The Email That Sounded Exactly Like Her Boss
The email used the right name, the right tone, and the right approval process. A 2015 case shows how business email compromise works, and why the company was lucky to get the money back.
Business email compromise does not usually rely on malware, hacked servers, or a single dramatic break-in. Most of the time, it relies on one convincing email, sent to exactly the right person, asking for something that sounds like a completely normal part of their job. That is what makes it so hard to catch in the moment — the request often does not look unusual at all.
A well-documented 2015 case at a major toy manufacturer shows how far this can go, and how a bit of luck, combined with fast action, was ultimately what saved the money.
The email reportedly used the real CEO's name and referenced a plausible business reason, arriving soon after his appointment — a detail that likely made an unfamiliar request feel more explainable rather than less. It asked for a wire transfer through what appeared to be a legitimate, if unfamiliar, vendor process, and the request was approved through what looked, on its face, like a normal internal channel.
Nothing about the interaction involved hacking Mattel's systems. The attackers did not need access to any internal network — they needed only enough information about the company's structure and a recent leadership change to write an email that fit naturally into an employee's expectations of what a routine, if unusual, request might look like.
This case is frequently cited because the recovery was closer to luck than to process — a banking holiday bought time that a normal business day would not have. The email itself passed every check that mattered to the person who received it: the sender's name was right, the tone was right, and the request fit inside an existing approval workflow. None of the usual advice about spotting suspicious emails, like watching for spelling mistakes or a strange sender address, would necessarily have caught this one.
That is the core lesson of business email compromise: it is designed to look unremarkable to the person processing it. A request that fits smoothly into someone's normal responsibilities does not trigger the same instinctive caution that an obviously strange email would.
Business email compromise is not a rare or unusual category of crime. The FBI's Internet Crime Complaint Center has repeatedly identified it as one of the costliest categories of cybercrime reported to it each year, ahead of many more technically dramatic attacks. The Mattel case is memorable not because it was unusual, but because the outcome — recovering the money — was.
Because these emails are built specifically to look routine, the most reliable protection is a verification step that does not depend on how convincing the email itself appears.
- Verify any request for a wire transfer or payment change through a separate channel, such as a phone call to a known number, before acting — regardless of how legitimate the email looks.
- Treat a first-time request from a new executive, vendor, or bank account as requiring extra confirmation, especially if it involves urgency or confidentiality.
- Establish a fixed second-approver requirement for large transfers, so no single email, however convincing, can authorize one alone.
The case is now a decade old, but the method hasn't aged out of use — business email compromise is still reported by the FBI as one of the highest-dollar categories of cybercrime it tracks every year, precisely because it doesn't require breaking into anything. It only requires writing an email that fits.
A common mistake
It is tempting to think this kind of scam only works on careless employees. The Mattel case involved an experienced finance executive following a process that looked entirely normal — which is exactly the point.
The Takeaways
Set a rule that any wire transfer or new-vendor payment needs a phone call to a known number before it goes out, no exceptions for urgency.
Be extra cautious around requests that arrive right after a leadership change or a public announcement — that timing is often used on purpose.
Require two people to sign off on large transfers, so a single convincing email can never be enough by itself.
If you would like a visual explanation, continue with the accompanying CyberBlink video.
AI Wrote This Phishing Email — And It Almost Worked
Inside a real business email compromise case: how a convincing, routine-looking request nearly cost millions, and what actually got the money back.