How one fake login cost Unatrac $11 million: the Forbes-listed fraudster's email scam
In 2016 a Nigerian businessman was named one of Africa's most promising young entrepreneurs. 2 years later, prosecutors say, a scheme he ran used one stolen email password to pull about $11 million out of a heavy equipment exporter in roughly 9 days.[1][3][4] This case file covers how the Unatrac fraud worked, how it ended in a 10-year federal sentence, and the one control that would have made the stolen password useless.
What happened
In June 2016 Obinwanne Okeke, then 28, appeared on Forbes Africa's 30 Under 30 list as the founder of Invictus Group, a company he described as spanning construction, agriculture, oil and gas, telecommunications and real estate.[4]
In April 2018 the chief financial officer of Unatrac Holding Limited, the export sales office for Caterpillar heavy industrial and farm equipment, received phishing emails. One linked to a page that looked like the sign-in page for the company's Microsoft Office 365 email. The login details typed there went to the scammers.[1][3]
With the CFO's mailbox open to them, the scammers sent wire transfer requests with fake invoices attached. Between April 11 and April 19, 2018, about 15 payments went out, totaling nearly $11 million, to accounts overseas.[1][2][3] Unatrac reported the fraud to the FBI in June 2018.[3]
How it worked
This is business email compromise, one of the most expensive frauds businesses face. The scammer does not need to break into the bank or the accounting system. They take over one trusted mailbox and let the company's own staff move the money.[1]
A CFO's mailbox is the best one to own. Requests to pay an invoice look routine when they come from the finance chief's real address, in an existing thread, at a normal time of day. According to an FBI affidavit described in the Nigerian press, the account was accessed about 464 times, mostly from internet addresses in Nigeria, with no sign in the reporting that anything blocked or challenged those logins.[3][5]
Prosecutors said this was not a one-off. They described Okeke as running the scheme from about 2015 to 2019, sending phishing emails, building fake login pages and collecting credentials from hundreds of victims in several countries.[1][2]
How it was caught
Investigators traced email accounts used in the scheme back to accounts associated with Okeke.[5] On August 6, 2019, FBI agents arrested him at Washington Dulles International Airport, shortly before he was due to board a flight to Nigeria.[3]
What it cost
On June 18, 2020, Okeke pleaded guilty in federal court in Virginia to conspiracy to commit wire fraud, which carried a maximum of 20 years.[2] On February 16, 2021, he was sentenced to 10 years in prison.[1] He also agreed to forfeit his interest in assets tied to the fraud.[5]
Prosecutors put the known losses from the scheme at about $11 million, most of it from Unatrac.[1]
The missing control
The missing control: multi-factor authentication on executive email accounts. A password alone opened the CFO's mailbox, again and again, from the other side of the world.
Multi-factor authentication asks for a second proof, such as a code from an app or a physical security key, before a new device can sign in. With it turned on, a password typed into a fake page would not have been enough on its own, and hundreds of logins from unfamiliar locations would have run into a wall instead of a mailbox. A second, simpler control would have caught the money on the way out: calling to confirm any new payment request or bank change on a number already on file, not one in the email.
What to do in your business
- Turn on MFA for every mailbox, starting with finance and owners. The people who can approve payments are the ones scammers want. Use an authenticator app or security key, not text messages, where you can.
- Call to confirm payment requests. Any new invoice, urgent wire or change of bank details gets a phone call to a number you already have, before money moves.
- Watch for strange sign-ins. Most business email services can alert you to logins from new countries or devices. Turn those alerts on and have someone read them.
- Check mailbox rules. Scammers often hide replies with forwarding or filtering rules. Look at the rules on finance mailboxes once a month.
- Require 2 people for large payments. No single inbox, even the CFO's, should be enough to send a big wire.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to stop fake invoices, changed bank details and fake-boss payment requests
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How Google and Facebook were scammed: the fake supplier invoices
- The Arup deepfake scam: the $25 million video call where everyone else was fake
- The first known AI voice scam: how a fake boss's call took $243,000
- The Bitfinex hack: how 119,754 bitcoin walked out, then sat still for 5 years
- How a fake Google support call stole 4,100 bitcoin from one person
- Every payments and fraud control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Attorney's Office, Eastern District of Virginia: Nigerian national sentenced to prison for $11 million global fraud scheme
- U.S. Attorney's Office, Eastern District of Virginia: Nigerian businessman pleads guilty to $11 million fraud scheme
- TheCable: FBI arrested Invictus Obi at Dulles International Airport just before escaping US
- Forbes: Africa's most promising entrepreneurs, Forbes Africa's 30 Under 30 for 2016
- Wikipedia: Obinwanne Okeke