Two Transposed Letters Cost ₹197 Crore. Eleven Years On, the Same Trick Still Lands.
A domain nobody read closely
In September 2015, Oil and Natural Gas Corporation agreed to ship 36,000 tonnes of naphtha to Saudi Aramco, a cargo worth roughly ₹100 crore. The payment did not arrive. ONGC was told public holidays had held things up, so it sent a second consignment worth a further ₹97 crore. On 7 October, still chasing the money, ONGC discovered that Aramco had paid — into an account at Bangkok Bank Public Company Limited that ONGC had never nominated.
Aramco’s staff had spent weeks corresponding with what they believed was ONGC, writing to an address on a domain that transposed two letters of ONGC’s own. Nobody read it closely, because nobody reads a domain closely on the fortieth email of a routine cargo deal. Mumbai’s cyber police registered cases of cheating, forgery and impersonation. The people behind the domain were never publicly identified, and ₹197 crore of naphtha had left the country.
Nothing was hacked
The detail worth sitting with is what the attackers did not do. They did not breach an ONGC server. They did not steal a password, plant malware, or exploit a vulnerability in anything either company ran. Every system on both sides worked exactly as designed. The fraud lived entirely in the space between two organisations — in a payment instruction that changed, and a verification step that did not exist.
That is why it resists the usual security spending. A stronger firewall at ONGC would have changed nothing: the attack was aimed at ONGC’s customer, using ONGC’s identity. The asset exploited was the trust between the two firms, and it sits on neither balance sheet and inside neither perimeter.
Eleven years, the same playbook
The reason to revisit a 2015 case is that the attack has not needed to evolve. In October 2025, Manipal Technologies Limited in Karnataka was due to pay the fifth quarterly instalment on a machinery lease from Equiflex Private Limited — ₹1,04,16,229. Four previous instalments had gone to the same account without incident.
On 11 October, a reminder arrived asking for payment by the 15th. On 13 October, a second email, apparently from the same supplier, said the money should go to a new bank account instead. Manipal paid. The fraud surfaced on 29 October, when Equiflex mentioned it had never received anything. A lookalike address, a changed account number, a routine invoice: the ONGC attack, scaled down by two orders of magnitude and run a decade later.
The scale is not marginal
Business email compromise is not an exotic threat that occasionally makes the news. In the FBI’s 2025 Internet Crime Report, BEC accounted for $3,046,598,558 in reported losses — the second-largest category of the year, behind investment fraud at $8.65 billion and ahead of tech support scams. Total reported cybercrime losses reached nearly $21 billion across 1,008,597 complaints, up 26% on 2024. And those are only the losses someone bothered to report to a US federal agency.
India’s own numbers point somewhere uncomfortable. Ministry of Home Affairs data shows 28.15 lakh cybercrime cases reported in 2025, up from 22.68 lakh the year before — a 24% jump. Reported losses were ₹22,495 crore, roughly flat against 2024’s ₹22,845 crore. But FIRs registered fell, from 66,370 to 55,484. More crime, more reports, fewer formal cases. Whatever is absorbing that gap, it is not prosecution.
Why the geography matters
Cross-border trade concentrates every weakness this attack needs. Counterparties sit in different jurisdictions and time zones, so email displaces the phone call that would have caught it. Payments route through correspondent banking chains and land in a third country — Bangkok, here — within hours. Recovery then depends on police in one country persuading a bank in another to freeze funds before they move again.
India has built real machinery here: the Indian Cyber Crime Coordination Centre says its registry of suspect accounts and mule identifiers has blocked ₹8,031.56 crore in fraudulent transactions since September 2024. That is a serious number. It is also, by construction, a domestic instrument. It does very little for a payment that has already reached a bank in Bangkok.
The control that actually works
The lesson usually drawn is that staff need more awareness training. Eleven years of identical attacks suggest otherwise. Awareness asks an accounts clerk to spot a transposed letter on an ordinary Tuesday — precisely the judgement call the attack is engineered to win.
The control that works is narrower and duller. Treat a change to banking details as a distinct, privileged event — not as an email to be actioned, but as a request that fails by default until someone confirms it out of band, by calling a number taken from the signed contract rather than from the message asking for the change. That single rule breaks the ONGC fraud and the Manipal fraud identically, and it costs a phone call. Pair it with DMARC enforcement so your own domain is harder to impersonate, and with monitoring for newly registered domains that resemble yours.
Then apply the uncomfortable corollary. Your controls protect your counterparties, and theirs protect you. ONGC did not lose ₹197 crore because ONGC was careless; it lost it because a customer’s verification process had a hole in it. If your firm handles cross-border payments and cannot say what your largest counterparty does when a supplier’s bank details change, you do not know your own exposure. That question belongs in the next contract review, not the next security audit.
Get the weekly briefing
One email a week on AI, infrastructure, policy and the supply chains underneath them. Free, and you can unsubscribe any time.