Proof Asset
$700K wire-fraud recovery: the evidence that proved what happened.
An anonymized financial-services incident story showing why control evidence matters after a breach: when credentials were captured and client funds were wired out, FCI helped establish the facts, support the FBI investigation, and recover the money.
By Brian Edelman, Founder & CEO, FCI Cyber · Case study summary · August 2026
The short version
After an incident, the question becomes evidence.
A financial-services firm faced a $700,000 wire-fraud incident after credentials were captured. The urgent problem was not only containment. It was proving what actually happened, what controls were in place, and whether the firm itself was responsible. FCI’s forensic and evidence work helped establish the incident path and support recovery for the rightful client.
Incident
Credential compromise
A phishing site captured credentials after an IT-provider change weakened authentication during upgrade work.
Exposure
$700K wired out
Client funds were transferred, creating immediate investigative, regulatory, insurance, and reputational risk.
Outcome
Funds recovered
FCI helped identify the breach path, preserve the technical record, support the FBI, and recover the funds.
Incident timeline
What happened, and why proof mattered.
The client and identifying details are anonymized. The operational lesson is not: after a cyber incident, firms must be able to show what happened, when it happened, what controls were operating, and what evidence supports the response.
An IT provider turned off multi-factor authentication to simplify upgrade scripts. That temporary operating choice created a security gap at exactly the point where a financial-services firm needed verifiable protection.
With authentication weakened, a phishing site captured credentials. The attacker used that access path to initiate a wire transfer from a client account.
When FCI became involved, the FBI’s attention included the advisory firm itself. Without a clear technical record, the firm could not simply assert what happened. It needed evidence that showed the breach path, the control state, and the difference between firm action and attacker action.
FCI identified the breach, documented what had actually happened, preserved the relevant technical record, and worked alongside the FBI. The goal was not only to contain the incident, but to give the investigation a defensible account of the event.
Working with the FBI, FCI helped recover the $700,000 for the rightful client. The result illustrates the difference between a provider that only monitors alerts and a response partner that can stand with the firm when the questions become technical, financial, and evidentiary.
What this means for your firm
Four records to have before the incident.
The worst time to build the evidence trail is after funds move, systems are changing, and outside parties are asking for answers. These records should exist before the event.
Control exception record
Who changed a control, why it changed, who approved it, when it expires, and what compensating controls are active.
Identity and endpoint record
MFA state, access logs, device status, endpoint protection, timestamps, and remediation actions preserved in one incident timeline.
Vendor action record
Which provider changed what, which systems were touched, and how vendor decisions affected the firm’s control posture.
Investigation and communication record
Containment steps, forensic findings, notification decisions, regulator/insurer communications, and FBI or law-enforcement coordination.
Would your evidence stand up after an incident?
Start with the 16-question assessment, or ask FCI to review whether your firm could produce the control, incident, vendor, and insurance evidence this kind of event requires.