Skip to main content

We use Google Analytics on Knowledge Center pages to understand aggregate readership. No account, session, or security-tool data is included. See our Privacy Policy.

CyberBlink AIEvidence. Clarity. Confidence.
Verified Incident

The Email That Sounded Exactly Like Her Boss

The email used the right name, the right tone, and the right approval process. A 2015 case shows how business email compromise works, and why the company was lucky to get the money back.

Business email compromise does not usually rely on malware, hacked servers, or a single dramatic break-in. Most of the time, it relies on one convincing email, sent to exactly the right person, asking for something that sounds like a completely normal part of their job. That is what makes it so hard to catch in the moment — the request often does not look unusual at all.

A well-documented 2015 case at a major toy manufacturer shows how far this can go, and how a bit of luck, combined with fast action, was ultimately what saved the money.

EVIDENCEAs reported by the Associated Press, in April 2015 a finance executive at Mattel received an email that appeared to come from Christopher Sinclair, the company's chief executive, who had taken office only that month, requesting a wire transfer of roughly $3 million to a bank account in China as part of what was described as a new vendor arrangement. The request matched Mattel's approval process closely enough that she authorized it. It was only when she mentioned the transfer to Sinclair directly, hours later, that the company realized the email had not come from him at all. Mattel contacted the FBI, which worked with Chinese banking authorities to freeze the account — helped by the transfer's timing, which landed on a Chinese banking holiday and delayed the money moving further. Mattel recovered the entire $3 million.
Illustrative reconstruction — right name, right tone, right process, wrong sender
01The Investigation

The email reportedly used the real CEO's name and referenced a plausible business reason, arriving soon after his appointment — a detail that likely made an unfamiliar request feel more explainable rather than less. It asked for a wire transfer through what appeared to be a legitimate, if unfamiliar, vendor process, and the request was approved through what looked, on its face, like a normal internal channel.

Nothing about the interaction involved hacking Mattel's systems. The attackers did not need access to any internal network — they needed only enough information about the company's structure and a recent leadership change to write an email that fit naturally into an employee's expectations of what a routine, if unusual, request might look like.

Illustrative reconstruction — only enough company knowledge was needed, not a single hacked system
02The Evidence

This case is frequently cited because the recovery was closer to luck than to process — a banking holiday bought time that a normal business day would not have. The email itself passed every check that mattered to the person who received it: the sender's name was right, the tone was right, and the request fit inside an existing approval workflow. None of the usual advice about spotting suspicious emails, like watching for spelling mistakes or a strange sender address, would necessarily have caught this one.

That is the core lesson of business email compromise: it is designed to look unremarkable to the person processing it. A request that fits smoothly into someone's normal responsibilities does not trigger the same instinctive caution that an obviously strange email would.

Business email compromise is not a rare or unusual category of crime. The FBI's Internet Crime Complaint Center has repeatedly identified it as one of the costliest categories of cybercrime reported to it each year, ahead of many more technically dramatic attacks. The Mattel case is memorable not because it was unusual, but because the outcome — recovering the money — was.

Illustrative reconstruction — no single message authorizes a transfer alone
03The Protection

Because these emails are built specifically to look routine, the most reliable protection is a verification step that does not depend on how convincing the email itself appears.

  • Verify any request for a wire transfer or payment change through a separate channel, such as a phone call to a known number, before acting — regardless of how legitimate the email looks.
  • Treat a first-time request from a new executive, vendor, or bank account as requiring extra confirmation, especially if it involves urgency or confidentiality.
  • Establish a fixed second-approver requirement for large transfers, so no single email, however convincing, can authorize one alone.

The case is now a decade old, but the method hasn't aged out of use — business email compromise is still reported by the FBI as one of the highest-dollar categories of cybercrime it tracks every year, precisely because it doesn't require breaking into anything. It only requires writing an email that fits.

A common mistake

It is tempting to think this kind of scam only works on careless employees. The Mattel case involved an experienced finance executive following a process that looked entirely normal — which is exactly the point.

Protection

The Takeaways

  1. Set a rule that any wire transfer or new-vendor payment needs a phone call to a known number before it goes out, no exceptions for urgency.

  2. Be extra cautious around requests that arrive right after a leadership change or a public announcement — that timing is often used on purpose.

  3. Require two people to sign off on large transfers, so a single convincing email can never be enough by itself.

Companion Video

If you would like a visual explanation, continue with the accompanying CyberBlink video.

A reconstructed email reading pane showing an urgent wire-transfer request that appears to come from the chief executive

AI Wrote This Phishing Email — And It Almost Worked

Inside a real business email compromise case: how a convincing, routine-looking request nearly cost millions, and what actually got the money back.

Now availableWatch on YouTube