Tech Firm Ubiquiti Suffers $46M Cyberheist
krebsonsecurity.com
krebsonsecurity.com
This will fall apart when we get to cashing out downstream, or buying physical goods that are on-demand manufactured/shipped, or stock market trades, but a large percentage should be recoverable in $large cases and (outside of certain sophisticated patterns) the receiver of the money who spent it should be on the hook for the difference.
30m unrecoverable as yet is just silly.
Paypal or now bitcoin (or the blockchain at least) as the main infrastructure would definitely reduce fraud and errors.
I've seen similar attacks before, granted for lower amounts, but in many companies, finance departments sending out wires for many hundreds of thousands of dollars is a common operation -- suppliers, contracts signed, and everyone wants their wire transfer to be done ASAP.
Get an email from the CFO/CEO/SVP of X saying to wire money for contract Z ASAP, and action will be taken.
I heard a story that at one place the only reason they didn't scammed is because the accountant walked over to the CEO to double-check the instructions of the wire transfer. It's easy to imagine what would have happened if the wire transfer instructions were correct!
With that said - internally, there are usually lots, and lots and lots of controls over who/how one can send money, and it's pretty darn rare for someone to be able to "spoof" a request like this without throwing a lot of red flags.