GoFirm
Back to Blog
Case Studies·3 min read

The Perimeter Was Never Breached. $46.7 Million Still Disappeared.

By GoFirm

In the summer of 2015, thieves stole $46.7 million from Ubiquiti Networks without ever touching the company's systems.

Ubiquiti's own SEC filing described what happened: "employee impersonation and fraudulent requests from an outside entity targeting the Company's finance department." Attackers spoofed communications from senior executives and directed the finance team to initiate a series of international wire transfers to overseas accounts. The transfers were processed. By the time Ubiquiti discovered the fraud on 5 June 2015, the money was gone. Only $15 million was ever recovered.

No systems were compromised. No malware was deployed. No credentials were stolen. The investigation found no evidence that Ubiquiti's network had been penetrated at all. The attackers did not need to get inside. They needed the finance department to act on instructions that appeared to come from authorised executives, and they did.

This is the attack pattern the FBI now calls Business Email Compromise. In 2025 alone, it generated over $3 billion in reported losses in the United States, with the average wire transfer request exceeding $122,000 per incident. Ubiquiti was one of the first major public disclosures of a BEC attack at this scale. A decade later, the same mechanism - impersonate an authority figure, instruct a financial action, collect the transfer - remains one of the most financially destructive and consistently successful attack vectors in enterprise security.

The reason it keeps working is straightforward. Wire transfer workflows are typically authorised through email instruction or internal messaging. Someone sends the request, someone else processes it. The processor verifies the apparent source of the instruction, not whether the named authority actually sanctioned the specific transfer through a confirmed, independent channel. When the apparent source has been convincingly spoofed, that verification fails.

GoFirm removes the gap entirely. Every wire transfer above a configured threshold requires a confirmation from the named authority on their registered personal device, through a channel completely separate from the email or messaging system used to initiate the request. The authority reviews the exact transfer details - amount, beneficiary, reference - and confirms with their biometric. An attacker who has successfully spoofed an executive's email address, or even compromised their inbox, cannot reach that device. Cannot produce that confirmation. The transfer does not execute.

Ubiquiti had no technical failure to fix after this incident. Their systems were clean. What they lacked was an authority confirmation requirement at the execution boundary of high-consequence financial actions. That gap cost them $31.7 million they never got back.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.

References

1. Ubiquiti Networks Inc., SEC Quarterly Financial Report, August 2015

2. Krebs on Security, Tech Firm Ubiquiti Suffers $46M Cyberheist, August 2015

3. FBI Internet Crime Complaint Center, 2025 Internet Crime Report, April 2026

Share this article