Case file · UBIQUITI 2015

How Ubiquiti lost $46.7 million: the wire requests nobody called to check

Published 2026-09-29 · 4 min read · Missing control: Callback verification for wire requests

In 2015 a publicly traded networking company sent $46.7 million to criminals, and its own investigators found no sign that anyone had broken into its computers.[1] This case file covers how a stream of fake requests emptied a subsidiary's accounts, how much came back, and the one habit that would have stopped it.

What happened

Ubiquiti Networks, a California maker of wireless and networking gear, kept money in a subsidiary incorporated in Hong Kong. In 2015 outsiders targeted the company's finance department with messages that impersonated employees and asked for payments to be sent abroad.[1][2]

The requests looked routine enough that staff acted on them. Over a series of transfers, $46.7 million left the Hong Kong subsidiary for overseas bank accounts held by third parties.[1]

On June 5, 2015, the company realized what had happened. It began working with its banks and law enforcement to trace and claw back the money, and its board's audit committee opened an independent investigation, which wrapped up on July 17, 2015.[1] The public learned about it that August, when the company disclosed the loss in a filing with the Securities and Exchange Commission.[1][2]

How it worked

This was a business email compromise, sometimes called CEO fraud. The criminals did not need malware or stolen passwords. They needed the finance team to believe that a message came from someone inside the company with the authority to move money.[2][3]

Scams like this usually lean on 3 things: a sender name that looks familiar, a plausible business reason such as a deal, a supplier payment or an urgent transfer, and pressure to act quickly or quietly. A finance employee who is used to taking instructions by email sees nothing unusual, follows the process they normally follow, and releases the wire. Each payment on its own can look ordinary. It is only when someone steps back and asks whether the real executive ever made the request that the whole thing falls apart.

The company's investigation found no evidence that its systems had been penetrated and no evidence that any employee was criminally involved.[1] In other words, the process worked exactly as designed. The design simply had no step that checked whether a request was real before the money moved.

What it cost

Once the fraud came to light, the recovery effort got some of the money back, but not most of it. As of the August 2015 filing, Ubiquiti had recovered $8.1 million, and another $6.8 million was frozen under legal injunctions while it tried to get that returned. The remaining $31.8 million was still missing.[1][2]

The fallout reached the company's financial reporting too. The audit committee concluded that Ubiquiti's internal control over financial reporting was ineffective because of one or more material weaknesses, a formal finding that public companies must disclose to investors.[1] In the same filing the company said its chief accounting officer had resigned and that an interim replacement had been appointed, while stating the resignation was not due to any disagreement over its operations or reporting.[1] Ubiquiti said it had put enhanced controls in place since June 5 and was adding more procedures recommended by the investigation.[1]

Ubiquiti was far from alone. Earlier in 2015 the FBI warned that scams of this kind had taken nearly $215 million from businesses over roughly 14 months.[2]

The missing control

The missing control: callback verification for wire requests. Before any new or unusual payment goes out, someone confirms it with the requester by phone, using a number already on file, never one supplied in the request itself.

A single call would have been enough. The people being impersonated had not asked for these payments, so the first time finance checked with them through a separate channel the scheme would have ended. Instead, each transfer relied only on the message that asked for it, and the losses kept growing until the fraud was finally noticed. Recovery after the fact is slow and partial, as Ubiquiti's numbers show. Verification before the money moves costs a few minutes.

What to do in your business

Watch the case
Fake executive emails that cost $46.7 millionDrops 2026-12-21
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More payments and fraud cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. SEC: Ubiquiti Networks, Inc. Form 8-K (August 2015)
  2. Krebs on Security: Tech firm Ubiquiti suffers $46M cyberheist
  3. CSO Online: Ubiquiti Networks victim of $39 million social engineering attack