Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County.
Social Engineering Examples·7 sources
Beginning November 27, 2018, criminals posing as representatives of Branch and Associates, Inc., the general contractor building West Cabarrus High School, emailed Cabarrus County Schools and county government staff requesting a change to the vendor's banking details for future payments. Following its normal process, the county had the "vendor" complete an EFT change form and submit supporting documentation on what appeared to be bank letterhead, along with signed approvals, submitted December 4, 2018. Seeing nothing suspicious, the county updated the vendor's banking record.
On December 21, 2018 it electronically transferred the next scheduled vendor payment of $2,504,601 into the fraudulent account, which cleared in December. The scammers immediately moved the funds through multiple accounts. The fraud was discovered on January 8, 2019 when a genuine Branch and Associates representative contacted the county about a missed payment.
The county notified its bank (SunTrust) and the receiving bank (Bank of America), which froze $776,518.40; the remaining $1,728,082.60 was never recovered. County Manager Mike Downs emphasized the county was "not hacked": it was a spoofed-identity social-engineering fraud. The incident is documented in the county's own public announcement and corroborated across AP, the Charlotte Observer, and multiple security-industry reports.
This is a classic vendor email compromise / bank-account-change BEC. The attackers exploited a legitimate, routine business process, since vendors do periodically update banking details, and impersonated a real, expected contractor whose relationship with the county was publicly known (a high-profile school construction project). Rather than hacking systems, they supplied convincing forged artifacts: an EFT form, documentation on apparent bank letterhead, and signed approvals, which satisfied the county's paper-based verification.
Crucially, the county verified the paperwork but did not independently confirm the change with a known-good phone contact at the real vendor (out-of-band verification). The attackers then simply waited for the next large scheduled payment, letting the county's own payment cycle move the money, which delayed detection until the real vendor complained weeks later.
Lure: an email from a trusted, expected contractor asking to update the account for future payments, backed by an EFT form, bank-letterhead documentation, and signed approvals that looked routine and valid. Tells: a banking-change request arriving by email; documents that "look right" but were never confirmed with the vendor via a phone number obtained independently (not from the email); and a large payment following a recent detail change.
The decisive missed control was out-of-band callback verification to a known vendor contact.
Net loss of $1,728,082.60. The county paid Branch and Associates the recovered $776,518.40 (March 20, 2019) and the remaining balance (May 22, 2019) so construction continued uninterrupted, then restored the capital project with a ~$1,653,082.60 transfer from its emergency/Assigned Fund Balance (approved July 29, 2019). Insurance reimbursed only $75,000. The Sheriff's Office and FBI investigated; no public arrests or recovery of the missing funds were reported.
The county halted EFT payments pending re-validation, redesigned its accounts-payable/vendor onboarding process with an outside consultant (Debra Richardson), and adopted a new authentication process with added external verification checks.
A well-run local government following its documented procedures still lost over $1.7M, showing that paper-based, in-band verification of banking changes is not enough against a determined impersonator with forged documents. Public-sector organizations are attractive BEC targets because their vendors, large contracts, and payment schedules are often public record.
The case is a widely cited teaching example precisely because the victim published a detailed, transparent post-mortem, underscoring that the single highest-value control is mandatory out-of-band callback verification to a pre-established vendor contact before any payment detail is changed.
Require out-of-band verification (call a known, pre-verified vendor number, never one from the request) before changing any vendor banking detail. Treat all banking-change requests as high-risk regardless of attached documentation, since letterhead and signatures are easily forged. Enforce dual authorization and a mandatory hold/cooling-off before the first payment to newly changed account details.
Maintain a verified vendor master with change-control and confirm changes with a second, independent vendor contact. Use vendor-verification/validation tooling and bank-account confirmation services. Train AP staff that "the paperwork looks right" is not verification. Enable large-transfer alerts and rapid bank/law-enforcement notification (FBI IC3 and financial-fraud kill-chain) to maximize recovery odds within the first hours.
Social Engineering Examples. “Cabarrus County $1.7M vendor-impersonation BEC (2019)”. Accessed 19 September 2026. https://socialengineeringexamples.com/cabarrus-county-vendor-bec-2019
Cabarrus County's vendor relationship with Branch and Associates on the West Cabarrus High School construction project was a matter of public record, likely visible through public procurement/contract postings, county commission agendas, and local news coverage of the school project, consistent with the pattern security reporting on this case notes: government projects and their contractors are public information that is readily available to would-be impersonators.
Public disclosure of government contracts and vendor relationships is generally a legal transparency requirement and cannot practically be hidden; the realistic control assumes attackers already know which vendors are due large payments and instead hardens the verification step further down the chain (see Stage 4), rather than trying to suppress public procurement information.
Before making contact, the conspirators likely prepared the fraud artifacts they would later submit, an EFT bank-change form, documentation styled to resemble the vendor's bank letterhead, and forged signed approvals, tradecraft typical of vendor-impersonation BEC as described in FBI IC3 reporting on this fraud category.
Forged letterhead and signed approvals are inexpensive to produce and hard to catch by visual review; the practical control is to treat any banking-change request as high risk regardless of how convincing the attached documentation looks, and to route it to a dedicated vendor-verification or bank-account confirmation service rather than relying on manual document review.
Posing as representatives of Branch and Associates, the conspirators emailed Cabarrus County Schools and county government staff requesting a change to the vendor's bank account for future payments, opening a multi-day email correspondence with county staff.
Train accounts-payable and school-district staff to flag any inbound email requesting a change to vendor banking details as inherently high risk, and require it to be logged and escalated through a defined fraud-review path before any further processing, regardless of how legitimate the sender appears.
Process exploitation via forged documentation (November 27 to December 4, 2018): County employees followed their normal process and asked for a signed EFT change form and supporting bank documentation; the conspirators supplied the completed form and letterhead-style documentation on December 4, 2018, satisfying the county's paper-based, in-band checks because no one called Branch and Associates through an independently obtained phone number to confirm the change.
Mandatory out-of-band callback verification (calling a known, pre-verified vendor phone number obtained independently of the request) plus dual authorization from a second AP staff member would have caught the impersonation at the one point the conspirators could not fake: a live conversation with the real vendor contact. This is the single highest-value control in the whole chain.
Rather than requesting an urgent transfer, the conspirators let the county's routine payment cycle run its course; the county submitted the regularly scheduled $2,504,601 vendor payment via EFT on December 21, 2018, a patient approach that avoided the urgency cues that often trigger scrutiny.
A mandatory hold or cooling-off period before the first payment to a newly changed vendor bank account, such as several business days plus a required second confirmation, would deny attackers the scheduled-payment window this scheme relied on.
Once the payment cleared, the scammers immediately diverted the funds through multiple accounts, a standard money-laundering layering technique intended to disperse the money before the fraud could be noticed and a freeze requested.
Large-transfer monitoring and near-real-time fraud alerts on the sending bank's side, paired with a rapid-notification relationship to the receiving bank, are the main lever for interrupting fund layering before money fully disperses across accounts.
The scheme was caught only when the genuine Branch and Associates representative inquired about a missing payment on January 8, 2019, roughly three weeks after the transfer; by then Bank of America could freeze and return only $776,518.40 of the $2,504,601, leaving $1,728,082.60 permanently lost and the conspirators' objective of extracting untraceable funds largely achieved.
Once funds clear the initial window and are laundered through multiple accounts, recovery odds fall sharply and there is no reliable control left at this stage; the realistic fix lies upstream, at Stage 6's rapid notification and especially Stage 4's callback verification, since money that has already moved is rarely fully recoverable.
Browse by what this case has in common with others in the library.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
Hours before Maharashtra's 2024 assembly election polling, BJP-amplified audio clips purporting to catch opposition leaders Supriya Sule and Nana Patole.
A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…
A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled…
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain.
Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread.
A compromised Constant Contact account let Russia-linked Nobelium send USAID-spoofed phishing emails to 150-350 government and NGO organizations.
CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters.
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.