A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M and $2.0M.
Social Engineering Examples·9 sources
By at least May 2021, Joel Zubaid, David Goran, Julian Rebiga and Martin Mizrahi had obtained unauthorized access to the business email account of the CFO of Brownsville Community Development Corporation (referred to in court filings as 'Corporation-1'). Using the compromised CFO mailbox, the conspirators sent fraudulent wire instructions to the bank holding the corporation's account; between on or about May 12 and June 1, 2021, the bank executed a series of wires totaling approximately $3,488,000 out of Corporation-1's account, with roughly $1,570,000 routed into an account controlled by Zubaid and Goran (the 'Goran Account').
By at least June 2021, the group similarly compromised the email account of an employee at a private-equity-owned portfolio company ('Corporation-2'). On or about June 28, 2021, they used that mailbox to send fraudulent wire instructions for a contractual payment owed to the employee, redirecting it to an account controlled by Zubaid and Rebiga (the 'Rebiga Account'); on or about July 1, 2021, Corporation-2 wired approximately $2,008,034.76 to that account.
In both cases, funds were rapidly moved through additional accounts controlled by co-conspirators and converted to Bitcoin to obscure the trail; when a bank froze one of the receiving accounts, the conspirators allegedly made misrepresentations to the bank to try to unfreeze and recover the funds. A December 2022 indictment (superseded December 2023) charged the four with conspiracy to commit wire and bank fraud, wire fraud, bank fraud, conspiracy to commit money laundering, money laundering, aggravated identity theft, and conspiracy to operate an unlicensed money-transmitting business.
Zubaid and Goran later pleaded guilty and became cooperating witnesses. Mizrahi went to trial and, per the court's own opinion denying his post-trial motion, his money-laundering conduct in the case spanned three distinct schemes: laundering the Brownsville BEC proceeds, laundering drug-cartel cash proceeds, and participating in a separate multi-million-dollar credit card fraud scheme, underscoring that the BEC ring operated as one node of a broader professional money-laundering operation rather than a standalone phishing crew.
The scheme did not rely on spoofed look-alike domains; it used genuine compromised mailboxes belonging to a CFO and an employee, which is why the fraudulent wire instructions passed scrutiny: they came from the real, expected sender address with correct writing style, thread history, and internal context. Once inside the mailbox, the actors waited for or engineered a legitimate wire-worthy event (a bank transfer authorization at Corporation-1, a contractual payment obligation at Corporation-2) and inserted new destination account details into that existing correspondence thread, so the request looked like a routine update to an in-flight payment rather than a novel, suspicious ask.
After the banks executed the wires, the ring moved the money through a layered chain of mule/shell accounts controlled by different co-conspirators (the 'Goran Account,' the 'Rebiga Account') within days, then converted proceeds to Bitcoin, a standard layering technique to break the paper trail before recovery efforts could catch up. When a bank did freeze a receiving account, the group tried to talk their way past the freeze with false explanations of the funds' origin (e.g., Mizrahi telling Bank of America the money was payment for hosting services), showing the operation had a practiced response for the recovery/clawback stage as well as the initial theft.
There was no external lure to spot in the conventional phishing sense: the fraudulent instructions arrived from the victims' own genuine, previously-trusted CFO/employee email accounts, likely obtained via prior credential compromise (indictment materials do not fully detail the initial access vector). The tell available to victims in hindsight was a last-minute change to wire/beneficiary account details on an existing payment rather than a wholly new request, and the destination accounts were newly opened, unfamiliar accounts rather than the counterparty's long-established bank relationship.
Charged December 2, 2022 in a four-defendant indictment (superseded December 19, 2023) covering conspiracy to commit wire and bank fraud, wire fraud, bank fraud, conspiracy to commit money laundering, money laundering, aggravated identity theft, and conspiracy to operate an unlicensed money-transmitting business. Joel Zubaid and David Goran pleaded guilty and cooperated as trial witnesses against Martin Mizrahi.
Mizrahi was convicted by a jury on all seven counts on March 4, 2024 after a 12-day trial and was sentenced on September 10, 2024 to 60 months' imprisonment (36 months concurrent on five counts plus 24 months consecutive on the money-transmitting count), 2 years' supervised release, a $50,000 fine, and forfeiture of $4,545,704; his post-trial motion for acquittal/new trial was denied by the court.
Julian Rebiga, who was detained pretrial, was sentenced on April 17, 2024 to 24 months (the government had sought 37 months; the defense had sought time served). David Goran, who pleaded guilty and cooperated as a trial witness, was sentenced on March 17, 2025 to time served, two years' supervised release, a $10,000 fine, and forfeiture of $10,000, per the SDNY docket's sentencing minute entry.
Joel Zubaid, who also pleaded guilty and cooperated as a trial witness, died before he could be sentenced, reportedly by apparent suicide, and was never sentenced; this is stated in Mizrahi's April 2026 petition for a writ of certiorari to the U.S. Supreme Court, which draws on the sentencing record to argue that Zubaid and Goran (who the petition says orchestrated the schemes and received the laundered Bitcoin) ended up with far lighter outcomes than Mizrahi.
This case shows BEC/wire fraud rings targeting organizations that handle large, infrequent wire transfers: a community development corporation and a private-equity portfolio company, where a single compromised mailbox can trigger a multi-million-dollar loss with no external malware or spoofed domain required. It also demonstrates that BEC crews are frequently embedded in broader professional money-laundering operations (the same defendant, Mizrahi, was convicted of laundering both the BEC proceeds and unrelated narcotics cash), meaning the 'exit' side of a BEC, the mule network and crypto conversion, is often shared infrastructure serving multiple criminal revenue streams, not a one-off cash-out built solely for this fraud.
Require out-of-band verification (phone call to a previously-known number, not one supplied in the email) for any change to wire/beneficiary instructions, especially on high-dollar or first-time-to-this-account transfers. Enforce dual control and a waiting/callback period on outbound wires above a threshold. Monitor CFO/finance-team mailboxes for anomalous forwarding rules, new-device logins, and impossible-travel sign-ins that indicate account takeover.
Treat mid-thread changes to banking details as a hard-stop event requiring verification through a separate channel, regardless of how convincing the email thread looks.
Social Engineering Examples. “Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company”. Accessed 19 September 2026. https://socialengineeringexamples.com/manhattan-bec-zubaid-rebiga-mizrahi-2021
BEC crews typically identify victim organizations that routinely handle large, infrequent wire transfers, such as nonprofits awaiting grant or loan disbursements and private-equity portfolio companies making contractual payments, using OSINT such as public filings, press releases, and LinkedIn to identify the specific finance staff (a CFO, a payments-handling employee) whose mailbox is worth targeting.
reconnaissance built on public information about an organization's wire-transfer activity and staff roles is very hard to eliminate. The realistic control is not hiding this exposure but hardening the wire-approval process that any reconnaissance ultimately has to get through, see Stage 6.
the conspirators obtained unauthorized access to the CFO's and, separately, the employee's genuine business email accounts. The court record does not specify the initial access technique, but this is consistent with common BEC vectors like credential phishing, credential-stuffing against reused passwords, or purchased stolen credentials.
phishing-resistant multi-factor authentication (hardware security keys or app-based MFA, not SMS), conditional-access policies that flag logins from new devices or locations, and regular credential-hygiene and security-awareness training reduce the odds that a CFO's or finance employee's mailbox can be taken over in the first place.
once inside a compromised mailbox, the actors likely monitored ongoing correspondence to identify a genuine wire-worthy event already in motion (an authorized bank transfer at Corporation-1, a contractual payment obligation at Corporation-2) rather than inventing a new, more suspicious request.
mailbox monitoring for anomalous behavior, such as new auto-forwarding or inbox rules, impossible-travel sign-ins, or logins from new devices, can catch an account takeover during the dwell period before a fraudulent instruction is ever sent.
the conspirators used the compromised mailbox to insert new destination account details into the existing, trusted correspondence thread, so the fraudulent request appeared as a routine update to an in-flight payment rather than a novel ask, and it carried the real sender address, writing style, and thread history.
treat any mid-thread change to banking or beneficiary details as a hard-stop event requiring verification through a separate channel, regardless of how convincing the email thread looks, since this is precisely the moment the fraud becomes detectable.
co-conspirators opened and controlled receiving bank accounts at other financial institutions (the 'Goran Account' and 'Rebiga Account') to accept the fraudulent wires without the victim organizations recognizing the destination as unfamiliar.
victim organizations have little visibility into mule accounts opened at other banks. The more effective control sits with the receiving institutions' own account-opening (KYC) and new-account transaction-monitoring controls, and with the victim's own callback verification at Stage 6 before money ever reaches those accounts.
acting on the fraudulent instructions from the genuine mailbox, the victims' banks executed the wires, approximately $3,488,000 from Corporation-1 between May 12 and June 1, 2021, and approximately $2,008,034.76 from Corporation-2 on July 1, 2021.
require out-of-band verification via a phone call to a previously known number, never one supplied in the email, plus dual control and a waiting or callback period for any high-dollar or first-time-to-this-account wire before the bank releases funds.
within days, the ring moved the stolen funds through additional mule and shell accounts controlled by different co-conspirators, then converted proceeds to Bitcoin, a standard layering technique meant to break the audit trail before banks or law enforcement could claw the funds back.
banks' anti-money-laundering transaction monitoring for rapid, layered transfers and same-day conversion to cryptocurrency can flag the funds while they are still moving, and immediate victim notification to the bank and to law enforcement's financial fraud recovery channels, such as the FBI's IC3 Recovery Asset Team, improves the odds of a freeze before conversion to Bitcoin completes.
when a bank froze a receiving account, conspirators, including Mizrahi in communications with Bank of America, made false statements about the funds' origin, such as claiming the money was payment for hosting services, to try to unfreeze the funds and complete the cash-out.
banks should independently verify a customer's claimed explanation for suspicious incoming funds, such as confirming a purported business relationship like 'hosting services', against documentary evidence before releasing a frozen account, rather than accepting the account holder's account of the transaction at face value.
Browse by what this case has in common with others in the library.
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title…
A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out.
The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning.
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
During an internal OpenAI benchmark run with safety refusals deliberately lowered.
An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South.
After going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.