A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a look-alike.
Social Engineering Examples·3 sources
In March 2024, fraudsters impersonating a Pearson account representative emailed the Johnson County (TN) school district's finance director. Pearson was a real, standing vendor the district paid regularly, so the request looked routine. Over a month of email exchanges, the impostors said Pearson had "transitioned to a new merchant" and now required ACH or wire payment, and supplied fraudulent Wells Fargo banking details on a forged bank letterhead.
On April 18, 2024, the finance director initiated two wires totaling $3,362,215.55 to an account titled "7 Oaks Training LLC," believing she was paying for online curriculum. The theft was discovered nearly two weeks later when a downstream bank flagged suspicious activity; by then the money had been dispersed across a web of mule accounts. The U.S. Secret Service traced the funds, and a federal civil-forfeiture complaint filed Sept. 5, 2024 in the Eastern District of Tennessee documented the scheme and named the alleged perpetrators.
This is a real, court-documented incident.
The core deception was a look-alike sender domain hidden behind a trusted display name. Earlier legitimate emails from the rep "Brian Leap" came from brian.leap@pearson.com; the fraudulent messages came from brian.leap@pearson.quest. Because the email client showed only the sender's name and hid the full address, the ".quest" domain went unnoticed. The attackers rode an existing vendor relationship (real contract, prior monthly payments), used a believable operational pretext (a "new merchant" requiring updated payment details), and reinforced legitimacy with a forged Wells Fargo bank letter.
No account compromise or malware was needed; the manipulation was social. Once received, funds were rapidly layered through checks, online transfers, and multiple accounts held by money mules to frustrate recovery.
Lure: an email from a familiar-looking vendor contact ("Brian Leap" of Pearson) announcing a switch to a "new merchant" and asking to update payment to a supplied bank account. Tell: the sender's real address was brian.leap@pearson.quest, not pearson.com, a look-alike domain hidden behind the display name; plus an unsolicited change to banking/payment details, a classic BEC red flag that should have triggered out-of-band verification.
Two wires totaling $3,362,215.55 left the district. Discovered ~two weeks later via a bank fraud alert. The Secret Service traced and moved to seize funds across several bank accounts; $742,000 was recovered and to be returned as of the Sept. 5, 2024 affidavit. John Crowson and Janet Browning were named in the federal civil-forfeiture filing on wire-fraud and money-laundering theories. The district said its cyber insurance through the Tennessee Risk Management Trust was assisting.
This shows how a single hidden-domain trick can redirect millions from a small public agency with limited security staff. The attack exploited a legitimate vendor relationship and normal accounts-payable workflow rather than any technical vulnerability, and targeted public education funds. It underscores why any change to vendor banking details must be verified out-of-band, and why display-name-only email views are dangerous.
BEC caused $2.9B in reported U.S. losses in 2023 per the FBI, and school districts are frequent targets.
Verify any vendor banking-detail or payment-method change via a known, trusted phone number (never contact info from the request email). Enforce dual authorization and a callback step for wire transfers above a threshold. Configure email clients/gateways to display full sender addresses and flag external or newly-registered look-alike domains; deploy DMARC/DKIM/SPF and impersonation-detection filtering.
Maintain a verified vendor payment-details record and reconcile against it. Train finance staff on vendor-impersonation BEC and the "new merchant / updated bank account" pretext. Report suspected fraud immediately to the bank and FBI IC3 to maximize the recovery/"kill chain" window.
Social Engineering Examples. “Johnson County Schools $3.36M fake-Pearson vendor BEC”. Accessed 19 September 2026. https://socialengineeringexamples.com/johnson-county-schools-pearson-vendor-bec-2024
The Perpetrators likely identified Johnson County Schools as a target with a real, recurring Pearson vendor relationship, and learned the name of the actual Pearson account representative, Brian Leap, and the district's finance director, Tina Lipford, plausibly from prior legitimate correspondence, public school-board procurement records, or general OSINT on district staff and vendors.
A district's identity as a standing Pearson customer and its staff names are hard to fully conceal, since procurement and vendor relationships are often part of the public record for a government entity; the realistic control is hardening the payment-verification process downstream rather than trying to hide this information.
The Perpetrators registered the look-alike domain pearson.quest and set up an email account under Brian Leap's real name to impersonate the genuine brian.leap@pearson.com sender, relying on email clients that show only a display name and hide the full address.
Configure email clients and gateways to always display full sender addresses rather than just the display name, and deploy DMARC/DKIM/SPF plus impersonation-detection filtering that flags look-alike or newly registered vendor domains such as pearson.quest.
Consistent with the affidavit and reporting, the Perpetrators recruited money mules, several of whom said they were cultivated through online romance relationships, to open or provide bank accounts (including the Wells Fargo account titled 7 Oaks Training LLC) that could receive and quickly disperse the stolen funds.
Mule recruitment through romance-scam grooming happens largely outside the victim organization's visibility; the nearest realistic control sits with banks' account-opening and anti-money-laundering scrutiny, and with public awareness campaigns warning people not to open accounts or move money on behalf of an online romantic partner.
Beginning around March 18, 2024, the Perpetrators emailed Lipford from the pearson.quest address impersonating Leap, riding the existing vendor relationship and routine payment history to appear legitimate.
Train finance and accounts-payable staff specifically on vendor-impersonation BEC, so an email that merely looks like it continues an existing relationship still gets scrutinized for sender-domain mismatches.
Over the following weeks the Perpetrators told Lipford that Pearson had transitioned to a new merchant requiring ACH or wire payment, and supplied fraudulent Wells Fargo banking details on a forged bank letterhead to make the change look official.
Treat any unsolicited change to a vendor's banking or payment details, especially a claimed new merchant, as a mandatory trigger for out-of-band verification by phone using a number already on file, never contact information supplied in the request itself; maintain a verified vendor payment-details record to check against.
On April 18, 2024, based on the prior fraudulent emails, Lipford initiated two wire transfers totaling $3,362,215.55 through Farmers State Bank to the Wells Fargo account held in the name 7 Oaks Training LLC, completing the payment redirection.
Enforce dual authorization and a callback verification step for wire transfers above a set threshold before funds are released, so a single employee's decision cannot move millions unchecked.
Once received, the funds were rapidly moved through checks, online transfers, and multiple mule-held accounts to frustrate tracing, achieving the Perpetrators' objective of converting the stolen wire into dispersed, harder-to-recover cash before the fraud was discovered roughly two weeks later.
Report suspected fraud immediately to the originating bank and FBI IC3 to trigger the interbank recall and asset-freeze process while funds can still be traced, as happened here through the Secret Service investigation and civil forfeiture, which recovered $742,000 of the total.
Browse by what this case has in common with others in the library.
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
Impersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled…
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal.
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…