Analysis · Economic criminal law · 18 July 2026

Financial cybercrime: online fraud, phishing, compromised accounts.

The accountant receives, by e-mail, an invoice from a supplier the company has worked with for years. The letterhead is correct, the amount is correct, only the IBAN is different, “we changed banks”. The payment goes out. Three weeks later, the supplier asks for its money. It is the same money, but it landed in a different account, in a different country, from where it was withdrawn within hours. No one hacked anything: someone read the correspondence, waited for the right moment and changed twenty-four characters.

Map of the offences

There is no offence called “online fraud”.

This is, statistically, the most frequent fraud hitting Romanian companies, and the most poorly handled legally, because the first reaction is anger, not procedure. This material explains which offences are involved, who bears the loss, what to do in the first hours and why the victim company can, without meaning to, become a suspect company. It is an informational analysis, not advice, and contains no promise of a result.

Computer fraud (Article 249)

Introducing, altering or deleting computer data, restricting access to it, or hindering the functioning of a computer system, in order to obtain a material benefit, where a loss has been caused: imprisonment of two to seven years. This is the umbrella provision for most fraud involving money.

Fraudulent financial operations (Article 250)

Withdrawing cash, loading or unloading an electronic money instrument, or transferring funds, monetary value or virtual currency, by using, without the holder's consent, a cashless payment instrument or the data enabling its use: two to seven years. Unauthorised transmission to another person of identification data, for the purpose of such an operation: one to five years.

Computer-related forgery (Article 325)

Introducing, altering or deleting, without right, computer data, or restricting access to it, resulting in data that does not correspond to the truth, for the purpose of its being used to produce a legal consequence: one to five years. This is the provision for a forged invoice or a fabricated e-mail, distinguished from classic forgery of documents.

Illegal access to a computer system (Article 360)

Three months, three years, or a fine; if the act is committed in order to obtain computer data, six months, five years; if it concerns a system to which access is restricted by security measures, two to seven years.

Interference with data integrity (Article 362)

Altering, deleting or damaging computer data, or restricting access to it, without right: one to five years. This is the basic provision in ransomware cases, alongside Article 249.

Illegal operations with devices (Article 365)

Producing, importing, distributing or making available devices, programs, passwords or access codes intended for committing the offences under Articles 360 to 364: six months, three years, or a fine; mere possession, without right, for the same purpose: three months, two years, or a fine.

NOTE: Not every prosecutor's office has jurisdiction. Computer offences fall, as a rule, within the jurisdiction of DIICOT. Do not file the complaint “wherever is closest” without checking, a complaint filed with the wrong office gets referred elsewhere, and that referral costs exactly the resource that is missing: time.

Typologies

The frauds that hit companies.

Three mechanisms cover most of these cases. All of them exploit the procedure, not the technology.

The invoice with the changed IBAN. The mechanism is simple, which is why it works. The attacker compromises a mailbox, yours or the supplier's, reads the correspondence for weeks, learns the tone, identifies the large invoices and steps in at exactly the right moment. Sometimes there is no compromise at all: the attacker registers a domain that differs by one letter and sends the message from there.

Legally, the key point is this: the transfer is authorised. The company ordered the payment; the bank executed a valid order. This is not a case of an unauthorised transaction, where payment-services legislation obliges the provider to refund the amount. The civil-law consequence is harsh: a payment made to someone other than the creditor does not discharge the debt. The supplier can still claim the price. The loss remains, as a rule, with the payer, who then has a claim for damages against the perpetrator of the fraud, a person who, as a rule, cannot be identified or has no assets.

There are also genuine counter-arguments, which are put on the table in negotiations with the supplier: if the breach was in the supplier's own system, its fault contributed to causing the loss, and the loss can be shared. If the bank executed a transfer to a beneficiary whose name did not match the IBAN and it had a duty to check this, the discussion shifts partly there. These are arguments for negotiation and for civil proceedings, not certainties.

CEO fraud (Business Email Compromise). An e-mail “from the director”, sent on a Friday at 16:30, requests an urgent, confidential transfer for an acquisition that “no one must find out about”. Hierarchical pressure plus urgency plus secrecy: the three ingredients that switch off the procedure. The typical classification is computer fraud in concurrence with computer-related forgery, and, if there was intrusion into the mailbox, illegal access as well.

Employee phishing and compromised accounts. A fake login form, a “security update”, an attached file. Once inside, the attacker has access to e-mail, to applications and, sometimes, to online banking. Here the basic provision is Article 360, and if payments were made, Articles 249 and 250 as well.

Ransomware

Is it lawful to pay the ransom?

The question comes up in every case. The cautious answer: the payment itself is not, as such, criminalised under Romanian law, but it is not neutral either. There are three real risks.

Risk 01

International sanctions

If the group of attackers or the recipient wallet appears on the restrictive-measures lists of the Union or of other jurisdictions, the payment may constitute a breach of the sanctions regime.

Risk 02

Money laundering

The payment circuit triggers reporting obligations for the entities involved in the intermediation and can raise, for the company, the question of money laundering or of terrorist financing.

Risk 03

The payment guarantees nothing

Not the decryption key, not the non-publication of the data, not the absence of a second attack.

NOTE, the sanctions regime has been tightened. Through Legea nr. 344/2025, which amended O.U.G. nr. 202/2008 on the implementation of international sanctions, transposing Directive (EU) 2024/1226, a breach of the Union's restrictive measures, including making funds or economic resources available to a designated person, entity or body, moved from the administrative-violation category into the criminal one, with aggravated forms depending on the nature of the assets and the value involved. Prosecution of these acts falls to DIICOT. The decision whether to pay or not is therefore taken after a sanctions check and with legal assistance, not in the panic of the first hours. Regardless of that decision, the attack generates its own notification obligations.

Victim or suspect

The company that receives the money.

This scenario is more common than it seems. A company receives an unexpected payment from an unknown client, “by mistake”, followed by a request to refund it to a different account. Or a “partner” proposes to use the company's account temporarily for a transfer, for a fee. In both cases, the company becomes a money mule, a link in the circuit of money coming from fraud.

The consequence is not that the company loses the money. The consequence is that the director can be investigated for money laundering, where the accepted form of fault in practice also covers the situation in which the perpetrator ought to have known that the assets came from the commission of offences. “I did not ask” is not a defence; sometimes it is itself the evidence. How a money circuit is read is also described in the analysis on the money trail and the risk of money laundering.

What to do if you receive suspicious money: do not transfer it onward and do not spend it; notify the bank immediately, in writing; document its origin (who, when, what explanation was given); if a request comes in to refund it to an account different from the one it came from, refuse and report it. Refunds should be made, where appropriate, to the account of origin, through the bank.

The first hours

What to do, in order.

The useful window is measured in hours, not days. The money usually passes through one or two intermediate accounts and is withdrawn or converted quickly.

Step 01

Call the bank immediately

By phone, not by e-mail. Ask for a recall of the transfer and for the amount to be frozen at the beneficiary bank. Ask for the reference number of the request.

Step 02

Confirm in writing

The request to the bank, on the same day.

Step 03

Isolate the compromised system

But do not wipe it and do not reinstall it: that is where the evidence is.

Step 04

Change the passwords

And enable two-factor authentication on all e-mail and banking accounts.

Step 05

File the criminal complaint

As soon as possible, international judicial cooperation to freeze the beneficiary account depends on a file existing. The later stages are the same as in any criminal prosecution, and recovery goes through precautionary measures.

Step 06

Notify the other party

The supplier or the client, in writing: they too may be compromised, they too can take action. If the money went to another country, the considerations in the analysis on foreign accounts are also relevant.

Step 07

Check your notification obligations

If personal data was affected, the 72-hour clock is already running.

Step 08

Notify the insurer

If you hold a cyber policy: most policies require notification within short deadlines, on pain of forfeiture.

The evidence

The effective criminal complaint.

A complaint that says “we were defrauded, please investigate” predictably produces a discontinuance. A useful complaint contains technical evidence, correctly preserved.

The complete headers

Not screenshots, but the original e-mail file, exported, that is where you see the servers the message passed through and the sender's real address.

The access logs

For the mailbox and for the affected systems: IP addresses, times, devices. Request these from the e-mail provider immediately, they have limited retention periods.

The statements and the payment order

With the exact time of execution.

The forged invoice

And the original invoice, for comparison.

The full correspondence

With the real partner, showing the moment of the intervention.

The technical reports

Antivirus, EDR, firewall and, if needed, a forensic image of the affected storage, made by a specialist.

The golden rule: preserving evidence takes priority over restoring operations. An IT person who “cleans” the server so people can work on Monday morning destroys, in good faith, the only chance of identifying the attacker.

If the matter involves a criminal complaint or an open file, the related analyses are grouped under economic criminal law. For how the defence is built, see defence in economic offences.

Compliance

Security and notification obligations.

Notifying the data breach. If the incident affected personal data, the controller has an obligation to notify the supervisory authority, ANSPDCP, within no more than 72 hours of becoming aware of the breach (Article 33 of the General Data Protection Regulation), and, if the risk to the data subjects is high, also has an obligation to inform them (Article 34). The time limit runs from the moment of becoming aware, not from the completion of the internal investigation, a notification made in stages is preferable to a late one.

NIS2. The Directive was transposed by OUG nr. 155/2024, approved by Legea nr. 124/2025 (in force since 10 July 2025), with DNSC as the authority. From 20 August 2025, DNSC Orders no. 1/2025 and no. 2/2025 entered into force, governing the registration notification process (30-day deadline) and the risk-assessment criteria. Fines can reach 10 million euros or 2% of worldwide annual turnover for essential entities, and 7 million euros or 1.4% for important entities, and management is personally liable for training and governance.

Who falls under NIS2, the size rule

Essential entities are large undertakings, over 250 employees or annual net turnover above 50 million euros or assets of 43 million euros, lei equivalent, from sectors of high critical importance (energy, transport, health, water, banking, digital infrastructure, management of ICT services, space, public administration and others). Important entities are large and medium undertakings from the sectors of high critical importance and critical importance (postal and courier services, waste, chemicals, food, manufacturing, digital providers, research) that are not identified as essential.

Who falls in regardless of size

Classification does not depend on size for central public administration entities, for critical entities, and, categories with a direct impact on the market, for DNS service providers, TLD name registries and qualified trust service providers. The check is therefore made in two steps: first the field of activity, then the size.

Incident reporting

The regime is staged and is measured in hours: an initial warning, followed by a full notification and a final report. The exact deadlines, significance thresholds and reporting channel result from OUG nr. 155/2024 and from the DNSC regulations, and differ by category of entity, and must be checked specifically, before an incident, not during one.

Micro-enterprises

Most micro-enterprises and small companies remain, as a rule, outside the scope of NIS2, but not all of them: in the categories above, classification applies regardless of size, and the obligations can also reach a small company contractually, as a supplier of a regulated entity.

DORA. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector applies from 17 January 2025, is directly applicable and does not concern ordinary companies: it targets financial entities, banks, investment firms, payment institutions, insurers, crypto-asset service providers and, indirectly, their critical ICT providers. If your company provides IT services to a financial entity, DORA reaches you through the contract.

For small entities within its scope, the Regulation does not provide an exemption, but a simplified ICT risk-management framework (Article 16), applicable to expressly listed categories, including small and non-interconnected investment firms, certain exempted institutions and financial micro-enterprises. These entities remain obliged to maintain a documented risk-management framework, to monitor their systems, to ensure business continuity through back-up and recovery measures, and to report major incidents, but they are exempted from part of the governance architecture imposed on large entities. The principle of proportionality, enshrined in the Regulation, governs its entire application.

Prevention

What actually works.

No corporate security budget is needed. What is needed is a written procedure, with one firm rule.

Telephone confirmation of the IBAN

Any change of IBAN is confirmed by phone, on a number from your own records, never on the number given in the e-mail announcing the change.

Dual signature

For payments above an internally set threshold.

Two-factor authentication

On e-mail and banking, with no exceptions for management.

“No urgency suspends the procedure”

A rule communicated explicitly by the director, so that the employee does not fear being blamed for delaying a payment requested by “the boss”.

Training on real scenarios

A simulated phishing exercise says more than ten presentations.

Cyber insurance, checked for exclusions

Many policies exclude precisely social-engineering fraud, unless a dedicated extension has been purchased.

Frequently asked questions

In brief, on cyber fraud.

Will the bank refund the money I paid on the invoice with the forged IBAN?

As a rule, no. Mandatory reimbursement concerns unauthorised transactions, those made without your consent. Here, the payment was ordered by the company, so it is authorised; the error concerns the recipient, not the authorisation. For comparison, in the case of a genuinely unauthorised transaction, Article 176 of Legea nr. 209/2019 on payment services limits the payer's consequences to the equivalent of no more than 30 euros, where the transaction results from the use of a payment instrument that was lost, stolen or used without right, and the payer did not act fraudulently and did not intentionally breach its obligations. Any fault of the bank in executing the order or in the checks it owed remains open for discussion.

The supplier is asking me for the money again. Do I have to pay twice?

From a strictly legal point of view, paying a third party does not release you from the debt. In practice, however, the discussion is about each party's fault: whether the breach was in the supplier's system, whether it sent the invoice from a compromised account, whether there was a verification procedure that one of the parties failed to follow. Many such situations are resolved through a negotiated sharing of the loss.

I paid the ransom and recovered the data. Is a complaint still worth filing?

Yes, for three reasons: notification obligations exist independently of payment; paying a sanctioned entity exposes you, and a file where you reported the incident immediately looks different from one where you stayed silent; and identifying the group can, through international cooperation, open a route to recovery.

Can the director of the victim company be prosecuted?

As a victim, no. But they can be investigated for related acts of their own: if the company received and then passed on money coming from the fraud (money laundering), if it concealed a data breach it was obliged to notify, or if it destroyed evidence. The presumption of innocence still applies, but these risks are managed from day one, not from the first interview.

Informational material, updated on 18 July 2026. It does not constitute legal or tax advice; individual situations must be analysed specifically, on the evidence in each case. No statement in this material amounts to a promise of a result.

Contact

Have you received a notice or an inspection notification from ANAF?

Time limits run from the date of communication. A first conversation clarifies what is being alleged, what you need to substantiate and how the defence is built, before an estimate becomes a tax assessment decision.

E-mail[email protected]
Phone+40 799 597 410
AvailabilityNational and international · office in Brașov