What happened
Online money-transfer provider Xoom Corporation disclosed in a Form 8-K on January 5, 2015 that on December 30, 2014 it had determined it was the victim of a criminal fraud involving employee impersonation and fraudulent requests targeting its finance department, resulting in $30.8 million of corporate cash being transferred to overseas accounts. Chief Financial Officer Matt Hibbard resigned effective immediately the same day. Federal law enforcement opened a multi-agency investigation and the audit committee commissioned an independent review.
How the deception worked
The attackers directed impersonated internal requests at Xoom's finance department, the function authorized to move corporate treasury cash. Posing as company personnel, they issued transfer instructions that fit the company's own internal request format, so the payments were processed as legitimate corporate disbursements rather than customer transactions. The money went to accounts abroad and was not recovered. Xoom emphasized that its systems were not breached and no customer funds or data were touched, underscoring that the failure was in the human approval chain for corporate wires. The board's response included an independent investigation, a review of internal controls, and the immediate departure of the CFO.
AI involvement · No AI reported
No AI or synthetic media reported.
The control that would have caught it· our reading, not a claim from the sources
Corporate treasury disbursement requests should be authenticated in a workflow system with enforced separation of duties, never accepted as an emailed instruction that appears to come from a colleague.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.