What happened
In its quarterly SEC filing in August 2015, Ubiquiti Networks disclosed that criminals had induced its Hong Kong subsidiary's finance staff to wire $46.7 million to attacker-controlled overseas accounts. The company said the fraud involved employee impersonation and fraudulent requests from an outside entity, with no intrusion into Ubiquiti's systems or loss of customer data.
How the deception worked
Fraudsters used spoofed email addresses and forged requests that appeared to come from senior Ubiquiti executives and from an external business counterparty, instructing the finance team of the company's Hong Kong subsidiary to make a series of international transfers. There was no malware or network compromise; the deception rode entirely on the apparent authority of the sender and on a payments process that accepted email as sufficient authorisation. The fraud was discovered only after the transfers had been made, and Ubiquiti moved to recover funds through legal injunctions in the receiving jurisdictions.
AI involvement · No AI reported
No AI element reported; impersonation was text-based email spoofing.
The control that would have caught it· our reading, not a claim from the sources
Out-of-band verification by known phone number for any payment instruction above a threshold, and dual authorisation for changes to beneficiary details, would have caught the fraudulent requests before the wires left.
Sources (4)
- Tech Firm Ubiquiti Suffers $46M CyberheistKrebs on Security·krebsonsecurity.comOpen ↗
- Networking Manufacturer Ubiquiti Lost $46.7M after Falling for Elaborate Impersonation ScamNextgov/FCW·nextgov.comOpen ↗
- Ubiquiti Networks says it was victim of $47 million cyber scamNBC News·nbcnews.comOpen ↗
- Ubiquiti Networks Form 8-K, August 2015U.S. Securities and Exchange Commission (EDGAR)·sec.govOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.