Skip to main content

A growing email scam has cost a major airline millions of dollars

email scam tricks major airline japan airlines
Japan Airlines
As individuals, we all know we have to keep our wits about us when we’re online. If you’re really unlucky, a couple of ill-considered clicks or downloads could quickly ensnare you in a scam that ends up costing you hundreds of dollars, possibly more.

But if you’re working for a company and your job is to make big payments to other businesses, the stakes are much higher. And yes, even global players can get caught out.

Recommended Videos

Take Japan Airlines (JAL). This week the international carrier admitted it had fallen victim to an email scam that cost it a not-insignificant 384 million yen (about $3.39 million).

Please enable Javascript to view this content

Known as “invoice redirect” or “business email compromise,” it seems that at least one JAL employee was tricked into making several payments to bogus bank accounts. One account purported to belong to a U.S. financial services company which had been leasing a plane to the airline, but it had in fact been set up by fraudsters, the Japan Times reported.

In such cases, cybercriminals first hack the service-providing company’s email system to gain information about its business procedures before using the gathered data to approach its customers for due payments. Posing as the company, the scammers contact the customer by email, even going so far as to imitate the writing style of the person that usually sends such emails. The correspondence will include invoice and bank details, and if the two companies have a history of doing business, there might even be a bogus explanation as to why the bank information has changed.

Recipients sometimes fail to spot the red flag presented by the change in bank details as they’re already expecting to make the payment to the company, so in their eyes nothing seems out of the ordinary.

In JAL’s case, an employee first transferred around 360 million yen ($3.17 million) to the criminal’s Hong Kong account for the lease of a plane when they believed they were paying into the account of the financial services company. This was soon followed by another payment of around 24 million yen ($212,000) into a different Hong Kong account that JAL thought belonged to an American logistics firm it had had dealings with. In the case of the first transaction, JAL only realized it had been scammed a month later when the company got in touch to inquire about its payment.

The incidents took place in September but came to light this week when the airline revealed it was working with law enforcement in a bid to find the perpetrators and track down the money.

In a similar incident reported on Thursday, December 21, scammers tricked officials at Dublin Zoo in Ireland into paying 500,000 euros ($590,000) into a fake account. Fortunately for the company, 370,000 euros ($440,000) of the total amount has been frozen and will be returned to the zoo, though the remainder may be lost.

The sting, which has become more prevalent in the last couple of years, targets companies big and small around the world. Experts suggest that an employee making a payment to an outside company first call it to confirm the validity of the emailed invoice and also the bank details contained within it, and to call again once the funds have been sent to ensure they’ve been received.

Cases like this surged in the U.S. last year, with fraudsters attempting to steal a total of more than $5.3 billion, the FBI said.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
The massive LastPass hack from 2022 is still haunting us
LastPass website on a laptop.

Just when you thought the LastPass breach of 2022 was over, we're still learning just how detrimental the hack was. According to blockchain expert ZachXBT and spotted by The Block, $5.36 million was stolen from 40 users in a string of attacks. This is on top of the $4.4 million stolen in October 2023 and $6.2 million earlier this year in February 2024.

The original hack goes back to 2022 when hackers claimed to have accessed LastPass' data, which contained API tokens, customer keys, multifactor authentication seeds (MFA), and encrypted password vaults. Although no official information explains how the breach happened, it's possible that the hacker responsible gained access to information that aided the breach. Hackers forced their way in despite the password vaults being encrypted because users reused weak or previously leaked combinations. This access, combined with the users' weak or reused passwords, led to the various accounts being compromised.

Read more
Apple Maps for web adds Look Around, its Street View-like feature
Apple Maps' Look Around feature on the web.

Apple launched Apple Maps for the web five months ago, but it was in beta and had limited features. As it gradually builds it up to become a serious competitor to Google Maps, Apple has now added Look Around, its own version of Street View that lets you explore your surroundings via panoramic imagery collected by camera-equipped cars, 9to5Mac reported. Look Around launched for Apple Maps' mobile and desktop versions in 2019, so it's great to see that it's finally made it to the web version.

You can use the Look Around feature on Apple Maps for the web by selecting the binoculars icon at the top right of the display. Similar to the Apple Maps desktop app, you click on the image to proceed along the street in a satisfyingly smooth way, or drag the picture around to survey your surroundings. When you launch it, the Look Around view only takes up a portion of the display, so as you move along the street, you can check the binoculars icon to keep track of your current position. You can also go full-screen by selecting the arrows on the Look Around viewer.

Read more
Get a 4070 Super Alienware gaming PC for $1,800 during Dell’s sale
Alienware Aurora R16 sitting on a coffee table.

If you’re a big gamer, the best desktop computer deals aren’t what you need. Instead, you want to track down the best gaming PC deals. Luckily, f you're reading this, we’ve done all the hard work for you. Right now, you can buy the Alienware Aurora R16 gaming desktop with a Nvidia GeForce RTX 4070 Super GPU for $1,800. It normally costs $2,210 so you’re saving $410 off the regular price and scoring a gaming PC that is built to last. If you want to game in style this holiday season, here’s all you need to know before you hit the buy button.

Why you should buy the Alienware Aurora R16 gaming desktop
The Alienware Aurora R16 tops our look at the best gaming PCs. This particular model has a 14th-generation Intel Core i7-14700F CPU teamed up with 32GB of RAM and 2TB of SSD storage -- aka the fast stuff across the board. It also has an Nvidia GeForce RTX 4070 Super graphics card with 12GB of dedicated VRAM, so you’ll be playing all your favorites at high detail levels for a while to come.

Read more