A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to a Chinese bank.
Social Engineering Examples·4 sources
In May 2014, an accounting director at AFGlobal Corporation (legally Ameriforge Group Inc.) received a series of emails purporting to come from CEO Gean Stalcup, assigning him a "strictly confidential financial operation" tied to a supposed acquisition in China. The emails told him to coordinate only with the CEO and with a purported KPMG attorney, "Steven Shapiro," and warned him not to discuss the matter with anyone to avoid "infringing SEC regulations." "Shapiro" followed up by phone and email with wiring instructions, and on May 21, 2014 the director wired $480,000 to an account at the Agricultural Bank of China.
On May 27, the imposter acknowledged receipt and requested a further $18 million; that outsized ask made the director suspicious, and he alerted supervisors, who determined the company had been defrauded. Attempts to recall the wire failed because the receiving account had already been drained and closed. AFGlobal filed an insurance claim; Federal Insurance Co. (a Chubb unit) denied it, and AFGlobal sued in January 2016 (Harris County, Texas; the case later proceeded in the U.S. District Court for the Southern District of Texas).
The facts here are drawn from AFGlobal's own court complaint and the insurer's denial letter, both widely reproduced. This record is confirmed as a real, documented incident; the specific attacker was never publicly identified.
This was a textbook business email compromise / CEO-fraud scheme. The attacker impersonated a specific, named executive and layered on a fake outside professional (a "KPMG attorney") to add legitimacy and a plausible reason for urgency and secrecy. The lure exploited authority (a direct instruction from the CEO), urgency ("take priority over other tasks"), and enforced isolation ("only communicate with me through this email... please do not speak with anyone by email or phone") framed as SEC-compliance discipline, which suppressed the natural instinct to verify out-of-band.
Per AFGlobal's complaint, the imposter appeared to know the company's normal procedures and that the CEO and the accounting director had a long-standing, personal relationship, so the request did not seem out of character. The wire went to an overseas account that was cashed out and closed almost immediately, defeating recovery.
Lure: an email from the "CEO" naming a confidential deal ("manage file T521"), directing the employee to work only with the CEO and a named attorney and to keep silent to avoid SEC issues, followed by phone-and-email wire instructions from the fake attorney. Tells: the demand for secrecy and single-channel communication (a deliberate block on verification), pressure and urgency around a large wire to a foreign bank, an unusual acquisition/due-diligence narrative, and ultimately the escalation to an implausible $18M request.
Any of these should trigger independent, out-of-band verification of the executive and the payment.
The $480,000 was lost and never recovered. The larger $18M request was caught before payment. Federal Insurance denied AFGlobal's claim, arguing the loss did not meet the policy's definitions of computer fraud, funds transfer fraud, or forgery of a financial instrument (since the employee voluntarily authorized the wire and an email is not a negotiable instrument).
AFGlobal sued for breach of contract and bad faith. The case is frequently cited alongside Medidata Solutions v. Federal Insurance as a cautionary example that cyber/crime policies may not cover voluntarily-authorized BEC transfers.
One of the early, well-documented CEO-fraud/BEC cases, and a landmark for the insurance-coverage gap it exposed: because a real employee voluntarily initiated the wire, insurers argued it fell outside "computer fraud" and "funds transfer fraud" coverage. It taught finance teams two lessons at once. First, no technical breach is needed; social engineering of a trusted employee is enough.
Second, organizations cannot assume cyber insurance will reimburse BEC losses, making prevention and payment controls the real defense.
Require out-of-band verification (a call-back to a known number, not one supplied in the email) for any wire request, especially urgent, confidential, or executive-initiated ones. Treat demands for secrecy and single-channel communication as red flags, not compliance. Enforce dual authorization and a callback threshold for large or foreign wires. Train finance staff that authority, urgency, and secrecy together are the classic BEC pattern, and that even a familiar executive's request must be verified.
Use email authentication (SPF/DKIM/DMARC) and external-sender/look-alike-domain warnings. Confirm in advance which insurance policy, if any, covers social-engineering fraud, since standard cyber/crime coverage often excludes voluntarily-authorized transfers.
Social Engineering Examples. “AFGlobal Corp. $480K CEO-impersonation wire fraud (2014)”. Accessed 19 September 2026. https://socialengineeringexamples.com/afglobal-ceo-fraud-bec-2014
The attacker(s) plausibly researched AFGlobal's corporate leadership and organizational details before making contact, likely drawing on public sources such as press releases, company filings, and professional-networking or corporate-bio pages, to learn the real CEO's name (Gean Stalcup), a plausible business narrative (an overseas acquisition, consistent with AFGlobal's actual oil-and-gas and industrial dealings in China), and enough about internal reporting lines to identify the Director of Accounting as the right target.
Public information about a company's executives, corporate structure, and business activity (M&A plans, overseas dealings) is very hard to eliminate at enterprise scale; the realistic control assumes attackers can learn this and instead hardens the payment-approval process that this knowledge would otherwise be used to exploit.
The attacker built a spoofed or look-alike sender identity for the CEO and invented a second, corroborating persona, a fictitious "KPMG attorney" borrowing a real, well-known accounting firm's name, to make the eventual wire request appear to come from two independent, credible sources rather than one.
Email authentication controls (SPF, DKIM, DMARC) and external-sender or look-alike-domain warning banners can flag a spoofed or lookalike executive sender identity before it ever reaches the target's inbox.
A message purporting to be from the CEO reached the accounting director, assigning him a "strictly confidential financial operation," invoking SEC-compliance secrecy, and instructing him to communicate only through that single channel, pre-emptively shutting down normal verification habits.
Train employees to treat any instruction demanding confidentiality and single-channel communication as a red flag rather than a legitimate compliance requirement, and require independent verification of unusual high-value or urgent requests regardless of the stated justification.
Shortly after, the fake KPMG attorney contacted the director by phone and email, corroborating the CEO's story and supplying specific wire instructions for a China-acquisition "due diligence fee," adding social proof and urgency on top of the initial authority pressure.
Mandate out-of-band verification, a callback to an independently sourced phone number, never one supplied in the suspect email or by the caller, for any payment instruction that arrives through or is corroborated by a third party claiming to act on an executive's behalf.
Under combined authority, urgency, and secrecy pressure, and with normal out-of-band verification discouraged by the pretext itself, the director wired $480,000 to an account at the Agricultural Bank of China.
Enforce dual authorization and a mandatory callback-verification threshold for large or first-time international wire transfers, so a single employee's authorization is never sufficient to release funds of this size.
The recipient account was emptied and closed almost immediately after the transfer cleared, completing the theft and defeating AFGlobal's and its bank's attempts to recall the funds before the fraud was discovered.
Once money has cleared into a foreign account, recovery is largely outside the victim organization's control; the closest thing to a control here is banks and payment processors monitoring for rapid deposit-then-empty-and-close activity on newly funded accounts, but the real point of prevention remains the dual-authorization and callback controls in Stage 5.
Browse by what this case has in common with others in the library.
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
Treasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China.
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
A single vishing call impersonating Carnival's own IT security team convinced an employee to hand over credentials.