International Edition
Latest News
World

BEC Scam Steals €35 Million From French Notaries

A sophisticated Business Email Compromise (BEC) campaign has defrauded French notaries of €35 million, according to cyber intelligence reports detailing a targeted financial cyberattack against the legal sector. The incident highlights vulnerabilities in high-value real estate and corporate…

BEC Scam Steals €35 Million From French Notaries

A sophisticated Business Email Compromise (BEC) campaign has defrauded French notaries of €35 million, according to cyber intelligence reports detailing a targeted financial cyberattack against the legal sector. The incident highlights vulnerabilities in high-value real estate and corporate transactions where massive funds move rapidly through traditional wire transfers.

Anatomy of the Notary Cyberattack

According to security researchers tracking the incident, attackers infiltrated the communication channels of French notarial offices to intercept legitimate property and corporate transactions. By executing precise social engineering tactics, the fraudsters manipulated staff into redirecting substantial escrow and client funds into attacker-controlled bank accounts. The €35 million loss represents one of the largest sector-specific BEC strikes recorded against European legal professionals in recent years.

BEC operations typically rely on prolonged reconnaissance, where threat actors monitor corporate email threads for months. Once they identify an impending transaction involving large sums, they deploy domain spoofing or compromised credentials to insert fraudulent payment instructions just as funds are due to transfer.

Financial Impact on the French Legal Sector

Notarial offices handle billions of euros annually in property purchases, inheritances, and corporate acquisitions, making them prime targets for cybercriminals seeking high-yield payouts. According to industry observations, these attacks bypass standard perimeter security by exploiting human trust and routine administrative workflows rather than raw technical exploits.

Unlike traditional ransomware attacks that lock computers and demand crypto ransoms with public exposure, BEC operations remain quiet. Attackers siphon funds silently, often routing money across multiple international accounts before victims realize the transfer destination is fraudulent.

Mitigation and Prevention for Legal Practices

Cybersecurity authorities emphasize that preventing similar losses requires strict out-of-band verification protocols for any wire transfer modification. According to incident response guidelines, staff must verify banking detail changes via a trusted telephone number or in-person confirmation rather than replying to an email thread.

BEC Scam Steals €35 Million From French Notaries
  • Implement multi-factor authentication (MFA) across all email accounts used by legal staff.
  • Establish mandatory dual-authorization workflows for dispersing funds exceeding defined thresholds.
  • Train employees to spot subtle domain spoofing and unusual requests for urgent wire re-routing.

Frequently Asked Questions

What is a Business Email Compromise (BEC) attack?

A BEC attack involves cybercriminals gaining unauthorized access to business email accounts or spoofing domains to trick organizations into wiring funds to fraudulent accounts.

Why are notaries targeted by cybercriminals?

Notaries regularly oversee the transfer of large sums of money for property and estate transactions, presenting lucrative opportunities for fraudsters.

How can law firms prevent BEC fraud?

Firms can stop these attacks by enforcing strict secondary verification steps over the phone before executing any changes to payment instructions.

About the author: Ibrahim Khalil - World Editor

PhD in International Relations, former UN press officer. Ibrahim has reported from 40+ countries, translating complex geopolitical shifts into clear, human‑focused narratives. “Ibrahim Khalil provides authoritative world news, from diplomacy to conflict zones, with on‑the‑ground insight.”