CSIDB logo
Incident

Breetec International

Incident posture

Attack window
May 2015
Location
Belgium
Status
Historical
CIA posture
Available to members
Updated
2026-01-15 12:19

Linked entities

Victim
Breetec International
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers compromised a Belgium metal company and several other businesses using malware targeting the Isabel payment system, distributed via malicious email attachments disguised as important documents. Upon execution, the malware created fraudulent transactions within the payment queue, leveraging legitimate user authentication for other transactions to authorize unauthorized transfers to foreign accounts, including one traced to Dubai. The breach resulted in a financial loss of 80,000 euros from the targeted organization.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In May 2015, Belgian metal company Breetec International and several other Belgium-based organizations fell victim to a financially motivated cyberattack targeting the Isabel electronic payment platform. The attackers deployed malware through phishing emails disguised as legitimate communications containing important attachments. When employees opened these malicious attachments, the malware executed on their devices and covertly established fraudulent Isabel payment transactions within the system's queue. The malware operated by waiting for legitimate user authentication of routine transactions before automatically executing its own unauthorized transfers to foreign bank accounts, exploiting the authenticated session to bypass security checks. This attack methodology allowed the malicious transactions to blend with normal business activities until completion.

Breetec International suffered direct financial losses totaling 80,000 euros from these fraudulent transfers. The company detected the compromise through transaction monitoring and successfully traced one of the unauthorized payments to a bank account located in Dubai. While Breetec identified this destination, the article did not specify whether funds were recovered or if law enforcement investigations ensued. The incident impacted multiple Belgian companies using the Isabel system, though Breetec was the only specifically named victim. No technical details about malware containment, system remediation, or broader operational disruptions were disclosed in the available reporting. The attack demonstrated deliberate targeting of financial transaction systems through social engineering and session hijacking techniques.

Sources

Sources available to members: 1 source.

CSIDB