Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad in 14 transfers over two weeks.
Reviewed by the Social Engineering Examples team.
Ubiquiti Networks, a San Jose networking-hardware maker, disclosed in an August 6, 2015 SEC Form 8-K (and its FY2015 10-K and later 10-Qs) that it was the victim of a business email compromise fraud. Between May 20 and June 5, 2015, criminals impersonating company executives and an outside law firm induced the finance function of Ubiquiti's Hong Kong subsidiary to make 14 wire transfers totaling $46,703,232 from an HSBC Hong Kong account to third-party accounts overseas. Per Ubiquiti's detailed correspondence with SEC staff, the fraud began on May 19, 2015 with an email appearing to come from a senior officer's genuine-looking corporate address, describing a confidential company acquisition and instructing that payments be made under the direction of a person named "Tom Evans," purportedly an attorney at the international law firm Latham & Watkins. The controller/principal financial officer, Rohit Chakravarthy, who had wire authority, then received follow-up emails bearing Evans's signature and Latham & Watkins branding but actually sent from an @consultant.com account, and authorized the payments. The scheme was uncovered only when CEO Robert Pera received an email from an FBI officer in San Francisco warning that money may have been fraudulently taken. Ubiquiti's audit committee found no evidence of employee complicity or IT-system penetration, but concluded its internal control over financial reporting had a material weakness.
This was pure social engineering, not a network breach. Attackers exploited a plausible, high-stakes business pretext (a secret acquisition) delivered through email that impersonated a trusted senior executive, reinforced by a second impersonated authority figure (an outside law-firm attorney) who supplied the banking details. The lures leaned on authority (instructions ostensibly from a superior), urgency (immediate first payment the same day), and enforced confidentiality (the deal was secret, discouraging the employee from verifying through normal channels). Because international wire transfers from the Hong Kong account were routine business practice, the controller treated the emailed instruction as binding rather than an anomaly. The impersonation relied on look-alike/spoofed sender identity rather than an actual takeover of the executive's mailbox, and the absence of an out-of-band verification step for large, unusual payments let 14 transfers proceed before detection.
Lure: emails posing as a senior Ubiquiti executive announcing a confidential acquisition and directing the finance controller to make urgent payments under the guidance of an outside "Latham & Watkins" attorney, "Tom Evans." Tells: the purported law-firm emails were sent not from a Latham & Watkins domain but from a generic @consultant.com address; there was no actual acquisition or business relationship with any of the recipient firms; payment instructions were confidential, urgent, and bypassed normal verification; and none of the counterparties were entities Ubiquiti had ever dealt with.
Ubiquiti lost $46.7M, recovered $8.1M by fiscal year-end with additional court-ordered recoveries over following quarters, and booked a $39.1M loss charge in Q4 FY2015. It disclosed a material weakness in internal control over financial reporting, implemented enhanced controls, cooperated with a multi-agency US and overseas law-enforcement investigation, and later faced shareholder litigation over the disclosures. No perpetrators were publicly identified in the filings.
One of the largest publicly documented BEC losses of its era, it showed that a company selling networking technology could lose tens of millions with no malware and no system intrusion. It demonstrated how impersonation of executives plus a fabricated confidential deal and a second "trusted advisor" persona can override a finance professional's judgment, and why large or unusual wire requests need mandatory out-of-band verification and dual-authorization controls. It also became a landmark for treating BEC exposure as a financial-reporting and disclosure risk, not just an IT problem.
Require out-of-band verification (a callback to a known phone number) for any wire request that is new, large, or urgent, regardless of who it appears to come from. Enforce dual authorization and payment limits on international transfers. Treat secrecy and time pressure as red flags rather than reasons to skip controls. Inspect sender domains carefully (a "law firm" writing from @consultant.com is a tell) and deploy email authentication such as SPF/DKIM/DMARC plus anti-spoofing and look-alike-domain monitoring. Train finance staff specifically on CEO-fraud and acquisition-pretext scenarios, and establish a no-blame escalation path to pause and verify. Note that these are defensive controls only.
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities,…
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…
A spoofed email impersonating Seagate's CEO tricked an HR/payroll employee into emailing every 2015 W-2 to a scammer, exposing SSNs…