Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County, NC wired $2.5M to the fraud account, losing $1.73M net.
Reviewed by the Social Engineering Examples team.
Beginning November 27, 2018, criminals posing as representatives of Branch and Associates, Inc., the general contractor building West Cabarrus High School, emailed Cabarrus County Schools and county government staff requesting a change to the vendor's banking details for future payments. Following its normal process, the county had the "vendor" complete an EFT change form and submit supporting documentation on what appeared to be bank letterhead, along with signed approvals, submitted December 4, 2018. Seeing nothing suspicious, the county updated the vendor's banking record. On December 21, 2018 it electronically transferred the next scheduled vendor payment of $2,504,601 into the fraudulent account, which cleared in December. The scammers immediately moved the funds through multiple accounts. The fraud was discovered on January 8, 2019 when a genuine Branch and Associates representative contacted the county about a missed payment. The county notified its bank (SunTrust) and the receiving bank (Bank of America), which froze $776,518.40; the remaining $1,728,082.60 was never recovered. County Manager Mike Downs emphasized the county was "not hacked": it was a spoofed-identity social-engineering fraud. The incident is documented in the county's own public announcement and corroborated across AP, the Charlotte Observer, and multiple security-industry reports.
This is a classic vendor email compromise / bank-account-change BEC. The attackers exploited a legitimate, routine business process, since vendors do periodically update banking details, and impersonated a real, expected contractor whose relationship with the county was publicly known (a high-profile school construction project). Rather than hacking systems, they supplied convincing forged artifacts: an EFT form, documentation on apparent bank letterhead, and signed approvals, which satisfied the county's paper-based verification. Crucially, the county verified the paperwork but did not independently confirm the change with a known-good phone contact at the real vendor (out-of-band verification). The attackers then simply waited for the next large scheduled payment, letting the county's own payment cycle move the money, which delayed detection until the real vendor complained weeks later.
Lure: an email from a trusted, expected contractor asking to update the account for future payments, backed by an EFT form, bank-letterhead documentation, and signed approvals that looked routine and valid. Tells: a banking-change request arriving by email; documents that "look right" but were never confirmed with the vendor via a phone number obtained independently (not from the email); and a large payment following a recent detail change. The decisive missed control was out-of-band callback verification to a known vendor contact.
Net loss of $1,728,082.60. The county paid Branch and Associates the recovered $776,518.40 (March 20, 2019) and the remaining balance (May 22, 2019) so construction continued uninterrupted, then restored the capital project with a ~$1,653,082.60 transfer from its emergency/Assigned Fund Balance (approved July 29, 2019). Insurance reimbursed only $75,000. The Sheriff's Office and FBI investigated; no public arrests or recovery of the missing funds were reported. The county halted EFT payments pending re-validation, redesigned its accounts-payable/vendor onboarding process with an outside consultant (Debra Richardson), and adopted a new authentication process with added external verification checks.
A well-run local government following its documented procedures still lost over $1.7M, showing that paper-based, in-band verification of banking changes is not enough against a determined impersonator with forged documents. Public-sector organizations are attractive BEC targets because their vendors, large contracts, and payment schedules are often public record. The case is a widely cited teaching example precisely because the victim published a detailed, transparent post-mortem, underscoring that the single highest-value control is mandatory out-of-band callback verification to a pre-established vendor contact before any payment detail is changed.
Require out-of-band verification (call a known, pre-verified vendor number, never one from the request) before changing any vendor banking detail. Treat all banking-change requests as high-risk regardless of attached documentation, since letterhead and signatures are easily forged. Enforce dual authorization and a mandatory hold/cooling-off before the first payment to newly changed account details. Maintain a verified vendor master with change-control and confirm changes with a second, independent vendor contact. Use vendor-verification/validation tooling and bank-account confirmation services. Train AP staff that "the paperwork looks right" is not verification. Enable large-transfer alerts and rapid bank/law-enforcement notification (FBI IC3 and financial-fraud kill-chain) to maximize recovery odds within the first hours.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition,…