{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ubiquiti-networks-loses-46-7m-to-executive-impersonation-business-email"},"incident":{"title":"Ubiquiti Networks loses $46.7M to executive-impersonation business email compromise","date":"2015-06-05","date_precision":"day","victim_org":"Ubiquiti Networks","sector":"Technology","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Spear Phishing (Email)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; impersonation was text-based email spoofing.","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":46700000,"loss_note":"Ubiquiti disclosed $46.7 million transferred; $8.1 million was recovered at the time of disclosure and the company said additional sums were subject to legal injunction and expected to be recovered.","records_affected":null,"threat_actor":null,"summary":"In its quarterly SEC filing in August 2015, Ubiquiti Networks disclosed that criminals had induced its Hong Kong subsidiary's finance staff to wire $46.7 million to attacker-controlled overseas accounts. The company said the fraud involved employee impersonation and fraudulent requests from an outside entity, with no intrusion into Ubiquiti's systems or loss of customer data.","how_it_worked":"Fraudsters used spoofed email addresses and forged requests that appeared to come from senior Ubiquiti executives and from an external business counterparty, instructing the finance team of the company's Hong Kong subsidiary to make a series of international transfers. There was no malware or network compromise; the deception rode entirely on the apparent authority of the sender and on a payments process that accepted email as sufficient authorisation. The fraud was discovered only after the transfers had been made, and Ubiquiti moved to recover funds through legal injunctions in the receiving jurisdictions.","lessons":"Out-of-band verification by known phone number for any payment instruction above a threshold, and dual authorisation for changes to beneficiary details, would have caught the fraudulent requests before the wires left.","confidence":"Confirmed","sources":[{"title":"Tech Firm Ubiquiti Suffers $46M Cyberheist","url":"https://krebsonsecurity.com/2015/08/tech-firm-ubiquiti-suffers-46m-cyberheist/","publisher":"Krebs on Security"},{"title":"Networking Manufacturer Ubiquiti Lost $46.7M after Falling for Elaborate Impersonation Scam","url":"https://www.nextgov.com/cybersecurity/2015/08/breach/143746/","publisher":"Nextgov/FCW"},{"title":"Ubiquiti Networks says it was victim of $47 million cyber scam","url":"https://www.nbcnews.com/tech/security/ubiquiti-networks-says-it-was-victim-47-million-cyber-scam-n406201","publisher":"NBC News"},{"title":"Ubiquiti Networks Form 8-K, August 2015","url":"https://www.sec.gov/Archives/edgar/data/1511737/000157104915006288/t1501817_8k.htm","publisher":"U.S. Securities and Exchange Commission (EDGAR)"}],"entry_type":"incident","slug":"2015-ubiquiti-networks-loses-46-7m-to-executive-impersonation-business-email","year":2015,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ubiquiti-networks-loses-46-7m-to-executive-impersonation-business-email"}}