The South Carolina Town in Turmoil Over a $545,000 Email Phishing Scam:
The South Carolina Town in Turmoil Over a $545,000 Email Phishing Scam:
According to the article:
- The victim: Surfside Beach, a town of about 4,300 residents.
- The amount stolen: $545,598.30 intended for Wildcat Contractors for utility work.
- How the attack worked: A cybercriminal inserted themselves into a legitimate email conversation about an invoice. They created look-alike domains (for example, replacing the lowercase "l" in "Wildcat" with an uppercase "I" to create wiidcatcontractors.com) and submitted fraudulent ACH payment instructions. The town then wired the payment to a bank account in Utah controlled by the scammers.
- Why it wasn't caught: The fraud wasn't discovered for approximately 45 days. According to the FBI, the chances of recovering stolen funds drop dramatically when these incidents aren't reported within 72 hours.
- The aftermath: The contractor says it still hasn't been paid, the town argues it followed its procedures, law enforcement and insurers are investigating, and the incident has become a major source of controversy among residents.
The most important takeaway isn't the amount of dollar.
It's that this wasn't a sophisticated hack. It was a Business Email Compromise (BEC) attack, one of the FBI's most financially damaging cybercrimes. The attacker didn't need ransomware or malware. They simply waited for a legitimate payment conversation, impersonated a trusted contact, changed the payment instructions, and exploited human trust.
For my audience of business owners, this story reinforces one critical message:
Never change payment instructions based solely on an email. Always verify changes by calling a known, trusted phone number before sending funds.
Images
Powered By GrowthZone