Case Library / Phishing / Mattel CEO-Fraud Wire ($3M, Recovered)
Phishing Confirmed

Mattel CEO-Fraud Wire ($3M, Recovered)

A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO, and the company clawed it back within days thanks to a Chinese bank holiday and an FBI letter.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On Thursday, April 30, 2015, a finance executive at Mattel received an email appearing to come from the company's chief executive, Christopher Sinclair, requesting a new vendor payment to China. Sinclair had officially taken over as CEO only that month, after Mattel fired his predecessor during a rough stretch for the Barbie business. The request looked routine, and the company was actively expanding in China (sales up 43% in 2015), so a China payment did not seem out of place. Mattel policy required two high-ranking managers to approve fund transfers; the finance executive qualified as one approver and the CEO as the other, so the forged request satisfied the control. She wired over $3 million to the Bank of Wenzhou. Hours later she mentioned the payment to Sinclair, who said he had never requested it. Mattel contacted its U.S. bank, police and the FBI and was told the money was already in China and gone. This incident is documented primarily through an Associated Press investigation (Erika Kinetz, published March 29, 2016) that reviewed FBI and Mattel letters and interviewed people familiar with the investigation; Mattel declined to comment, citing the ongoing case, so some specifics (including the executive's name) rely on anonymous sources and documents rather than a company disclosure.

How the Attack Worked

The attackers did their homework: they mined social media and, according to a person familiar with the investigation, likely hacked corporate email to learn Mattel's org chart, who could approve wires, and its payment patterns. They then sent a well-crafted email impersonating the CEO with a plausible business justification (a vendor payment to China) at a moment of maximum leverage. The timing exploited organizational chaos: a just-installed CEO whose habits staff did not yet know, a subordinate eager to please a new boss, and a live China-expansion push that made an overseas payment look normal. Critically, the fraud fit inside Mattel's own control (dual approval): the request satisfied the process on paper because the impersonated CEO was one of the two required approvers. The money was directed to the Bank of Wenzhou, a coastal city that intelligence memos cited by the AP describe as the destination for roughly 90% of funds stolen through fake-CEO scams in Europe.

The Lure & the Tell

Lure: an email purporting to be from the newly installed CEO asking a finance executive to wire funds for a new vendor payment to China. Tells (recognizable in hindsight): the request came from a boss who had been in the seat only weeks (no established pattern to compare against); it introduced a brand-new payee/vendor and an overseas transfer; and it was never verified out-of-band with the CEO before sending. The executive followed written protocol but did not confirm the instruction with the supposed sender through a separate channel, the single point that would have exposed the forgery.

Outcome

Mattel recovered the full $3 million. Luck bought time: Friday, May 1 was Labor Day, a bank holiday in China, so the funds sat before they could be dispersed. Mattel notified Chinese police, who opened a criminal investigation. When the Bank of Wenzhou reopened the following Monday, a China-based anti-fraud executive from Mattel arrived at the bank's headquarters with a letter from the FBI; Chinese police froze the account that morning, and on May 6, 2015 the money was returned. No arrests or attacker identification were publicly disclosed. The FBI has said the fake-CEO / fake-president scam had, at that point, cost companies (many American) more than $1.8 billion, with most stolen funds passing through banks in China or Hong Kong.

Why It Matters

This is a textbook CEO-fraud (BEC) case and a rare, instructive recovery success. It shows that a well-researched impersonation can defeat a formal dual-approval control when one of the "two approvers" is the very person being impersonated: the process was followed and still failed, because no step verified the request independently of the email. It also underlines that leadership transitions are prime attack windows: a new CEO's requests can't be sanity-checked against known behavior, and staff feel extra pressure to comply quickly. Finally, the recovery demonstrates that speed, immediate law-enforcement engagement across jurisdictions, and a bit of timing luck can sometimes reverse even completed international wires, but the outcome hinged on a bank holiday, not on a repeatable control, which is why prevention matters far more than recovery.

Defenses

Verify any payment instruction, especially new vendors, changed bank details, or overseas transfers, through an independent, pre-known channel (call the executive back on a known number), never by replying to the email. Require out-of-band callback verification as a mandatory step for wires above a threshold, separate from approval sign-off. Do not let the requester/impersonated party count as one of the required approvers; enforce genuine separation of duties. Treat new-vendor setup and first payments as high-risk with extra checks. Add friction and a cooling-off/second-review window for large or unusual transfers. Train finance staff that leadership transitions and urgency are classic pressure tactics. Harden email against impersonation (authentication, external-sender flags, lookalike-domain detection) and act on any sign of compromised corporate mailboxes. Have an incident playbook ready: on suspicion, immediately contact your bank, file with the FBI/IC3, and pursue recall through correspondent and destination banks fast, since recovery windows are short.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: per the AP investigation, the attackers are described as mining social media and, per a person familiar with the investigation, likely compromising Mattel's corporate email to learn the company's org chart, who could approve wires, and its payment patterns, consistent with typical pre-BEC target profiling.
Countering Stage 1: employee-facing OSINT exposure and org-chart details are hard to fully suppress, so the realistic control is email-authentication hygiene (SPF/DKIM/DMARC), monitoring for anomalous mailbox rules or logins, and treating any hint of a compromised executive mailbox as a payment-fraud precursor, not just a security ticket.
2
Timing selection: the attackers waited for a moment of maximum organizational disruption, a brand-new CEO (Christopher Sinclair, installed that same month after Mattel fired his predecessor) whose habits staff did not yet know, layered on top of a live, publicized China-expansion push (China sales up 43% in 2015) that made an overseas payment plausible.
Countering Stage 2: flag leadership-transition periods (new CEO, CFO, or other wire-approving executive) as a defined high-risk window and add temporary extra scrutiny to any unusual payment request arriving during it, since staff cannot yet sanity-check a new executive's habits.
3
Pretext construction: the attackers crafted a forged email impersonating the new CEO, requesting a routine-sounding new-vendor payment to China, timed and worded to fit inside Mattel's known dual-approval control rather than bypass it.
Countering Stage 3: treat any new vendor or first-time payee, especially paired with an overseas destination, as high-risk regardless of who requested it, and require enhanced verification before the first payment goes out.
4
Lure delivery and social engineering: the email reached a finance executive positioned as one of the two required wire approvers, exploiting her stated eagerness to please a newly installed boss and the appearance of a legitimate, in-process business request.
Countering Stage 4: train finance staff that urgency and eagerness to please a new or senior requester are classic pressure tactics, and normalize pausing to verify rather than treating speed of compliance as a virtue.
5
Control exploitation: because the impersonated CEO was himself one of the two required approvers, the forged request satisfied Mattel's dual-approval policy on paper without ever being verified out-of-band with the real Sinclair.
Countering Stage 5: never allow the requester or impersonated party to count as one of the required independent approvers; enforce genuine separation of duties plus a mandatory out-of-band callback to a pre-known number (never a number or address supplied in the request) before releasing funds.
6
Payment execution: the finance executive wired over $3 million to the Bank of Wenzhou, a Chinese money-laundering transit hub the AP reports as the destination for roughly 90% of funds stolen through fake-CEO scams in Europe, completing the objective of the fraud.
Countering Stage 6: maintain a fast incident playbook, on suspicion, immediately contact the sending and receiving banks, file with the FBI/IC3, and pursue recall through correspondent and destination banks, since recovery windows are short and, per this case, hinged on a fortunate bank holiday rather than a repeatable control.
Quick Facts
Victim
Mattel, Inc. (Los Angeles-based maker of Barbie and Hot Wheels); an unnamed finance executive authorized to approve wire transfers.
Location
United States (Mattel HQ, Los Angeles) with funds sent to Wenzhou, China
Date
2015-04-30
Impact
$3 million wired; fully recovered on May 6, 2015 (net loss effectively $0).
Status
Confirmed
Case Type
Real-World Incident
Sector
Retail & E-commerce
Related

Related Cases

Ubiquiti Networks $46.7M business email compromise (2015)

Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…

Incident 2015Read →

2015 Ukraine Power Grid Attack (Sandworm/BlackEnergy)

Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities,…

Incident 2015Read →

Scoular Company $17.2M grain-trader wire fraud (2014)

Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…

Incident 2014Read →