{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-xoom-corporation-loses-30-8-million-to-employee-impersonation-fraud"},"incident":{"title":"Xoom Corporation loses $30.8 million to employee impersonation fraud","date":"2014-12-30","date_precision":"day","victim_org":"Xoom Corporation","sector":"Financial Services","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI or synthetic media reported.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":30800000,"loss_note":"$30.8 million of corporate cash transferred to overseas accounts. The company said no customer data or customer funds were involved.","records_affected":null,"threat_actor":null,"summary":"Online money-transfer provider Xoom Corporation disclosed in a Form 8-K on January 5, 2015 that on December 30, 2014 it had determined it was the victim of a criminal fraud involving employee impersonation and fraudulent requests targeting its finance department, resulting in $30.8 million of corporate cash being transferred to overseas accounts. Chief Financial Officer Matt Hibbard resigned effective immediately the same day. Federal law enforcement opened a multi-agency investigation and the audit committee commissioned an independent review.","how_it_worked":"The attackers directed impersonated internal requests at Xoom's finance department, the function authorized to move corporate treasury cash. Posing as company personnel, they issued transfer instructions that fit the company's own internal request format, so the payments were processed as legitimate corporate disbursements rather than customer transactions. The money went to accounts abroad and was not recovered. Xoom emphasized that its systems were not breached and no customer funds or data were touched, underscoring that the failure was in the human approval chain for corporate wires. The board's response included an independent investigation, a review of internal controls, and the immediate departure of the CFO.","lessons":"Corporate treasury disbursement requests should be authenticated in a workflow system with enforced separation of duties, never accepted as an emailed instruction that appears to come from a colleague.","confidence":"Confirmed","sources":[{"title":"Xoom Corporation Form 8-K (filed January 5, 2015)","url":"https://www.sec.gov/Archives/edgar/data/1315657/000110465915000360/a15-1144_18k.htm","publisher":"U.S. Securities and Exchange Commission (EDGAR)"}],"entry_type":"incident","slug":"2014-xoom-corporation-loses-30-8-million-to-employee-impersonation-fraud","year":2014,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-xoom-corporation-loses-30-8-million-to-employee-impersonation-fraud"}}