Desk live·
ForensicPost
Breaches/Fraud/File 25-0602

Senegalese Petroleum Firm Hit by Executive Impersonation Wire Fraud

A petroleum company in Senegal detected a business email compromise in which fraudsters impersonated executives from inside its own mail systems to authorise a wire transfer.

Constructed geometry · not a chart of case data
TargetSenegalese petroleum company
ActorUnattributed
D. Kennedy11 min readConfidence: medium2 sources reviewed

A major petroleum company in Senegal detected a business email compromise scheme in which fraudsters infiltrated internal email systems and impersonated executives to authorise a fraudulent wire transfer of $7.9 million.

Business Email Compromise Is The Largest Category Nobody Files

It produces no data breach notification, because the objective is a payment rather than a dataset. It produces no leak-site listing, because nothing is published. It generates a bank transfer that looks entirely legitimate at the point of execution.

This corpus has 370 files and almost none of them are BEC, which says more about what gets disclosed than about how much of it happens — the selection problem at 25-1225.

Being Inside The Mail System Is The Whole Technique

The corpus distinguishes carefully between impersonation from outside and instruction from inside. At 25-0806 an employee authorised a connected application because the caller sounded like IT. At 25-0514 authorised support agents performed lookups they were entitled to perform.

Here the instruction arrived from a genuine executive mailbox, in a real thread, with the correct history behind it. No control that checks sender authenticity helps, because the sender was authentic. What was false was the person operating it.

And The Only Defence Is Procedural

Out-of-band verification of payment instructions above a threshold — a phone call to a number held on file, not one supplied in the email. It is unglamorous, cheap, and repeatedly absent, which is the same finding as the volumetric alerting at 25-0612 and the connected-application inventory at 25-1207.

Graded medium: the incident is recorded in an intergovernmental assessment, the company is not named, and this desk cannot establish whether the funds were recovered.

How we reported this

Compiled from INTERPOL’s published regional assessment, listed below, which describes the incident without naming the company. Recovery outcome is not established. Corrections: corrections@forensicpost.com.

Sources
  1. Africa Cyberthreat Assessment Report 2025, 4th editionINTERPOL
  2. Continent experiences sharp rise in cybercrimeAfrica Defense Forum
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary