Case Library / Phishing / SEC Section 21(a) Report on Nine Issuers' Business Email Compromise Losses
Phishing Confirmed

SEC Section 21(a) Report on Nine Issuers' Business Email Compromise Losses

SEC's landmark 2018 Section 21(a) report examined how fake-executive and fake-vendor BEC emails drained nearly $100 million combined from nine U.S. public companies, finding that existing wire-authorization controls weren't consistently followed under the pressure of the schemes.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On October 16, 2018, the U.S. Securities and Exchange Commission issued Release No. 34-84429, a Report of Investigation under Section 21(a) of the Securities Exchange Act of 1934, describing business email compromise (BEC) frauds that had struck nine unnamed U.S. public companies in the technology, machinery, real estate, energy, financial, and consumer-goods sectors. The report did not identify the companies or bring enforcement action against any of them; it was issued purely as investor-protection guidance. It found that each of the nine issuers lost at least $1 million to email-based fraud, two lost more than $30 million each, one lost more than $45 million, and the group's combined losses approached $100 million, almost none of which was recovered. The frauds fell into two patterns: "fake-executive" schemes, where attackers spoofed a senior executive's email identity to direct finance staff to wire money to attacker-controlled foreign accounts (often via a purported outside attorney), and "fake-vendor" schemes, where attackers compromised a real foreign vendor's email account and inserted fraudulent payment instructions or doctored invoices into genuine ongoing correspondence. The SEC used the report to argue that such frauds, though executed by outsiders with no computer intrusion into the victim companies' own networks, exposed failures of the issuers' internal accounting controls under Section 13(b)(2)(B) of the Exchange Act, because personnel did not follow or correctly apply existing authorization and verification procedures.

How the Attack Worked

Fake-executive variant: attackers spoofed the email domain or address of a company executive (typically the CEO) and emailed finance/accounting personnel with urgent, confidential instructions to wire funds, directing them to coordinate with a purported outside attorney (using real law-firm and attorney names to add credibility) who then supplied wiring instructions to foreign bank accounts controlled by the perpetrators. Messages leaned on secrecy ("don't discuss with anyone else"), time pressure, and invoked deal-related pretexts (e.g., acquisitions); some contained telltale spelling/grammar errors or spurious references to SEC or regulatory oversight to lend false legitimacy. Fake-vendor variant: perpetrators first compromised a foreign vendor's actual email account/system, then monitored or hijacked genuine purchase-order and invoicing threads, inserting doctored invoices or a bank-detail change request that redirected payment to an account the impersonators controlled. Because the messages arrived inside real, ongoing vendor correspondence, they bypassed the skepticism a purely spoofed message might trigger. Both variants exploited the same underlying failure: employees who were nominally covered by dual-authorization or verification policies did not apply them, either misreading authorization matrices, treating an email as sufficient authorization on its own, or failing to independently verify unusual payment or bank-change instructions before releasing funds.

The Lure & the Tell

The lure: an email that looked like it came from the company's own CEO or a real, currently-corresponding vendor, wrapped in urgency and, in the fake-executive cases, confidentiality ("don't tell anyone, work directly with our attorney on this"). The tell, in hindsight: out-of-domain or spoofed sender addresses that a careful header check would have caught; requests to bypass or reinterpret established dual-authorization / authorization-matrix controls; wire instructions to newly designated foreign accounts with no independent verification call placed; in some fake-executive emails, spelling/grammar errors or oddly specific but false invocations of SEC/government process; and, in fake-vendor cases, an invoice or bank-change request arriving with no advance notice inside an otherwise-legitimate thread, discoverable only when the genuine vendor separately complained about a past-due bill that had, unbeknownst to them, already been "paid" to the wrong account.

Outcome

The SEC issued the Section 21(a) report as an investor-protection and issuer-guidance measure rather than an enforcement vehicle; it explicitly declined to bring charges against any of the nine issuers, framing the report instead as a warning that cyber-related frauds implicate the internal-accounting-controls provisions of the securities laws (Exchange Act Section 13(b)(2)(B)) and that public companies must factor cyber-fraud risk into their controls design. Almost all of the stolen funds across the nine companies went unrecovered. The report became a widely cited baseline for BEC-related internal-controls guidance and is frequently referenced in subsequent SEC cyber-disclosure rulemaking and enforcement discussions, and in corporate-governance/audit-committee training on wire-fraud controls. The closely matching prior real-world case, Ubiquiti Networks' 2015 disclosure of a $46.7 million loss to employee impersonation, similarly resulted in no SEC enforcement action but a company finding that its own internal control over financial reporting had been ineffective; Ubiquiti recovered a portion of the funds.

Why It Matters

This is the first (and remains among the most cited) SEC pronouncements that BEC and social-engineering losses are not merely an IT/security problem but can constitute an internal-accounting-controls failure under the federal securities laws, exposing public companies to potential Section 13(b)(2)(B) exposure even absent any actual computer intrusion. It is widely used in corporate-governance, audit-committee, and controls-design training as the canonical proof that "the fraud used no malware and no hacking of internal systems, only a well-crafted email" is not a defense, and that inter-personnel process discipline (dual authorization, out-of-band verification of bank-detail changes, treating email instructions as insufficient on their own) is the actual control surface that failed. It also documents, at aggregate scale, how effective simple executive-impersonation and vendor-email-compromise pretexts are against large, sophisticated public companies, arguing for BEC awareness training as a first-line defense regardless of company size or technical sophistication.

Defenses

The SEC report's own prescription, restated as the defense checklist it implies: (1) require and actually enforce dual-authorization for wire transfers above set thresholds, with no email-only override; (2) train finance/accounting staff to read and correctly apply authorization matrices rather than deferring to a sender's apparent seniority; (3) verify any vendor bank-detail change through an out-of-band channel (phone call to a known number, not a number in the email) before paying; (4) flag and manually review payment instructions in emails from spoofed or lookalike domains, or with unusual urgency/secrecy framing; (5) reconcile outgoing payments and vendor invoices promptly so mismatches surface within days, not months; (6) run recurring phishing/BEC awareness training keyed to these two specific pretexts; (7) treat the control failure as a securities-law internal-accounting-controls issue (Exchange Act Section 13(b)(2)(B)) requiring board/audit-committee attention, not just an IT problem.

Sources
Quick Facts
Victim
Nine unnamed U.S. public companies (aggregate), spanning technology, machinery, real estate, energy, financial, and consumer-goods sectors
Location
United States (nine unnamed U.S. public companies across technology, machinery, real estate, energy, financial, and consumer-goods sectors, listed on national exchanges)
Date
2018-10-16 (SEC report release date; underlying frauds occurred in prior years)
Impact
Aggregate losses across the nine issuers were nearly $100 million. Per the SEC report: each of the nine issuers lost at least $1 million; two lost more than $30 million each; one lost more than $45 million; almost all losses were unrecovered. The report's two detailed examples: a fake-executive scheme with 14 wire payments over several weeks causing over $45 million in losses (closely matching Ubiquiti Networks' disclosed $46.7 million 2015 loss), and a fake-vendor scheme with eight fraudulent invoices totaling $1.5 million paid over several months.
Status
Confirmed
Case Type
Real-World Incident
Sector
Cross-Sector / Multiple Industries
Related

Related Cases

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…

Incident 2018Read →

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…

Incident 2018Read →

Pathé €19.2M fake-CEO cinema-chain fraud (2018)

Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition,…

Incident 2018Read →