How Ubiquiti lost $46.7 million: the wire requests nobody called to check
In 2015 a publicly traded networking company sent $46.7 million to criminals, and its own investigators found no sign that anyone had broken into its computers.[1] This case file covers how a stream of fake requests emptied a subsidiary's accounts, how much came back, and the one habit that would have stopped it.
What happened
Ubiquiti Networks, a California maker of wireless and networking gear, kept money in a subsidiary incorporated in Hong Kong. In 2015 outsiders targeted the company's finance department with messages that impersonated employees and asked for payments to be sent abroad.[1][2]
The requests looked routine enough that staff acted on them. Over a series of transfers, $46.7 million left the Hong Kong subsidiary for overseas bank accounts held by third parties.[1]
On June 5, 2015, the company realized what had happened. It began working with its banks and law enforcement to trace and claw back the money, and its board's audit committee opened an independent investigation, which wrapped up on July 17, 2015.[1] The public learned about it that August, when the company disclosed the loss in a filing with the Securities and Exchange Commission.[1][2]
How it worked
This was a business email compromise, sometimes called CEO fraud. The criminals did not need malware or stolen passwords. They needed the finance team to believe that a message came from someone inside the company with the authority to move money.[2][3]
Scams like this usually lean on 3 things: a sender name that looks familiar, a plausible business reason such as a deal, a supplier payment or an urgent transfer, and pressure to act quickly or quietly. A finance employee who is used to taking instructions by email sees nothing unusual, follows the process they normally follow, and releases the wire. Each payment on its own can look ordinary. It is only when someone steps back and asks whether the real executive ever made the request that the whole thing falls apart.
The company's investigation found no evidence that its systems had been penetrated and no evidence that any employee was criminally involved.[1] In other words, the process worked exactly as designed. The design simply had no step that checked whether a request was real before the money moved.
What it cost
Once the fraud came to light, the recovery effort got some of the money back, but not most of it. As of the August 2015 filing, Ubiquiti had recovered $8.1 million, and another $6.8 million was frozen under legal injunctions while it tried to get that returned. The remaining $31.8 million was still missing.[1][2]
The fallout reached the company's financial reporting too. The audit committee concluded that Ubiquiti's internal control over financial reporting was ineffective because of one or more material weaknesses, a formal finding that public companies must disclose to investors.[1] In the same filing the company said its chief accounting officer had resigned and that an interim replacement had been appointed, while stating the resignation was not due to any disagreement over its operations or reporting.[1] Ubiquiti said it had put enhanced controls in place since June 5 and was adding more procedures recommended by the investigation.[1]
Ubiquiti was far from alone. Earlier in 2015 the FBI warned that scams of this kind had taken nearly $215 million from businesses over roughly 14 months.[2]
The missing control
The missing control: callback verification for wire requests. Before any new or unusual payment goes out, someone confirms it with the requester by phone, using a number already on file, never one supplied in the request itself.
A single call would have been enough. The people being impersonated had not asked for these payments, so the first time finance checked with them through a separate channel the scheme would have ended. Instead, each transfer relied only on the message that asked for it, and the losses kept growing until the fraud was finally noticed. Recovery after the fact is slow and partial, as Ubiquiti's numbers show. Verification before the money moves costs a few minutes.
What to do in your business
- Make the callback rule written policy. Any request to send money, change bank details or pay a new account gets confirmed by phone with a known number before it is paid. No exceptions for urgency or seniority.
- Use the number you already have. Call the person from your contact list or vendor file, not from the email signature, invoice or message that made the request.
- Tell staff it is safe to slow the boss down. Say out loud that nobody will be in trouble for checking a request from an owner or manager. Scammers count on people being afraid to ask.
- Set a threshold for a second approver. Above a dollar amount you choose, require 2 people to sign off on a wire, so one convincing message cannot move money alone.
- Know who to call if it happens. Keep your bank's fraud line handy and report quickly. The faster a bank is told, the better the chance of freezing funds.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to stop fake invoices, changed bank details and fake-boss payment requests
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How Google and Facebook were scammed: the fake supplier invoices
- The Arup deepfake scam: the $25 million video call where everyone else was fake
- The first known AI voice scam: how a fake boss's call took $243,000
- The Bitfinex hack: how 119,754 bitcoin walked out, then sat still for 5 years
- How a fake Google support call stole 4,100 bitcoin from one person
- Every payments and fraud control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.