A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO, and the company clawed it back within days thanks to a Chinese bank holiday and an FBI letter.
Reviewed by the Social Engineering Examples team.
On Thursday, April 30, 2015, a finance executive at Mattel received an email appearing to come from the company's chief executive, Christopher Sinclair, requesting a new vendor payment to China. Sinclair had officially taken over as CEO only that month, after Mattel fired his predecessor during a rough stretch for the Barbie business. The request looked routine, and the company was actively expanding in China (sales up 43% in 2015), so a China payment did not seem out of place. Mattel policy required two high-ranking managers to approve fund transfers; the finance executive qualified as one approver and the CEO as the other, so the forged request satisfied the control. She wired over $3 million to the Bank of Wenzhou. Hours later she mentioned the payment to Sinclair, who said he had never requested it. Mattel contacted its U.S. bank, police and the FBI and was told the money was already in China and gone. This incident is documented primarily through an Associated Press investigation (Erika Kinetz, published March 29, 2016) that reviewed FBI and Mattel letters and interviewed people familiar with the investigation; Mattel declined to comment, citing the ongoing case, so some specifics (including the executive's name) rely on anonymous sources and documents rather than a company disclosure.
The attackers did their homework: they mined social media and, according to a person familiar with the investigation, likely hacked corporate email to learn Mattel's org chart, who could approve wires, and its payment patterns. They then sent a well-crafted email impersonating the CEO with a plausible business justification (a vendor payment to China) at a moment of maximum leverage. The timing exploited organizational chaos: a just-installed CEO whose habits staff did not yet know, a subordinate eager to please a new boss, and a live China-expansion push that made an overseas payment look normal. Critically, the fraud fit inside Mattel's own control (dual approval): the request satisfied the process on paper because the impersonated CEO was one of the two required approvers. The money was directed to the Bank of Wenzhou, a coastal city that intelligence memos cited by the AP describe as the destination for roughly 90% of funds stolen through fake-CEO scams in Europe.
Lure: an email purporting to be from the newly installed CEO asking a finance executive to wire funds for a new vendor payment to China. Tells (recognizable in hindsight): the request came from a boss who had been in the seat only weeks (no established pattern to compare against); it introduced a brand-new payee/vendor and an overseas transfer; and it was never verified out-of-band with the CEO before sending. The executive followed written protocol but did not confirm the instruction with the supposed sender through a separate channel, the single point that would have exposed the forgery.
Mattel recovered the full $3 million. Luck bought time: Friday, May 1 was Labor Day, a bank holiday in China, so the funds sat before they could be dispersed. Mattel notified Chinese police, who opened a criminal investigation. When the Bank of Wenzhou reopened the following Monday, a China-based anti-fraud executive from Mattel arrived at the bank's headquarters with a letter from the FBI; Chinese police froze the account that morning, and on May 6, 2015 the money was returned. No arrests or attacker identification were publicly disclosed. The FBI has said the fake-CEO / fake-president scam had, at that point, cost companies (many American) more than $1.8 billion, with most stolen funds passing through banks in China or Hong Kong.
This is a textbook CEO-fraud (BEC) case and a rare, instructive recovery success. It shows that a well-researched impersonation can defeat a formal dual-approval control when one of the "two approvers" is the very person being impersonated: the process was followed and still failed, because no step verified the request independently of the email. It also underlines that leadership transitions are prime attack windows: a new CEO's requests can't be sanity-checked against known behavior, and staff feel extra pressure to comply quickly. Finally, the recovery demonstrates that speed, immediate law-enforcement engagement across jurisdictions, and a bit of timing luck can sometimes reverse even completed international wires, but the outcome hinged on a bank holiday, not on a repeatable control, which is why prevention matters far more than recovery.
Verify any payment instruction, especially new vendors, changed bank details, or overseas transfers, through an independent, pre-known channel (call the executive back on a known number), never by replying to the email. Require out-of-band callback verification as a mandatory step for wires above a threshold, separate from approval sign-off. Do not let the requester/impersonated party count as one of the required approvers; enforce genuine separation of duties. Treat new-vendor setup and first payments as high-risk with extra checks. Add friction and a cooling-off/second-review window for large or unusual transfers. Train finance staff that leadership transitions and urgency are classic pressure tactics. Harden email against impersonation (authentication, external-sender flags, lookalike-domain detection) and act on any sign of compromised corporate mailboxes. Have an incident playbook ready: on suspicion, immediately contact your bank, file with the FBI/IC3, and pursue recall through correspondent and destination banks fast, since recovery windows are short.
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities,…
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…