Skip to main content
When $46.7 Million Vanished in 17 DaysThird-Party Due Diligence
5 min readFor Security Awareness Teams

When $46.7 Million Vanished in 17 Days

The Challenge

Between wire transfers one through fourteen, nobody noticed. The emails looked legitimate, the invoices matched expected patterns, and the payment requests came from addresses that seemed to belong to known vendors. By the time Ubiquiti Networks discovered the fraud, $46.7 million had left their accounts over 17 days. The company didn't catch it themselves; the FBI did.

This isn't about a sophisticated attack. It's about process gaps that existed long before the attacker showed up.

When fraud investigators reconstruct these incidents, they're not usually chasing technical exploits. They're documenting the moment someone skipped a phone call, the moment nobody checked whether a domain was three weeks old, and the moment an invoice sailed through because it looked like all the other exceptions the organization had already normalized.

The Environment and Constraints

Vendor email compromise thrives in the space between urgency and verification. Finance teams process hundreds of invoices under time pressure. Procurement cycles move faster than policy documentation. Accounts payable systems accumulate exceptions: payments processed directly by finance, invoices approved without procurement sign-off, amounts structured just below dual-authorization thresholds.

The FBI's Internet Crime Complaint Center recorded $2.77 billion in confirmed business email compromise losses in 2024, with the average loss per incident nearly $130,000. These aren't anomalies. They're the predictable outcome of organizations running payment processes with gaps wide enough for an attacker to walk through.

Attackers study email traffic patterns before they strike. They identify which vendor relationships move quickly, which payment categories bypass standard controls, and which thresholds trigger additional scrutiny. They don't defeat your controls; they identify where your controls don't apply.

In most cases, detection doesn't happen through real-time monitoring. It happens at a quarterly audit when a legitimate vendor calls to ask why their payment never arrived. By then, the funds have moved through multiple jurisdictions. The practical window for intervention is 24 to 72 hours after transfer. Discovery typically happens weeks or months later.

The Approach That Should Have Been Taken

Preventing these losses doesn't require sophisticated fraud detection systems or expensive technology. It requires three basic verification steps applied consistently:

Callback verification for banking detail changes. Any change to vendor payment information requires a verbal confirmation call to a phone number sourced independently from the change request. Not the number in the email. Not the number in the email signature. The number on file from the original vendor setup. This applies to existing vendors, not just new ones. Attackers know that organizations often skip verification for longstanding relationships.

Domain verification during payment approval. Before processing a payment request that arrived by email, check the sending domain. A basic WHOIS lookup shows when a domain was registered. Newly registered domains, domains with no established history, or domains that don't match the vendor's known email address should trigger immediate holds. This doesn't require a security team. It requires 90 seconds and a policy that flags mismatches.

Exception auditing. Every accounts payable process has categories of transactions that move faster than standard workflows. Map those exceptions. Understand why they exist. Close the ones that can't be justified by operational necessity. The invoices that get approved without full verification are the ones attackers study and replicate.

Results That Organizations Actually See

Organizations that formalize these three controls see detection move from months to hours. When banking detail changes require callback verification with documented records, fraudulent change requests get caught before any transfer is initiated. When domain checks become mandatory steps in payment workflows, spoofed email addresses get flagged immediately.

The Ubiquiti case would have been stopped at the domain verification step. The fraudulent emails used addresses that looked like legitimate internal and vendor contacts but came from recently registered domains. A verification protocol would have caught the mismatch before the first wire transfer.

The practical outcome isn't just fraud prevention. It's faster detection when fraud does occur. Organizations with consistent verification protocols discover incidents in days, not quarters. That timing matters. Funds can sometimes be recovered in the first 72 hours. After that, recovery becomes partial at best.

What Investigators Wish Had Happened Differently

After reconstructing these cases, investigators consistently identify the same missed opportunities. The callback that would have taken three minutes. The domain check that would have taken 90 seconds. The exception audit that would have revealed which payment categories were routinely bypassing verification.

The question investigators ask isn't "How did the attacker get in?" It's "Why was there no second check?" In the majority of vendor fraud cases, the loss was preceded by at least one moment where a standard verification step either didn't exist, was skipped under time pressure, or had never been formalized into policy.

The organizations that avoid these losses aren't the ones with the most sophisticated detection systems. They're the ones that made basic checks non-negotiable before an investigator ever had a reason to ask why they were skipped.

Takeaways for Your Team

Start with your exceptions. Identify which payment categories move faster than your standard workflow. Those are your exposure points. If you can't justify the exception with operational necessity, close it.

Formalize callback verification for any banking detail change. Make it a documented step with a record of who called, when, and what number they used. Remove discretion. Remove the option to skip it under time pressure.

Build domain verification into your payment approval checklist. Train your accounts payable team to run a basic WHOIS lookup before processing vendor email requests. Flag domains registered within the past 90 days.

The most effective fraud prevention isn't technology. It's process discipline applied consistently to the moments of highest risk. By the time an investigator is reconstructing your incident, the money is already gone. The window for intervention is before the transfer, not after.

FBI's Internet Crime Complaint Center

You Might Also Like