Case Library / Phishing / Scoular Company $17.2M grain-trader wire fraud (2014)
Phishing Confirmed

Scoular Company $17.2M grain-trader wire fraud (2014)

Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he wired $17.2M in three tranches to a Shanghai account.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In June 2014, Scoular corporate controller Keith McMurtry received emails appearing to come from CEO Chuck Elsea instructing him to wire funds for a confidential acquisition of a Chinese company, purportedly conducted under SEC supervision. The emails told him to coordinate with a named KPMG partner (Scoular's real auditor) who would provide wiring instructions. Over three transactions McMurtry wired a total of $17.2 million to an account in the name of "Dadi Co" at Shanghai Pudong Development Bank. Every element was fraudulent: the CEO emails came from a spoofed account (not Elsea's real address), and the "KPMG" contact used a look-alike domain (kpmg-office.com) with a fake phone number answered by an accomplice. The real KPMG partner said he had never heard of Scoular. This is a well-documented, real incident: detailed in an FBI special agent's affidavit filed in U.S. District Court in Omaha (District of Nebraska) and confirmed on the record by a Scoular spokesperson; reported by Reuters, the Financial Times, The Guardian, CSO Online and others in Feb 2015.

How the Attack Worked

The attackers built a layered pretext rather than a single spoofed email. They impersonated the CEO to invoke authority and imposed secrecy ("communicate only through this email... in order for us not to infringe SEC regulations"), which discouraged the controller from verifying through normal channels. They then added a trusted third party by impersonating a genuine KPMG partner via a convincing look-alike domain and staffing a phone line so that a call to "verify" was answered by a confederate using the right name. The scheme was strengthened by real-world plausibility: Scoular was in fact considering China expansion and was mid-audit with KPMG, so the story fit the controller's expectations. Flattery and reward ("I will not forget your professionalism... I will show you my appreciation") and urgency to complete tranches quickly reduced further scrutiny. Infrastructure was internationally distributed (email/phone traced to Germany, France, Israel and Moscow servers) to frustrate attribution.

The Lure & the Tell

Lure: a "strictly confidential" CEO email assigning the controller to a secret, SEC-supervised acquisition ("I have assigned you to manage file FT-809... Have you already been contacted by [the KPMG lawyer]?") with instructions to wire funds and coordinate with a named KPMG partner. Tells: the CEO email did not come from his real corporate address; the "KPMG" contact used a look-alike domain (kpmg-office.com) instead of kpmg.com; an insistence on communicating only through one channel and invoking "SEC regulations" to block out-of-band verification; and a large, unusual, secret cross-border wire that bypassed normal approval and could have been debunked by one independent phone call to the CEO or KPMG's main line.

Outcome

Scoular discovered the fraud in June 2014 and reported it to authorities. The FBI investigated and, in late January 2015, sought seizure warrants targeting the Shanghai-based recipient (Dadi Co Ltd), but the account had been closed and the funds transferred away, so the $17.2M was not recovered. The controller who sent the wires was no longer with the company. No individual perpetrators have been publicly charged. Scoular, a multibillion-dollar-revenue firm, absorbed the loss.

Why It Matters

A textbook, high-dollar business email compromise (CEO fraud) that shows social engineering, not malware, drove the loss. It is widely cited as an early landmark BEC case: the attackers combined executive impersonation, enforced secrecy, a trusted-brand third party (a real auditor) via a look-alike domain, and even a live phone confederate, all wrapped around a genuine business context (real China-expansion talks) that made the story believable. It demonstrates why out-of-band verification of payment changes and large wires, using independently obtained contact details, must be mandatory regardless of apparent seniority or confidentiality demands.

Defenses

Require out-of-band verification (a call-back to a known, independently sourced number) for any large or unusual wire, and never accept a phone number supplied within the request itself. Treat demands for secrecy or "do not discuss through other channels" as a red flag, not a reason to skip controls. Enforce dual authorization and separation of duties on high-value transfers. Verify sender domains carefully (kpmg.com vs kpmg-office.com) and deploy email authentication (SPF/DKIM/DMARC) plus display-name/look-alike-domain detection. Independently confirm that any "confidential deal" is real with the named executive directly. Train finance staff specifically on CEO-fraud/BEC pretexts and rehearse the "verify before you wire" reflex.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target and pretext research: The attackers identified Scoular's controller, not the CEO, as the payment-execution target, and gathered enough real business context (that Scoular was genuinely exploring China expansion and mid-audit with KPMG) to make a fabricated acquisition story plausible rather than generic.
Countering Stage 1: Genuine sensitive business plans (M&A talks, audit timing) are hard to fully protect, but limiting who knows deal details, on a need-to-know basis, reduces how convincing an attacker's pretext can be built.
2
Infrastructure setup: The attackers registered a look-alike domain for the trusted third party (kpmg-office.com instead of kpmg.com) and staffed a phone line with a confederate who could answer using the real KPMG partner's name if the controller tried to verify using the number supplied in the email.
Countering Stage 2: Deploy look-alike-domain monitoring (flagging registrations like kpmg-office.com) and email authentication (SPF/DKIM/DMARC) that would flag or block a spoofed sender domain before it reaches an inbox.
3
Initial contact, authority and secrecy: A spoofed email impersonating CEO Chuck Elsea instructed the controller to handle a 'strictly confidential' acquisition, directing him to communicate only through that channel and invoking SEC-regulation secrecy to pre-empt normal verification.
Countering Stage 3: Treat any instruction to bypass normal channels or keep a financial matter secret from finance leadership as an automatic escalation trigger, never a reason for compliance.
4
Trusted third-party layering: The email named a real KPMG partner and told the controller to expect contact from him about wiring instructions, adding a second, seemingly independent voice to the pretext rather than relying on the CEO impersonation alone.
Countering Stage 4: Independently verify a named auditor or vendor contact using details sourced from your own records, not the number or email supplied in the request, before treating them as confirmation of anything.
5
Verification neutralization: The look-alike domain and staffed phone line meant any check the controller ran using the information supplied within the scam itself came back 'clean.' The fraud was built so that verifying through the attacker-provided channels would not reveal anything wrong.
Countering Stage 5: Build 'verify independently' into policy as calling a number looked up separately (firm directory, prior correspondence), never one provided inside the suspicious message itself. This single habit would have caught this scheme.
6
Psychological reinforcement: Flattery and promised future reward, plus urgency to complete the tranches quickly, reduced the controller's motivation to pause and verify independently.
Countering Stage 6: Train staff that urgency and flattery paired with a request to bypass controls is itself a threat pattern, regardless of how plausible the underlying business story sounds.
7
Payout and fund exfiltration: The controller wired $17.2M in three tranches to an account in Shanghai; the receiving account was closed and funds moved before law enforcement could act, and the scam's own internationally distributed infrastructure (Germany, France, Israel, Russia) frustrated attribution.
Countering Stage 7: Dual authorization and separation of duties on large wires, so no single controller can both initiate and finalize a multi-million-dollar transfer, plus bank-side alerts on new-payee cross-border wires of unusual size.
Quick Facts
Victim
The Scoular Company, a privately held (employee-owned) grain-trading and commodities handling firm; the individual target was corporate controller Keith McMurtry.
Location
Omaha, Nebraska, USA (funds sent to Shanghai, China)
Date
June 2014 (discovered June 2014; publicly reported Feb 2015)
Impact
$17.2 million lost across three wire transfers ($780,000; $7 million; $9.4 million). Funds not recovered; the Shanghai account was closed and money moved before an FBI seizure order could be executed.
Status
Confirmed
Case Type
Real-World Incident
Sector
Manufacturing & Industrial
Threat Actor
Organized Crime
Related

Related Cases

Sony Pictures 'Guardians of Peace' hack: fake Apple ID emails to admins

North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated…

Incident 2014Read →

Ubiquiti Networks $46.7M business email compromise (2015)

Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…

Incident 2015Read →

2015 Ukraine Power Grid Attack (Sandworm/BlackEnergy)

Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities,…

Incident 2015Read →