Case Library / Phishing / AFGlobal Corp. $480K CEO-impersonation wire fraud (2014)
Phishing Confirmed

AFGlobal Corp. $480K CEO-impersonation wire fraud (2014)

A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to a Chinese bank; a follow-up $18M ask blew the scheme.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In May 2014, an accounting director at AFGlobal Corporation (legally Ameriforge Group Inc.) received a series of emails purporting to come from CEO Gean Stalcup, assigning him a "strictly confidential financial operation" tied to a supposed acquisition in China. The emails told him to coordinate only with the CEO and with a purported KPMG attorney, "Steven Shapiro," and warned him not to discuss the matter with anyone to avoid "infringing SEC regulations." "Shapiro" followed up by phone and email with wiring instructions, and on May 21, 2014 the director wired $480,000 to an account at the Agricultural Bank of China. On May 27, the imposter acknowledged receipt and requested a further $18 million; that outsized ask made the director suspicious, and he alerted supervisors, who determined the company had been defrauded. Attempts to recall the wire failed because the receiving account had already been drained and closed. AFGlobal filed an insurance claim; Federal Insurance Co. (a Chubb unit) denied it, and AFGlobal sued in January 2016 (Harris County, Texas; the case later proceeded in the U.S. District Court for the Southern District of Texas). The facts here are drawn from AFGlobal's own court complaint and the insurer's denial letter, both widely reproduced. This record is confirmed as a real, documented incident; the specific attacker was never publicly identified.

How the Attack Worked

This was a textbook business email compromise / CEO-fraud scheme. The attacker impersonated a specific, named executive and layered on a fake outside professional (a "KPMG attorney") to add legitimacy and a plausible reason for urgency and secrecy. The lure exploited authority (a direct instruction from the CEO), urgency ("take priority over other tasks"), and enforced isolation ("only communicate with me through this email... please do not speak with anyone by email or phone") framed as SEC-compliance discipline, which suppressed the natural instinct to verify out-of-band. Per AFGlobal's complaint, the imposter appeared to know the company's normal procedures and that the CEO and the accounting director had a long-standing, personal relationship, so the request did not seem out of character. The wire went to an overseas account that was cashed out and closed almost immediately, defeating recovery.

The Lure & the Tell

Lure: an email from the "CEO" naming a confidential deal ("manage file T521"), directing the employee to work only with the CEO and a named attorney and to keep silent to avoid SEC issues, followed by phone-and-email wire instructions from the fake attorney. Tells: the demand for secrecy and single-channel communication (a deliberate block on verification), pressure and urgency around a large wire to a foreign bank, an unusual acquisition/due-diligence narrative, and ultimately the escalation to an implausible $18M request. Any of these should trigger independent, out-of-band verification of the executive and the payment.

Outcome

The $480,000 was lost and never recovered. The larger $18M request was caught before payment. Federal Insurance denied AFGlobal's claim, arguing the loss did not meet the policy's definitions of computer fraud, funds transfer fraud, or forgery of a financial instrument (since the employee voluntarily authorized the wire and an email is not a negotiable instrument). AFGlobal sued for breach of contract and bad faith. The case is frequently cited alongside Medidata Solutions v. Federal Insurance as a cautionary example that cyber/crime policies may not cover voluntarily-authorized BEC transfers.

Why It Matters

One of the early, well-documented CEO-fraud/BEC cases, and a landmark for the insurance-coverage gap it exposed: because a real employee voluntarily initiated the wire, insurers argued it fell outside "computer fraud" and "funds transfer fraud" coverage. It taught finance teams two lessons at once. First, no technical breach is needed; social engineering of a trusted employee is enough. Second, organizations cannot assume cyber insurance will reimburse BEC losses, making prevention and payment controls the real defense.

Defenses

Require out-of-band verification (a call-back to a known number, not one supplied in the email) for any wire request, especially urgent, confidential, or executive-initiated ones. Treat demands for secrecy and single-channel communication as red flags, not compliance. Enforce dual authorization and a callback threshold for large or foreign wires. Train finance staff that authority, urgency, and secrecy together are the classic BEC pattern, and that even a familiar executive's request must be verified. Use email authentication (SPF/DKIM/DMARC) and external-sender/look-alike-domain warnings. Confirm in advance which insurance policy, if any, covers social-engineering fraud, since standard cyber/crime coverage often excludes voluntarily-authorized transfers.

Sources
  • Firm Sues Cyber Insurer Over $480K Loss. Krebs on Security Secondary. Verified live 2026-07-29. Reproduces verbatim quotes from AFGlobal's court complaint and Federal Insurance's Oct. 9, 2014 denial letter, and links to the complaint (PDF) and the insurer's response; strongest primary-adjacent account.
  • Business Email Fraud: Who's Liable?. BankInfoSecurity (ISMG) Secondary. Verified live 2026-07-29. Details the incident and lawsuit filed in Harris County District Court on Jan. 4, 2016; notes claim was reported to the company's bank as fraud.
  • Cyber Crime Victim Sues Insurance Provider for Denying $480,000.00 Claim. ERAI Secondary. Verified live 2026-07-29. Recounts the May 21 and May 27, 2014 events and Agricultural Bank of China destination; references the Federal Insurance denial-of-coverage letter, and notes trial scheduled ~June 26, 2017 in S.D. Texas.
  • Are You Covered Against The Business E-Mail Compromise Scam?. Mondaq (Orrick / Darren S. Teshima) Secondary. Verified live 2026-07-29. Legal analysis confirming the lawsuit (filed Jan. 4, 2016, Harris County, TX), the KPMG-attorney due-diligence-fee ruse, the coverage theories tendered (forgery, computer fraud, funds transfer fraud), and comparison to Medidata and Taylor & Lieberman cases.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: The attacker(s) plausibly researched AFGlobal's corporate leadership and organizational details before making contact, likely drawing on public sources such as press releases, company filings, and professional-networking or corporate-bio pages, to learn the real CEO's name (Gean Stalcup), a plausible business narrative (an overseas acquisition, consistent with AFGlobal's actual oil-and-gas and industrial dealings in China), and enough about internal reporting lines to identify the Director of Accounting as the right target.
Countering Stage 1: Public information about a company's executives, corporate structure, and business activity (M&A plans, overseas dealings) is very hard to eliminate at enterprise scale; the realistic control assumes attackers can learn this and instead hardens the payment-approval process that this knowledge would otherwise be used to exploit.
2
Persona and pretext setup: The attacker built a spoofed or look-alike sender identity for the CEO and invented a second, corroborating persona, a fictitious "KPMG attorney" borrowing a real, well-known accounting firm's name, to make the eventual wire request appear to come from two independent, credible sources rather than one.
Countering Stage 2: Email authentication controls (SPF, DKIM, DMARC) and external-sender or look-alike-domain warning banners can flag a spoofed or lookalike executive sender identity before it ever reaches the target's inbox.
3
Initial phishing contact: A message purporting to be from the CEO reached the accounting director, assigning him a "strictly confidential financial operation," invoking SEC-compliance secrecy, and instructing him to communicate only through that single channel, pre-emptively shutting down normal verification habits.
Countering Stage 3: Train employees to treat any instruction demanding confidentiality and single-channel communication as a red flag rather than a legitimate compliance requirement, and require independent verification of unusual high-value or urgent requests regardless of the stated justification.
4
Trust reinforcement via secondary impersonation: Shortly after, the fake KPMG attorney contacted the director by phone and email, corroborating the CEO's story and supplying specific wire instructions for a China-acquisition "due diligence fee," adding social proof and urgency on top of the initial authority pressure.
Countering Stage 4: Mandate out-of-band verification, a callback to an independently sourced phone number, never one supplied in the suspect email or by the caller, for any payment instruction that arrives through or is corroborated by a third party claiming to act on an executive's behalf.
5
Fraudulent wire execution: Under combined authority, urgency, and secrecy pressure, and with normal out-of-band verification discouraged by the pretext itself, the director wired $480,000 to an account at the Agricultural Bank of China.
Countering Stage 5: Enforce dual authorization and a mandatory callback-verification threshold for large or first-time international wire transfers, so a single employee's authorization is never sufficient to release funds of this size.
6
Cash-out and objective completion: The recipient account was emptied and closed almost immediately after the transfer cleared, completing the theft and defeating AFGlobal's and its bank's attempts to recall the funds before the fraud was discovered.
Countering Stage 6: Once money has cleared into a foreign account, recovery is largely outside the victim organization's control; the closest thing to a control here is banks and payment processors monitoring for rapid deposit-then-empty-and-close activity on newly funded accounts, but the real point of prevention remains the dual-authorization and callback controls in Stage 5.
Quick Facts
Victim
AFGlobal Corporation (Ameriforge Group Inc.), a Houston, Texas manufacturer serving the oil/energy and aerospace markets; direct victim was Director of Accounting Glen Wurm.
Location
Houston, Texas, USA
Date
2014-05-21
Impact
$480,000 wired and unrecoverable (recipient account at Agricultural Bank of China was emptied and closed shortly after transfer). A second fraudulent request for $18,000,000 was stopped. Loss became the subject of a coverage dispute over a policy covering up to $3M with a $100,000 deductible.
Status
Confirmed
Case Type
Real-World Incident
Sector
Defense & Aerospace, Manufacturing & Industrial
Related

Related Cases

Scoular Company $17.2M grain-trader wire fraud (2014)

Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…

Incident 2014Read →

Sony Pictures 'Guardians of Peace' hack: fake Apple ID emails to admins

North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated…

Incident 2014Read →

Ubiquiti Networks $46.7M business email compromise (2015)

Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…

Incident 2015Read →