Ubiquiti lost $46.7 million after fraudulent requests hit its finance team

Ubiquiti Networks lost $46.7 million after fraudulent requests hit its finance team. On June 5, 2015, the company determined it had been the victim of a criminal fraud. Per its SEC Form 8-K, the incident involved employee impersonation and fraudulent requests from an outside entity targeting the company’s finance department. Thieves moved $46.7 million from a Hong Kong subsidiary into overseas accounts held by third parties.
Ubiquiti contacted the Hong Kong bank, started legal actions abroad, and recovered $8.1 million quickly. Another $6.8 million sat under injunction and was expected back; $31.8 million was still being chased while U.S. and overseas investigators worked the case. An Audit Committee probe found no evidence the company’s systems were penetrated, no data exposure, and no employee criminal involvement — but it did find material weaknesses in internal control over financial reporting. Krebs on Security framed the filing in the broader “CEO fraud” / business-email-compromise pattern; Ubiquiti itself did not publish a step-by-step of the spoof.
Large wires that start with an urgent email from “leadership” need a second channel that isn’t reply.
If you want a plain read on whether strangers can email as your company — spoofcoach.com. Free.
Sources: SEC 8-K 000157104915006288; krebsonsecurity.com 2015-08.