Case Library / Phishing / Ubiquiti Networks $46.7M business email compromise (2015)
Phishing Confirmed

Ubiquiti Networks $46.7M business email compromise (2015)

Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad in 14 transfers over two weeks.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Ubiquiti Networks, a San Jose networking-hardware maker, disclosed in an August 6, 2015 SEC Form 8-K (and its FY2015 10-K and later 10-Qs) that it was the victim of a business email compromise fraud. Between May 20 and June 5, 2015, criminals impersonating company executives and an outside law firm induced the finance function of Ubiquiti's Hong Kong subsidiary to make 14 wire transfers totaling $46,703,232 from an HSBC Hong Kong account to third-party accounts overseas. Per Ubiquiti's detailed correspondence with SEC staff, the fraud began on May 19, 2015 with an email appearing to come from a senior officer's genuine-looking corporate address, describing a confidential company acquisition and instructing that payments be made under the direction of a person named "Tom Evans," purportedly an attorney at the international law firm Latham & Watkins. The controller/principal financial officer, Rohit Chakravarthy, who had wire authority, then received follow-up emails bearing Evans's signature and Latham & Watkins branding but actually sent from an @consultant.com account, and authorized the payments. The scheme was uncovered only when CEO Robert Pera received an email from an FBI officer in San Francisco warning that money may have been fraudulently taken. Ubiquiti's audit committee found no evidence of employee complicity or IT-system penetration, but concluded its internal control over financial reporting had a material weakness.

How the Attack Worked

This was pure social engineering, not a network breach. Attackers exploited a plausible, high-stakes business pretext (a secret acquisition) delivered through email that impersonated a trusted senior executive, reinforced by a second impersonated authority figure (an outside law-firm attorney) who supplied the banking details. The lures leaned on authority (instructions ostensibly from a superior), urgency (immediate first payment the same day), and enforced confidentiality (the deal was secret, discouraging the employee from verifying through normal channels). Because international wire transfers from the Hong Kong account were routine business practice, the controller treated the emailed instruction as binding rather than an anomaly. The impersonation relied on look-alike/spoofed sender identity rather than an actual takeover of the executive's mailbox, and the absence of an out-of-band verification step for large, unusual payments let 14 transfers proceed before detection.

The Lure & the Tell

Lure: emails posing as a senior Ubiquiti executive announcing a confidential acquisition and directing the finance controller to make urgent payments under the guidance of an outside "Latham & Watkins" attorney, "Tom Evans." Tells: the purported law-firm emails were sent not from a Latham & Watkins domain but from a generic @consultant.com address; there was no actual acquisition or business relationship with any of the recipient firms; payment instructions were confidential, urgent, and bypassed normal verification; and none of the counterparties were entities Ubiquiti had ever dealt with.

Outcome

Ubiquiti lost $46.7M, recovered $8.1M by fiscal year-end with additional court-ordered recoveries over following quarters, and booked a $39.1M loss charge in Q4 FY2015. It disclosed a material weakness in internal control over financial reporting, implemented enhanced controls, cooperated with a multi-agency US and overseas law-enforcement investigation, and later faced shareholder litigation over the disclosures. No perpetrators were publicly identified in the filings.

Why It Matters

One of the largest publicly documented BEC losses of its era, it showed that a company selling networking technology could lose tens of millions with no malware and no system intrusion. It demonstrated how impersonation of executives plus a fabricated confidential deal and a second "trusted advisor" persona can override a finance professional's judgment, and why large or unusual wire requests need mandatory out-of-band verification and dual-authorization controls. It also became a landmark for treating BEC exposure as a financial-reporting and disclosure risk, not just an IT problem.

Defenses

Require out-of-band verification (a callback to a known phone number) for any wire request that is new, large, or urgent, regardless of who it appears to come from. Enforce dual authorization and payment limits on international transfers. Treat secrecy and time pressure as red flags rather than reasons to skip controls. Inspect sender domains carefully (a "law firm" writing from @consultant.com is a tell) and deploy email authentication such as SPF/DKIM/DMARC plus anti-spoofing and look-alike-domain monitoring. Train finance staff specifically on CEO-fraud and acquisition-pretext scenarios, and establish a no-blame escalation path to pause and verify. Note that these are defensive controls only.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target mapping: the fraud ring likely identified Ubiquiti's Hong Kong subsidiary, its wire-authority holder (Controller Rohit Chakravarthy), and CEO Robert Pera's identity through OSINT sources such as corporate filings, the company website, and professional-networking profiles, consistent with how BEC operators typically map finance-department roles and reporting lines before contact.
Countering Stage 1: the OSINT footprint that reveals which named employee holds wire authority is very hard to eliminate at enterprise scale; the realistic control assumes attackers can identify the controller and CEO by name and instead hardens the verification process used at Stages 3 and 5, rather than trying to hide organizational roles.
2
Impersonation infrastructure setup: the actor likely prepared a corporate-look-alike sender identity for the CEO and a separate throwaway @consultant.com account, plus fabricated Latham & Watkins letterhead and a fictitious attorney persona ("Tom Evans"), consistent with commodity BEC tradecraft (spoofed or look-alike domains, forged branding) rather than any network intrusion, which the audit committee's investigation confirmed did not occur.
Countering Stage 2: sender-domain scrutiny and email authentication (SPF/DKIM/DMARC) plus anti-spoofing and look-alike-domain monitoring can catch the mismatch between a claimed law firm and an @consultant.com sending address before any instruction is acted on.
3
Initial pretext contact: the fraudster emailed the controller from what appeared to be the CEO's genuine corporate address on May 19, 2015, announcing a confidential acquisition and directing that a named outside party would issue payment instructions, establishing authority and secrecy in the same message.
Countering Stage 3: require mandatory out-of-band verification, a callback to a pre-established phone number for the purported sender, for any instruction claiming executive authority, regardless of how urgent or routine the request appears.
4
Authority escalation via a second persona: a fraudster posing as "Tom Evans" of Latham & Watkins then contacted the controller directly with signed, law-firm-branded correspondence carrying banking details, corroborating the CEO's instruction through an apparently independent, high-credibility source.
Countering Stage 4: independently verify any newly introduced third party (law firm, advisor, counterparty) through that firm's published contact channels rather than the contact information supplied within the email itself.
5
Urgency-driven first transfer: the pretext demanded an immediate same-day payment, pressuring the controller to act before seeking independent verification, and exploited the fact that international wires from the Hong Kong account were routine business practice rather than an anomaly.
Countering Stage 5: enforce dual authorization and a mandatory hold or cooling-off period on large or first-time international wire requests, explicitly overriding claimed urgency as a justification to skip the check.
6
Sustained exploitation over two weeks: with no out-of-band callback or dual-authorization check in place, the attacker directed 13 additional wire transfers between May 20 and June 5, 2015, continuing to invoke confidentiality to suppress any internal verification of the recurring large payments.
Countering Stage 6: transaction-pattern monitoring for a rapid sequence of large wires to new counterparties, combined with escalating re-verification requirements after the first unusual transfer rather than treating repeat requests as already-approved and routine.
7
Fund dispersal and objective completion: the $46,703,232 was routed to third-party accounts across five jurisdictions (Russia, Hong Kong, China, Hungary, and Poland), consistent with rapid layering intended to frustrate tracing and recovery, completing the fraud before it was flagged externally by an FBI agent's tip to the CEO.
Countering Stage 7: fast-response fund-freeze and recall procedures through banking relationships, plus prompt law-enforcement engagement (as occurred here via the FBI and multi-jurisdiction legal injunctions), can claw back a portion of dispersed funds; this is a post-loss recovery control, not a preventive one, so the real leverage remains further upstream at Stages 3 and 5.
Quick Facts
Victim
Ubiquiti Networks, Inc. (San Jose, CA; NASDAQ: UBNT) via its indirect wholly-owned Hong Kong subsidiary, Ubiquiti Networks International Limited
Location
Hong Kong subsidiary of a US-headquartered company; funds sent to accounts in Russia, Hong Kong, China (PRC), Hungary and Poland
Date
2015-05-20 to 2015-06-05 (discovered 2015-06-05; disclosed 2015-08-06)
Impact
$46,703,232 fraudulently transferred in 14 wires; $8.1M recovered by June 30, 2015, with further court-ordered recoveries thereafter; a $39.1M net BEC fraud loss charge recorded in Q4 FY2015. Company continued pursuing roughly $30M that was likely unrecoverable.
Status
Confirmed
Case Type
Real-World Incident
Sector
Technology & Software
Related

Related Cases

2015 Ukraine Power Grid Attack (Sandworm/BlackEnergy)

Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities,…

Incident 2015Read →

Scoular Company $17.2M grain-trader wire fraud (2014)

Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…

Incident 2014Read →

Seagate CEO-Spoof W-2 Phishing Breach (2016)

A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…

Incident 2016Read →