Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district; the FBI and U.S. Attorney's Office later seized about $4.86M.
Reviewed by the Social Engineering Examples team.
Dickinson Public Schools, a K-12 district in southwestern North Dakota, disclosed on February 10, 2026 that it had been defrauded of roughly $4.92 million through what it described as a "sophisticated email fraud scheme." According to the district's public statement and coordinated Dickinson Police release, criminals impersonated a trusted district vendor and redirected two scheduled vendor payments to a fraudulent account. The money came from the district's Building Fund, a restricted fund earmarked for facility and construction projects, including a high school expansion; the district stressed classroom budgets, operations, and the construction project were not affected, and that there was no evidence student or staff personal data was accessed. Dickinson Police said the scope of the case exceeded local jurisdictional capabilities and enlisted the FBI and the U.S. Attorney's Office / DOJ. On April 30, 2026, U.S. Attorney Nicholas W. Chase announced that approximately $4,856,578.51 had been traced to a Citibank account and seized via a civil forfeiture warrant (civil case 1:26-cv-008); Citibank turned the funds over to the U.S. Marshals Service. As of that announcement the money remained in federal custody pending a final order of disposition, with no arrests announced. The district itself labeled the incident a business email compromise (BEC) involving vendor impersonation.
This was a vendor-impersonation business email compromise. Rather than breaking through technical defenses, the attackers exploited an existing, trusted payment relationship: they posed as a known vendor and used email to request that scheduled payments be routed to attacker-controlled banking details. Because the payments were expected and the "vendor" was familiar, the redirected transfers looked like routine business. Two payments were sent before the fraud was detected. Officials involved in the case emphasized the classic BEC playbook of "time and distance": using email anonymity to impersonate a legitimate counterparty and applying pressure so staff act on payment or wiring changes without independently verifying them through a separate, known channel.
Lure: an email appearing to come from a trusted, established vendor requesting a change to payment or banking details for expected invoices/payments. Tells: any unsolicited request to change payment methods, alter wiring/bank instructions, or provide company/payment information; subtle irregularities in the sender's email address versus the person previously worked with; and pressure to act quickly. The reliable defense cited by prosecutors is to stop and confirm any payment-detail change via an independently sourced phone number to the vendor, supervisor, or banker before acting.
Two payments totaling $4.92M were successfully redirected before detection. The district notified financial institutions and cooperated with law enforcement. On April 30, 2026, federal authorities announced they had traced and seized about $4.86M (held by the U.S. Marshals Service pending a final court order for return to the district). The remainder of the initial $4.92M loss was not clearly accounted for in the recovery announcement, and no suspects had been arrested; the criminal investigation remained ongoing. The district implemented enhanced vendor-verification procedures, strengthened email security protocols, and staff cybersecurity/fraud training.
Public institutions like school districts are increasingly targeted by BEC because they run predictable, high-value vendor and construction payments with limited fraud-detection staffing. The case shows how a purely social attack, impersonating a trusted vendor over email, can extract millions without any malware or account breach, and that even large losses can sometimes be partially recovered if reported fast enough for law enforcement to trace and freeze the funds. It also underscores that recovery is uncertain and slow: seized funds sat in federal custody with no guaranteed timeline for return.
Verify any change to vendor payment or banking details out-of-band using a phone number already on file (never a number or contact from the request email). Require dual approval and a callback step for changes to wiring instructions or payee bank accounts. Treat urgency around payment changes as a red flag. Train finance and accounts-payable staff specifically on vendor-impersonation BEC. Inspect sender addresses for subtle spoofing/lookalike domains. Report suspected BEC immediately to the bank and to the FBI (IC3); rapid reporting materially improves the odds of freezing and recovering funds.
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…
A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…