Proof Asset

$700K wire-fraud recovery: the evidence that proved what happened.

An anonymized financial-services incident story showing why control evidence matters after a breach: when credentials were captured and client funds were wired out, FCI helped establish the facts, support the FBI investigation, and recover the money.

By Brian Edelman, Founder & CEO, FCI Cyber · Case study summary · August 2026

The short version

After an incident, the question becomes evidence.

A financial-services firm faced a $700,000 wire-fraud incident after credentials were captured. The urgent problem was not only containment. It was proving what actually happened, what controls were in place, and whether the firm itself was responsible. FCI’s forensic and evidence work helped establish the incident path and support recovery for the rightful client.

Incident

Credential compromise

A phishing site captured credentials after an IT-provider change weakened authentication during upgrade work.

Exposure

$700K wired out

Client funds were transferred, creating immediate investigative, regulatory, insurance, and reputational risk.

Outcome

Funds recovered

FCI helped identify the breach path, preserve the technical record, support the FBI, and recover the funds.

Incident timeline

What happened, and why proof mattered.

The client and identifying details are anonymized. The operational lesson is not: after a cyber incident, firms must be able to show what happened, when it happened, what controls were operating, and what evidence supports the response.

1. A control was weakened
Authentication was changed for operational convenience.

An IT provider turned off multi-factor authentication to simplify upgrade scripts. That temporary operating choice created a security gap at exactly the point where a financial-services firm needed verifiable protection.

Evidence lesson: control exceptions need ownership, approval, expiration, and monitoring. If MFA is disabled, the firm needs a record of who approved it, why, for how long, and what compensating controls were active.
2. Credentials were captured
A phishing site turned the control gap into an incident.

With authentication weakened, a phishing site captured credentials. The attacker used that access path to initiate a wire transfer from a client account.

Evidence lesson: identity logs, endpoint telemetry, email/security alerts, and access records need to be preserved immediately. The firm cannot reconstruct a reliable incident record after systems are wiped, overwritten, or manually patched without documentation.
3. The firm needed to prove the facts
The investigation initially put pressure on the firm.

When FCI became involved, the FBI’s attention included the advisory firm itself. Without a clear technical record, the firm could not simply assert what happened. It needed evidence that showed the breach path, the control state, and the difference between firm action and attacker action.

Evidence lesson: incident response is not just technical cleanup. It is evidence production for investigators, regulators, insurers, executives, and clients.
4. FCI established the incident path
Forensics, control records, and communication had to move together.

FCI identified the breach, documented what had actually happened, preserved the relevant technical record, and worked alongside the FBI. The goal was not only to contain the incident, but to give the investigation a defensible account of the event.

Evidence lesson: the strongest response record connects containment, remediation, identity/access logs, endpoint state, vendor actions, timeline, and third-party communication in one coherent package.
5. The funds were recovered
The evidence helped support recovery for the rightful client.

Working with the FBI, FCI helped recover the $700,000 for the rightful client. The result illustrates the difference between a provider that only monitors alerts and a response partner that can stand with the firm when the questions become technical, financial, and evidentiary.

Evidence lesson: after a breach, the firm needs a technical voice that can explain the facts to investigators, regulators, cyber insurers, and leadership.

What this means for your firm

Four records to have before the incident.

The worst time to build the evidence trail is after funds move, systems are changing, and outside parties are asking for answers. These records should exist before the event.

Control exception record

Who changed a control, why it changed, who approved it, when it expires, and what compensating controls are active.

Identity and endpoint record

MFA state, access logs, device status, endpoint protection, timestamps, and remediation actions preserved in one incident timeline.

Vendor action record

Which provider changed what, which systems were touched, and how vendor decisions affected the firm’s control posture.

Investigation and communication record

Containment steps, forensic findings, notification decisions, regulator/insurer communications, and FBI or law-enforcement coordination.

Would your evidence stand up after an incident?

Start with the 16-question assessment, or ask FCI to review whether your firm could produce the control, incident, vendor, and insurance evidence this kind of event requires.