A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to a Chinese bank; a follow-up $18M ask blew the scheme.
Reviewed by the Social Engineering Examples team.
In May 2014, an accounting director at AFGlobal Corporation (legally Ameriforge Group Inc.) received a series of emails purporting to come from CEO Gean Stalcup, assigning him a "strictly confidential financial operation" tied to a supposed acquisition in China. The emails told him to coordinate only with the CEO and with a purported KPMG attorney, "Steven Shapiro," and warned him not to discuss the matter with anyone to avoid "infringing SEC regulations." "Shapiro" followed up by phone and email with wiring instructions, and on May 21, 2014 the director wired $480,000 to an account at the Agricultural Bank of China. On May 27, the imposter acknowledged receipt and requested a further $18 million; that outsized ask made the director suspicious, and he alerted supervisors, who determined the company had been defrauded. Attempts to recall the wire failed because the receiving account had already been drained and closed. AFGlobal filed an insurance claim; Federal Insurance Co. (a Chubb unit) denied it, and AFGlobal sued in January 2016 (Harris County, Texas; the case later proceeded in the U.S. District Court for the Southern District of Texas). The facts here are drawn from AFGlobal's own court complaint and the insurer's denial letter, both widely reproduced. This record is confirmed as a real, documented incident; the specific attacker was never publicly identified.
This was a textbook business email compromise / CEO-fraud scheme. The attacker impersonated a specific, named executive and layered on a fake outside professional (a "KPMG attorney") to add legitimacy and a plausible reason for urgency and secrecy. The lure exploited authority (a direct instruction from the CEO), urgency ("take priority over other tasks"), and enforced isolation ("only communicate with me through this email... please do not speak with anyone by email or phone") framed as SEC-compliance discipline, which suppressed the natural instinct to verify out-of-band. Per AFGlobal's complaint, the imposter appeared to know the company's normal procedures and that the CEO and the accounting director had a long-standing, personal relationship, so the request did not seem out of character. The wire went to an overseas account that was cashed out and closed almost immediately, defeating recovery.
Lure: an email from the "CEO" naming a confidential deal ("manage file T521"), directing the employee to work only with the CEO and a named attorney and to keep silent to avoid SEC issues, followed by phone-and-email wire instructions from the fake attorney. Tells: the demand for secrecy and single-channel communication (a deliberate block on verification), pressure and urgency around a large wire to a foreign bank, an unusual acquisition/due-diligence narrative, and ultimately the escalation to an implausible $18M request. Any of these should trigger independent, out-of-band verification of the executive and the payment.
The $480,000 was lost and never recovered. The larger $18M request was caught before payment. Federal Insurance denied AFGlobal's claim, arguing the loss did not meet the policy's definitions of computer fraud, funds transfer fraud, or forgery of a financial instrument (since the employee voluntarily authorized the wire and an email is not a negotiable instrument). AFGlobal sued for breach of contract and bad faith. The case is frequently cited alongside Medidata Solutions v. Federal Insurance as a cautionary example that cyber/crime policies may not cover voluntarily-authorized BEC transfers.
One of the early, well-documented CEO-fraud/BEC cases, and a landmark for the insurance-coverage gap it exposed: because a real employee voluntarily initiated the wire, insurers argued it fell outside "computer fraud" and "funds transfer fraud" coverage. It taught finance teams two lessons at once. First, no technical breach is needed; social engineering of a trusted employee is enough. Second, organizations cannot assume cyber insurance will reimburse BEC losses, making prevention and payment controls the real defense.
Require out-of-band verification (a call-back to a known number, not one supplied in the email) for any wire request, especially urgent, confidential, or executive-initiated ones. Treat demands for secrecy and single-channel communication as red flags, not compliance. Enforce dual authorization and a callback threshold for large or foreign wires. Train finance staff that authority, urgency, and secrecy together are the classic BEC pattern, and that even a familiar executive's request must be verified. Use email authentication (SPF/DKIM/DMARC) and external-sender/look-alike-domain warnings. Confirm in advance which insurance policy, if any, covers social-engineering fraud, since standard cyber/crime coverage often excludes voluntarily-authorized transfers.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…