Online Fraud Steals €780,000 from Bosnian Ammunition Manufacturer

Bosnia and Herzegovina-based Igman d.d. Konjic, one of the largest manufacturers of military and sporting ammunition in Southeast Europe, has fallen victim to an online fraud scheme in which approximately €780,000 was stolen from the company’s bank account. According to the information available so far, the attackers did not compromise Igman’s internal systems but instead gained access to the email account of one of its suppliers. This allowed them to monitor business correspondence and, at the crucial moment, send modified payment instructions containing fraudulent SWIFT and IBAN details. As the message appeared to be part of the companies’ regular business communication, the payment was transferred to an account controlled by the attackers, after which the funds were routed through multiple foreign bank accounts to make tracing more difficult.

Cybersecurity experts warn that attacks of this type, known as Business Email Compromise (BEC), are among the most costly forms of cybercrime and are becoming increasingly sophisticated with the help of artificial intelligence, which enables highly convincing phishing messages and greater attack automation. Following the incident, renewed calls have been made to strengthen Bosnia and Herzegovina’s national cybersecurity capabilities, including the adoption of a national cybersecurity strategy and the establishment of a functional Computer Emergency Response Team (CERT).

The case has also raised concerns about security procedures for financial transactions, as payments of such significant amounts should be protected by additional verification measures, including multi-level authorization and independent confirmation of any changes to banking details before funds are transferred.

Related Posts