Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he wired $17.2M in three tranches to a Shanghai account.
Reviewed by the Social Engineering Examples team.
In June 2014, Scoular corporate controller Keith McMurtry received emails appearing to come from CEO Chuck Elsea instructing him to wire funds for a confidential acquisition of a Chinese company, purportedly conducted under SEC supervision. The emails told him to coordinate with a named KPMG partner (Scoular's real auditor) who would provide wiring instructions. Over three transactions McMurtry wired a total of $17.2 million to an account in the name of "Dadi Co" at Shanghai Pudong Development Bank. Every element was fraudulent: the CEO emails came from a spoofed account (not Elsea's real address), and the "KPMG" contact used a look-alike domain (kpmg-office.com) with a fake phone number answered by an accomplice. The real KPMG partner said he had never heard of Scoular. This is a well-documented, real incident: detailed in an FBI special agent's affidavit filed in U.S. District Court in Omaha (District of Nebraska) and confirmed on the record by a Scoular spokesperson; reported by Reuters, the Financial Times, The Guardian, CSO Online and others in Feb 2015.
The attackers built a layered pretext rather than a single spoofed email. They impersonated the CEO to invoke authority and imposed secrecy ("communicate only through this email... in order for us not to infringe SEC regulations"), which discouraged the controller from verifying through normal channels. They then added a trusted third party by impersonating a genuine KPMG partner via a convincing look-alike domain and staffing a phone line so that a call to "verify" was answered by a confederate using the right name. The scheme was strengthened by real-world plausibility: Scoular was in fact considering China expansion and was mid-audit with KPMG, so the story fit the controller's expectations. Flattery and reward ("I will not forget your professionalism... I will show you my appreciation") and urgency to complete tranches quickly reduced further scrutiny. Infrastructure was internationally distributed (email/phone traced to Germany, France, Israel and Moscow servers) to frustrate attribution.
Lure: a "strictly confidential" CEO email assigning the controller to a secret, SEC-supervised acquisition ("I have assigned you to manage file FT-809... Have you already been contacted by [the KPMG lawyer]?") with instructions to wire funds and coordinate with a named KPMG partner. Tells: the CEO email did not come from his real corporate address; the "KPMG" contact used a look-alike domain (kpmg-office.com) instead of kpmg.com; an insistence on communicating only through one channel and invoking "SEC regulations" to block out-of-band verification; and a large, unusual, secret cross-border wire that bypassed normal approval and could have been debunked by one independent phone call to the CEO or KPMG's main line.
Scoular discovered the fraud in June 2014 and reported it to authorities. The FBI investigated and, in late January 2015, sought seizure warrants targeting the Shanghai-based recipient (Dadi Co Ltd), but the account had been closed and the funds transferred away, so the $17.2M was not recovered. The controller who sent the wires was no longer with the company. No individual perpetrators have been publicly charged. Scoular, a multibillion-dollar-revenue firm, absorbed the loss.
A textbook, high-dollar business email compromise (CEO fraud) that shows social engineering, not malware, drove the loss. It is widely cited as an early landmark BEC case: the attackers combined executive impersonation, enforced secrecy, a trusted-brand third party (a real auditor) via a look-alike domain, and even a live phone confederate, all wrapped around a genuine business context (real China-expansion talks) that made the story believable. It demonstrates why out-of-band verification of payment changes and large wires, using independently obtained contact details, must be mandatory regardless of apparent seniority or confidentiality demands.
Require out-of-band verification (a call-back to a known, independently sourced number) for any large or unusual wire, and never accept a phone number supplied within the request itself. Treat demands for secrecy or "do not discuss through other channels" as a red flag, not a reason to skip controls. Enforce dual authorization and separation of duties on high-value transfers. Verify sender domains carefully (kpmg.com vs kpmg-office.com) and deploy email authentication (SPF/DKIM/DMARC) plus display-name/look-alike-domain detection. Independently confirm that any "confidential deal" is real with the named executive directly. Train finance staff specifically on CEO-fraud/BEC pretexts and rehearse the "verify before you wire" reflex.
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities,…