as strategic priorities.
