A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then used the live CFO mailbox to send about 15 fake-invoice wire requests over nine days, draining nearly $11 million overseas.
Reviewed by the Social Engineering Examples team.
In April 2018, an attacker phished the CFO of Unatrac Holding Limited (a UK export sales office for Caterpillar heavy equipment) with a fake Microsoft Office365 login page, stealing his real credentials. Using that access, the intruder logged into the CFO's live email account over 460 times across two weeks, learned the company's invoice formats and branding, and then sent roughly 15 fraudulent wire-transfer requests with fake invoices from the CFO's genuine mailbox to Unatrac finance staff between April 11 and April 19, 2018. Believing the requests were legitimate, staff wired nearly $11 million to accounts overseas; almost none of it was recovered. The FBI later tied the intrusion to Nigerian national Obinwanne Okeke, who was charged, pleaded guilty, and was sentenced to 10 years in federal prison as part of a broader multi-victim BEC/computer-fraud conspiracy.
Around April 1, 2018, Unatrac's CFO received a phishing email containing a link to a spoofed Microsoft Office365 login page. He entered his credentials on the fake page, and the attacker captured them. Using the stolen credentials, the intruder logged into the CFO's actual Office365 mailbox at least 464 times between April 6 and April 20, 2018, mostly from IP addresses geolocated to Nigeria. With full access to the CFO's live mailbox, OneDrive files, and email history, the attacker studied Unatrac's real invoice templates and company logos, then impersonated the CFO by sending wire-transfer instructions directly from his actual email account (not a lookalike domain) to Unatrac's internal finance staff. Fake invoices, some using genuine Unatrac branding, were attached to make the requests appear routine. In at least one instance (April 19, 2018), the attacker forwarded an external email from a Gmail address with a fraudulent invoice into the CFO's outgoing traffic within two minutes of it arriving, evidently to make the payment request appear corroborated. The intruder also created or modified mailbox filter/forwarding rules to intercept and hide any replies from the real CFO, delaying discovery. Believing the requests came from their own CFO, finance staff processed roughly 15 fraudulent wire payments between April 11 and April 19, 2018, sending funds to accounts including one held by "Pak Fei Trade Limited."
The lure was a phishing email luring the CFO to a convincing fake Microsoft Office365 login page to harvest his credentials. Once inside, the attacker's fraudulent wire requests came from the CFO's genuine, unspoofed email address, complete with real company logos and preformatted invoice templates, and were reinforced by a forwarded third-party email inserted into the thread within minutes to simulate independent confirmation. The tells investigators later identified: a new, unfamiliar payee (Pak Fei Trade Limited) suddenly receiving large wires; 464+ mailbox logins from Nigerian IP addresses against a UK executive's account in a two-week span; creation of hidden mailbox filter/forwarding rules that would have silently diverted the real CFO's replies; and payment instructions that arrived and were acted upon within minutes without any verbal or out-of-band verification, an unusually fast turnaround for multi-hundred-thousand to multi-million dollar wires.
Nearly $11 million was wired out of Unatrac to overseas accounts (including one belonging to "Pak Fei Trade Limited") before the fraud was discovered; the FBI affidavit states very little of the money was recovered. The FBI traced the intrusion, via linked Google/email account records, to Nigerian national Obinwanne Okeke (aka "Invictus Obi"), who was arrested in August 2019 and charged in the Eastern District of Virginia with conspiracy to commit computer fraud and conspiracy to commit wire fraud as part of a broader multi-year (circa 2015-2019) BEC and phishing conspiracy that victimized multiple companies. Okeke pleaded guilty to wire-fraud conspiracy on June 18, 2020, and was sentenced on February 16, 2021 by Chief U.S. District Judge Rebecca Beach Smith to 10 years in federal prison.
This case is one of the best court-documented anatomies of a "true" business email compromise: no lookalike domain or spoofed sender was needed because the attacker had the CFO's actual mailbox, making the fraudulent wire requests functionally indistinguishable from genuine ones to the recipients. It illustrates how a single successful credential-phishing click can cascade into millions in loss over just days, how attackers use mailbox reconnaissance (real logos, real invoice templates, real reply history) to make fraud look routine, and how mailbox rule manipulation is used to delay detection. It also shows that even well-documented federal prosecution and asset-tracing recovered very little of the stolen funds, underscoring that prevention (MFA, callback verification, dual controls) is far more effective than after-the-fact recovery.
Multi-factor authentication on all email/O365 accounts (would have blocked reuse of stolen credentials across 464+ logins); anomalous-login/impossible-travel alerting (logins originated mostly from Nigeria against a UK-based executive); monitoring/alerting on mailbox rule creation (attacker created filter rules to hide replies from the real CFO, a well-known BEC persistence technique); out-of-band verbal/callback verification for any changed or new wire/bank instructions, especially for high-value payments; dual-control/second-approval sign-off on wire transfers above a threshold; scrutiny of invoice-only "confirmation" of payee bank details rather than confirming via a known-good phone number or separate channel; staff training to treat urgent CFO-authorized payment requests via email, especially involving unfamiliar payees, as requiring independent verification; DMARC/anti-spoofing and safe-link/URL rewriting to catch credential-phishing pages impersonating Microsoft login; incident response plan for rapid bank recall requests (recovery was minimal here, underscoring the value of speed, since many banks can claw back funds only within hours of a fraudulent wire).
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition,…
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…