A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO.
Social Engineering Examples·3 sources
On Thursday, April 30, 2015, a finance executive at Mattel received an email appearing to come from the company's chief executive, Christopher Sinclair, requesting a new vendor payment to China. Sinclair had officially taken over as CEO only that month, after Mattel fired his predecessor during a rough stretch for the Barbie business. The request looked routine, and the company was actively expanding in China (sales up 43% in 2015), so a China payment did not seem out of place.
Mattel policy required two high-ranking managers to approve fund transfers; the finance executive qualified as one approver and the CEO as the other, so the forged request satisfied the control. She wired over $3 million to the Bank of Wenzhou. Hours later she mentioned the payment to Sinclair, who said he had never requested it. Mattel contacted its U.S. bank, police and the FBI and was told the money was already in China and gone.
This incident is documented primarily through an Associated Press investigation (Erika Kinetz, published March 29, 2016) that reviewed FBI and Mattel letters and interviewed people familiar with the investigation; Mattel declined to comment, citing the ongoing case, so some specifics (including the executive's name) rely on anonymous sources and documents rather than a company disclosure.
The attackers did their homework: they mined social media and, according to a person familiar with the investigation, likely hacked corporate email to learn Mattel's org chart, who could approve wires, and its payment patterns. They then sent a well-crafted email impersonating the CEO with a plausible business justification (a vendor payment to China) at a moment of maximum leverage.
The timing exploited organizational chaos: a just-installed CEO whose habits staff did not yet know, a subordinate eager to please a new boss, and a live China-expansion push that made an overseas payment look normal. Critically, the fraud fit inside Mattel's own control (dual approval): the request satisfied the process on paper because the impersonated CEO was one of the two required approvers.
The money was directed to the Bank of Wenzhou, a coastal city that intelligence memos cited by the AP describe as the destination for roughly 90% of funds stolen through fake-CEO scams in Europe.
Lure: an email purporting to be from the newly installed CEO asking a finance executive to wire funds for a new vendor payment to China. Tells (recognizable in hindsight): the request came from a boss who had been in the seat only weeks (no established pattern to compare against); it introduced a brand-new payee/vendor and an overseas transfer; and it was never verified out-of-band with the CEO before sending.
The executive followed written protocol but did not confirm the instruction with the supposed sender through a separate channel, the single point that would have exposed the forgery.
Mattel recovered the full $3 million. Luck bought time: Friday, May 1 was Labor Day, a bank holiday in China, so the funds sat before they could be dispersed. Mattel notified Chinese police, who opened a criminal investigation. When the Bank of Wenzhou reopened the following Monday, a China-based anti-fraud executive from Mattel arrived at the bank's headquarters with a letter from the FBI; Chinese police froze the account that morning, and on May 6, 2015 the money was returned.
No arrests or attacker identification were publicly disclosed. The FBI has said the fake-CEO / fake-president scam had, at that point, cost companies (many American) more than $1.8 billion, with most stolen funds passing through banks in China or Hong Kong.
This is a textbook CEO-fraud (BEC) case and a rare, instructive recovery success. It shows that a well-researched impersonation can defeat a formal dual-approval control when one of the "two approvers" is the very person being impersonated: the process was followed and still failed, because no step verified the request independently of the email. It also underlines that leadership transitions are prime attack windows: a new CEO's requests can't be sanity-checked against known behavior, and staff feel extra pressure to comply quickly.
Finally, the recovery demonstrates that speed, immediate law-enforcement engagement across jurisdictions, and a bit of timing luck can sometimes reverse even completed international wires, but the outcome hinged on a bank holiday, not on a repeatable control, which is why prevention matters far more than recovery.
Verify any payment instruction, especially new vendors, changed bank details, or overseas transfers, through an independent, pre-known channel (call the executive back on a known number), never by replying to the email. Require out-of-band callback verification as a mandatory step for wires above a threshold, separate from approval sign-off. Do not let the requester/impersonated party count as one of the required approvers; enforce genuine separation of duties.
Treat new-vendor setup and first payments as high-risk with extra checks. Add friction and a cooling-off/second-review window for large or unusual transfers. Train finance staff that leadership transitions and urgency are classic pressure tactics. Harden email against impersonation (authentication, external-sender flags, lookalike-domain detection) and act on any sign of compromised corporate mailboxes.
Have an incident playbook ready: on suspicion, immediately contact your bank, file with the FBI/IC3, and pursue recall through correspondent and destination banks fast, since recovery windows are short.
Social Engineering Examples. “Mattel CEO-Fraud Wire ($3M, Recovered)”. Accessed 19 September 2026. https://socialengineeringexamples.com/mattel-ceo-fraud-wire-recovered-2015
per the AP investigation, the attackers are described as mining social media and, per a person familiar with the investigation, likely compromising Mattel's corporate email to learn the company's org chart, who could approve wires, and its payment patterns, consistent with typical pre-BEC target profiling.
employee-facing OSINT exposure and org-chart details are hard to fully suppress, so the realistic control is email-authentication hygiene (SPF/DKIM/DMARC), monitoring for anomalous mailbox rules or logins, and treating any hint of a compromised executive mailbox as a payment-fraud precursor, not just a security ticket.
the attackers waited for a moment of maximum organizational disruption, a brand-new CEO (Christopher Sinclair, installed that same month after Mattel fired his predecessor) whose habits staff did not yet know, layered on top of a live, publicized China-expansion push (China sales up 43% in 2015) that made an overseas payment plausible.
flag leadership-transition periods (new CEO, CFO, or other wire-approving executive) as a defined high-risk window and add temporary extra scrutiny to any unusual payment request arriving during it, since staff cannot yet sanity-check a new executive's habits.
the attackers crafted a forged email impersonating the new CEO, requesting a routine-sounding new-vendor payment to China, timed and worded to fit inside Mattel's known dual-approval control rather than bypass it.
treat any new vendor or first-time payee, especially paired with an overseas destination, as high-risk regardless of who requested it, and require enhanced verification before the first payment goes out.
the email reached a finance executive positioned as one of the two required wire approvers, exploiting her stated eagerness to please a newly installed boss and the appearance of a legitimate, in-process business request.
train finance staff that urgency and eagerness to please a new or senior requester are classic pressure tactics, and normalize pausing to verify rather than treating speed of compliance as a virtue.
because the impersonated CEO was himself one of the two required approvers, the forged request satisfied Mattel's dual-approval policy on paper without ever being verified out-of-band with the real Sinclair.
never allow the requester or impersonated party to count as one of the required independent approvers; enforce genuine separation of duties plus a mandatory out-of-band callback to a pre-known number (never a number or address supplied in the request) before releasing funds.
the finance executive wired over $3 million to the Bank of Wenzhou, a Chinese money-laundering transit hub the AP reports as the destination for roughly 90% of funds stolen through fake-CEO scams in Europe, completing the objective of the fraud.
maintain a fast incident playbook, on suspicion, immediately contact the sending and receiving banks, file with the FBI/IC3, and pursue recall through correspondent and destination banks, since recovery windows are short and, per this case, hinged on a fortunate bank holiday rather than a repeatable control.
Browse by what this case has in common with others in the library.
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
Advance Machine Company's West Coast sales manager repeatedly rifled Tennant Company's sealed, covered dumpster in California to steal sales leads.
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project.