Case Library / Phishing / Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise
Phishing Confirmed

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then used the live CFO mailbox to send about 15 fake-invoice wire requests over nine days, draining nearly $11 million overseas.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In April 2018, an attacker phished the CFO of Unatrac Holding Limited (a UK export sales office for Caterpillar heavy equipment) with a fake Microsoft Office365 login page, stealing his real credentials. Using that access, the intruder logged into the CFO's live email account over 460 times across two weeks, learned the company's invoice formats and branding, and then sent roughly 15 fraudulent wire-transfer requests with fake invoices from the CFO's genuine mailbox to Unatrac finance staff between April 11 and April 19, 2018. Believing the requests were legitimate, staff wired nearly $11 million to accounts overseas; almost none of it was recovered. The FBI later tied the intrusion to Nigerian national Obinwanne Okeke, who was charged, pleaded guilty, and was sentenced to 10 years in federal prison as part of a broader multi-victim BEC/computer-fraud conspiracy.

How the Attack Worked

Around April 1, 2018, Unatrac's CFO received a phishing email containing a link to a spoofed Microsoft Office365 login page. He entered his credentials on the fake page, and the attacker captured them. Using the stolen credentials, the intruder logged into the CFO's actual Office365 mailbox at least 464 times between April 6 and April 20, 2018, mostly from IP addresses geolocated to Nigeria. With full access to the CFO's live mailbox, OneDrive files, and email history, the attacker studied Unatrac's real invoice templates and company logos, then impersonated the CFO by sending wire-transfer instructions directly from his actual email account (not a lookalike domain) to Unatrac's internal finance staff. Fake invoices, some using genuine Unatrac branding, were attached to make the requests appear routine. In at least one instance (April 19, 2018), the attacker forwarded an external email from a Gmail address with a fraudulent invoice into the CFO's outgoing traffic within two minutes of it arriving, evidently to make the payment request appear corroborated. The intruder also created or modified mailbox filter/forwarding rules to intercept and hide any replies from the real CFO, delaying discovery. Believing the requests came from their own CFO, finance staff processed roughly 15 fraudulent wire payments between April 11 and April 19, 2018, sending funds to accounts including one held by "Pak Fei Trade Limited."

The Lure & the Tell

The lure was a phishing email luring the CFO to a convincing fake Microsoft Office365 login page to harvest his credentials. Once inside, the attacker's fraudulent wire requests came from the CFO's genuine, unspoofed email address, complete with real company logos and preformatted invoice templates, and were reinforced by a forwarded third-party email inserted into the thread within minutes to simulate independent confirmation. The tells investigators later identified: a new, unfamiliar payee (Pak Fei Trade Limited) suddenly receiving large wires; 464+ mailbox logins from Nigerian IP addresses against a UK executive's account in a two-week span; creation of hidden mailbox filter/forwarding rules that would have silently diverted the real CFO's replies; and payment instructions that arrived and were acted upon within minutes without any verbal or out-of-band verification, an unusually fast turnaround for multi-hundred-thousand to multi-million dollar wires.

Outcome

Nearly $11 million was wired out of Unatrac to overseas accounts (including one belonging to "Pak Fei Trade Limited") before the fraud was discovered; the FBI affidavit states very little of the money was recovered. The FBI traced the intrusion, via linked Google/email account records, to Nigerian national Obinwanne Okeke (aka "Invictus Obi"), who was arrested in August 2019 and charged in the Eastern District of Virginia with conspiracy to commit computer fraud and conspiracy to commit wire fraud as part of a broader multi-year (circa 2015-2019) BEC and phishing conspiracy that victimized multiple companies. Okeke pleaded guilty to wire-fraud conspiracy on June 18, 2020, and was sentenced on February 16, 2021 by Chief U.S. District Judge Rebecca Beach Smith to 10 years in federal prison.

Why It Matters

This case is one of the best court-documented anatomies of a "true" business email compromise: no lookalike domain or spoofed sender was needed because the attacker had the CFO's actual mailbox, making the fraudulent wire requests functionally indistinguishable from genuine ones to the recipients. It illustrates how a single successful credential-phishing click can cascade into millions in loss over just days, how attackers use mailbox reconnaissance (real logos, real invoice templates, real reply history) to make fraud look routine, and how mailbox rule manipulation is used to delay detection. It also shows that even well-documented federal prosecution and asset-tracing recovered very little of the stolen funds, underscoring that prevention (MFA, callback verification, dual controls) is far more effective than after-the-fact recovery.

Defenses

Multi-factor authentication on all email/O365 accounts (would have blocked reuse of stolen credentials across 464+ logins); anomalous-login/impossible-travel alerting (logins originated mostly from Nigeria against a UK-based executive); monitoring/alerting on mailbox rule creation (attacker created filter rules to hide replies from the real CFO, a well-known BEC persistence technique); out-of-band verbal/callback verification for any changed or new wire/bank instructions, especially for high-value payments; dual-control/second-approval sign-off on wire transfers above a threshold; scrutiny of invoice-only "confirmation" of payee bank details rather than confirming via a known-good phone number or separate channel; staff training to treat urgent CFO-authorized payment requests via email, especially involving unfamiliar payees, as requiring independent verification; DMARC/anti-spoofing and safe-link/URL rewriting to catch credential-phishing pages impersonating Microsoft login; incident response plan for rapid bank recall requests (recovery was minimal here, underscoring the value of speed, since many banks can claw back funds only within hours of a fraudulent wire).

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target and Pretext Research: Before contact, the conspirators (per DOJ, operating as part of Obinwanne Okeke's multi-year, multi-victim Invictus Group fraud network) typically identify a target company that routinely moves large wire sums, such as an export/distribution dealer, and research its executives (for example, the CFO by name and title) likely through public company information, LinkedIn, and other open sources, to build a credible pretext before any email is sent.
Countering Stage 1: Public information about executives and company scale (LinkedIn profiles, org charts, trade-press coverage of deal volume) is very hard to suppress at enterprise scale; the realistic control assumes attackers can already build this pretext and instead hardens the payment-approval process it later gets used against, addressed at Stages 8 and 9.
2
Phishing Infrastructure Setup: Consistent with the conspiracy's documented pattern of using look-alike domains elsewhere (the FBI affidavit notes a related misspelled domain registered to an associated email address), the attacker sets up a fake web page cloned to imitate the legitimate Microsoft Office365 login screen, built to capture whatever username and password a victim enters.
Countering Stage 2: Brand-protection and look-alike domain monitoring, combined with DMARC/anti-spoofing controls and safe-link/URL rewriting on inbound mail, can flag or block phishing pages impersonating a Microsoft login before an employee ever reaches them.
3
Initial Access via Credential Phishing: On or about April 1, 2018, Unatrac's CFO received a phishing email containing a link to the spoofed Office365 login page; he entered his real credentials there, and the attacker captured them.
Countering Stage 3: Phishing-resistant multi-factor authentication (such as hardware security keys) on all O365 accounts is the single highest-leverage control here; even with the password captured, MFA would have stopped the attacker from ever completing login and would have prevented every downstream stage.
4
Account Takeover and Persistent Access: Using the stolen credentials, the intruder logged into the CFO's live Office365 mailbox at least 464 times between April 6 and April 20, 2018, mostly from IP addresses geolocated to Nigeria, establishing durable, repeated access rather than a single smash-and-grab.
Countering Stage 4: Conditional-access policies with anomalous-login and impossible-travel alerting would have flagged 464+ logins from Nigerian IP addresses against a UK executive's account and could have forced re-authentication or automatically suspended the session.
5
Internal Reconnaissance: With full mailbox and OneDrive access, the attacker browsed the CFO's email history and files (viewing at least 15 documents, including tax filings and travel schedules) to learn Unatrac's real invoice templates, logos, and communication norms needed to make fraudulent requests look authentic.
Countering Stage 5: Mailbox and file-access logging with alerting on unusual volumes of message reads and OneDrive file opens on executive accounts would have surfaced the abnormal internal browsing before the attacker had time to build a convincing pretext.
6
Concealment via Mailbox Rule Manipulation: Between April 10 and April 17, 2018, the intruder created or modified email filter/forwarding rules on the CFO's account on seven documented occasions, silently rerouting incoming replies from finance staff so the real CFO would not see them.
Countering Stage 6: Dedicated monitoring and alerting on the creation or modification of mailbox filter/forwarding rules, a well-documented BEC persistence technique, would have flagged the seven rule changes made on the CFO's account within days of the intrusion.
7
Fabricated Third-Party Corroboration: On April 19, 2018, the attacker had an external Gmail address send a message into the CFO's account, then forwarded it internally within two minutes with a fraudulent invoice attached, engineering the appearance of an independently confirmed, outside-originated invoice.
Countering Stage 7: Staff training and procedure that treat an emailed "confirmation" of new payee or invoice details as insufficient on its own, since a forwarded third-party email can itself be fabricated, and instead require corroboration through a separate, known-good channel.
8
Social Engineering of Finance Staff: Impersonating the CFO from his genuine, unspoofed mailbox, the attacker sent roughly 15 wire-transfer requests with fake invoices bearing real Unatrac branding to internal finance staff between April 11 and April 19, 2018.
Countering Stage 8: Policy that any urgent CFO-authorized wire instruction sent by email, particularly one naming an unfamiliar payee, automatically triggers independent verification regardless of how legitimate the sending mailbox appears.
9
Fraudulent Wire Execution and Fund Exfiltration: Believing the requests were legitimate, finance staff processed the payments, sending nearly $11 million to overseas accounts including one held by Pak Fei Trade Limited; by the time the fraud was discovered, the transfers could not be recalled and almost none of the money was recovered.
Countering Stage 9: Out-of-band verbal or callback verification plus dual-control/second-approval sign-off above a dollar threshold for wire transfers is the last realistic backstop; paired with a rapid-response relationship with the bank and law enforcement (IC3) for emergency recall requests, since banks can typically only claw back a fraudulent wire within hours of the transfer.
Quick Facts
Victim
Unatrac Holding Limited, a UK-based export sales office/dealer for Caterpillar heavy equipment
Location
Unatrac Holding Limited, headquartered in the United Kingdom (Caterpillar heavy-equipment export/sales office); fraudulent logins traced mostly to Nigeria; federal prosecution in the Eastern District of Virginia, USA
Date
2018-04-01 (initial phishing/compromise); 2018-04-11 to 2018-04-19 (fraudulent wire requests); 2020-06-18 (Okeke guilty plea); 2021-02-16 (sentencing)
Impact
Approximately $11 million (three documented Pak Fei Trade Limited wires alone totaled $278,270.66 + $898,461.17 + $1,957,100.00 = $3,133,831.83; total across ~15 fraudulent payments reached nearly $11,000,000); DOJ's sentencing materials describe the loss as "approximately $11 million." Per the FBI affidavit, Unatrac was able to recover very little of the transferred funds.
Status
Confirmed
Case Type
Real-World Incident
Sector
Manufacturing & Industrial
Threat Actor
Organized Crime
Related

Related Cases

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…

Incident 2018Read →

Pathé €19.2M fake-CEO cinema-chain fraud (2018)

Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition,…

Incident 2018Read →

Toyota Boshoku European Subsidiary $37M BEC (2019)

A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…

Incident 2019Read →