Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller, tricked finance staff into wiring $4.8M to an overseas account for a bogus acquisition.
Reviewed by the Social Engineering Examples team.
In summer 2014, Medidata told its finance team to be ready to help with urgent transactions tied to a possible acquisition. On September 16, 2014, an accounts payable employee (Alicia Evans) received an email that appeared to come from Medidata's president, complete with his name, email address, and photo in the "From" field. It said an acquisition was near, that it was strictly confidential, and that an attorney named "Michael Meyer" would contact her. Meyer then phoned her demanding an urgent wire transfer. When Evans said she needed presidential authorization plus sign-off from a VP and the director of revenue, a follow-up group email, again appearing to come from the president, instructed all three to process and approve the payment. Evans entered the payee details Meyer supplied into Chase's online banking system, and the two executives approved it; $4,770,226 was wired to an overseas (Chinese) bank account. On September 18, "Meyer" requested a second transfer; the VP (Ho Chin) grew suspicious of the reply-to address, contacted the real president directly, and learned he had never made the requests. Medidata contacted the FBI and outside counsel. Investigators found the emails had been spoofed: an unknown actor embedded code so the messages displayed the president's identity while masking the true sender. Medidata disclosed the roughly $4.8M loss in a September 2014 SEC Form 8-K. This is a fully documented, real incident, confirmed by the company's own SEC filing and multiple federal court opinions.
The scheme layered three pressures. First, authority and impersonation: emails were crafted so Medidata's Gmail-hosted system displayed the president's name, address, and photo, making them look genuinely internal. Second, a fake external "attorney" added legitimacy and a live, insistent human voice by phone, a classic BEC pattern of pairing a spoofed email with a corroborating caller. Third, secrecy and urgency: the "confidential acquisition" framing discouraged the employee from openly verifying, and the same-day timeline pressured fast action. Crucially, the attackers had context: finance staff had been pre-warned to expect urgent acquisition-related transfers, so the fraudulent request fit an expected pattern. When the employee's control (needing executive sign-off) kicked in, the fraudsters simply produced another spoofed "presidential" email to satisfy it, turning the internal check into part of the con.
Lure: a spoofed email appearing to be from the company president announcing a confidential, urgent acquisition and directing the employee to cooperate fully with an outside "attorney," reinforced by that attorney's phone call demanding a wire. Tells: the request bypassed normal process (wire demanded because a check would be "too slow"), leaned on secrecy to prevent verification, and originated from addresses that did not truly match the executive. The scam unraveled only when an executive independently examined a suspicious reply-to address and confirmed the request out-of-band with the real president, the single step that would have caught it earlier.
The first $4.77M wire was lost; the second attempt was blocked after an executive's suspicion prompted out-of-band verification. Medidata filed an insurance claim under its $5M Chubb/Federal Insurance "Federal Executive Protection" crime policy; Federal denied coverage, arguing no hacking occurred and that employees transferred the funds voluntarily. Medidata sued (S.D.N.Y., 1:15-cv-00907). In July 2017 the district court granted summary judgment for Medidata under the policy's computer-fraud and funds-transfer-fraud provisions, awarding about $5.8M. The Second Circuit affirmed on July 6, 2018, holding the spoofing was a covered computer fraud and the proximate cause of the loss. No perpetrators were publicly identified or charged.
This is a landmark early business email compromise (BEC) case and a foundational cyber-insurance precedent. It shows that no malware or system breach is needed: manipulating what recipients see in the "From" field, plus social pressure, is enough to move millions. It also crystallized a legal question that shaped how crime and cyber policies are written and litigated: whether "computer fraud" coverage extends to spoofing-driven wire fraud where employees themselves push the button. The court's answer ("larceny by trick is still larceny") helped establish that authorized-but-deceived transfers can still be covered fraud, influencing later BEC coverage disputes.
Require out-of-band verification (a known phone number or in-person confirmation) for any wire transfer or change of payee, especially "urgent" or "confidential" executive requests; verification must be independent of the request channel. Treat secrecy demands that discourage checking as a red flag, not a reason to skip controls. Enforce dual-authorization that is genuinely independent (approvers should confirm with the executive directly, not rely on another email). Deploy email authentication (SPF, DKIM, DMARC) and external-sender/lookalike-domain warnings, and flag reply-to addresses that differ from the display sender. Pre-briefing finance staff to expect urgent transfers, as happened here, can backfire; pair any such heads-up with a mandatory verification protocol.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…