Case Library / Phishing / Johnson County Schools $3.36M fake-Pearson vendor BEC
Phishing Confirmed

Johnson County Schools $3.36M fake-Pearson vendor BEC

A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a look-alike "pearson.quest" domain.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In March 2024, fraudsters impersonating a Pearson account representative emailed the Johnson County (TN) school district's finance director. Pearson was a real, standing vendor the district paid regularly, so the request looked routine. Over a month of email exchanges, the impostors said Pearson had "transitioned to a new merchant" and now required ACH or wire payment, and supplied fraudulent Wells Fargo banking details on a forged bank letterhead. On April 18, 2024, the finance director initiated two wires totaling $3,362,215.55 to an account titled "7 Oaks Training LLC," believing she was paying for online curriculum. The theft was discovered nearly two weeks later when a downstream bank flagged suspicious activity; by then the money had been dispersed across a web of mule accounts. The U.S. Secret Service traced the funds, and a federal civil-forfeiture complaint filed Sept. 5, 2024 in the Eastern District of Tennessee documented the scheme and named the alleged perpetrators. This is a real, court-documented incident.

How the Attack Worked

The core deception was a look-alike sender domain hidden behind a trusted display name. Earlier legitimate emails from the rep "Brian Leap" came from brian.leap@pearson.com; the fraudulent messages came from brian.leap@pearson.quest. Because the email client showed only the sender's name and hid the full address, the ".quest" domain went unnoticed. The attackers rode an existing vendor relationship (real contract, prior monthly payments), used a believable operational pretext (a "new merchant" requiring updated payment details), and reinforced legitimacy with a forged Wells Fargo bank letter. No account compromise or malware was needed; the manipulation was social. Once received, funds were rapidly layered through checks, online transfers, and multiple accounts held by money mules to frustrate recovery.

The Lure & the Tell

Lure: an email from a familiar-looking vendor contact ("Brian Leap" of Pearson) announcing a switch to a "new merchant" and asking to update payment to a supplied bank account. Tell: the sender's real address was brian.leap@pearson.quest, not pearson.com, a look-alike domain hidden behind the display name; plus an unsolicited change to banking/payment details, a classic BEC red flag that should have triggered out-of-band verification.

Outcome

Two wires totaling $3,362,215.55 left the district. Discovered ~two weeks later via a bank fraud alert. The Secret Service traced and moved to seize funds across several bank accounts; $742,000 was recovered and to be returned as of the Sept. 5, 2024 affidavit. John Crowson and Janet Browning were named in the federal civil-forfeiture filing on wire-fraud and money-laundering theories. The district said its cyber insurance through the Tennessee Risk Management Trust was assisting.

Why It Matters

This shows how a single hidden-domain trick can redirect millions from a small public agency with limited security staff. The attack exploited a legitimate vendor relationship and normal accounts-payable workflow rather than any technical vulnerability, and targeted public education funds. It underscores why any change to vendor banking details must be verified out-of-band, and why display-name-only email views are dangerous. BEC caused $2.9B in reported U.S. losses in 2023 per the FBI, and school districts are frequent targets.

Defenses

Verify any vendor banking-detail or payment-method change via a known, trusted phone number (never contact info from the request email). Enforce dual authorization and a callback step for wire transfers above a threshold. Configure email clients/gateways to display full sender addresses and flag external or newly-registered look-alike domains; deploy DMARC/DKIM/SPF and impersonation-detection filtering. Maintain a verified vendor payment-details record and reconcile against it. Train finance staff on vendor-impersonation BEC and the "new merchant / updated bank account" pretext. Report suspected fraud immediately to the bank and FBI IC3 to maximize the recovery/"kill chain" window.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: The Perpetrators likely identified Johnson County Schools as a target with a real, recurring Pearson vendor relationship, and learned the name of the actual Pearson account representative, Brian Leap, and the district's finance director, Tina Lipford, plausibly from prior legitimate correspondence, public school-board procurement records, or general OSINT on district staff and vendors.
Countering Stage 1: A district's identity as a standing Pearson customer and its staff names are hard to fully conceal, since procurement and vendor relationships are often part of the public record for a government entity; the realistic control is hardening the payment-verification process downstream rather than trying to hide this information.
2
Infrastructure setup: The Perpetrators registered the look-alike domain pearson.quest and set up an email account under Brian Leap's real name to impersonate the genuine brian.leap@pearson.com sender, relying on email clients that show only a display name and hide the full address.
Countering Stage 2: Configure email clients and gateways to always display full sender addresses rather than just the display name, and deploy DMARC/DKIM/SPF plus impersonation-detection filtering that flags look-alike or newly registered vendor domains such as pearson.quest.
3
Mule network setup: Consistent with the affidavit and reporting, the Perpetrators recruited money mules, several of whom said they were cultivated through online romance relationships, to open or provide bank accounts (including the Wells Fargo account titled 7 Oaks Training LLC) that could receive and quickly disperse the stolen funds.
Countering Stage 3: Mule recruitment through romance-scam grooming happens largely outside the victim organization's visibility; the nearest realistic control sits with banks' account-opening and anti-money-laundering scrutiny, and with public awareness campaigns warning people not to open accounts or move money on behalf of an online romantic partner.
4
Initial contact and pretext building: Beginning around March 18, 2024, the Perpetrators emailed Lipford from the pearson.quest address impersonating Leap, riding the existing vendor relationship and routine payment history to appear legitimate.
Countering Stage 4: Train finance and accounts-payable staff specifically on vendor-impersonation BEC, so an email that merely looks like it continues an existing relationship still gets scrutinized for sender-domain mismatches.
5
Payment-redirection pretext: Over the following weeks the Perpetrators told Lipford that Pearson had transitioned to a new merchant requiring ACH or wire payment, and supplied fraudulent Wells Fargo banking details on a forged bank letterhead to make the change look official.
Countering Stage 5: Treat any unsolicited change to a vendor's banking or payment details, especially a claimed new merchant, as a mandatory trigger for out-of-band verification by phone using a number already on file, never contact information supplied in the request itself; maintain a verified vendor payment-details record to check against.
6
Fraudulent wire execution: On April 18, 2024, based on the prior fraudulent emails, Lipford initiated two wire transfers totaling $3,362,215.55 through Farmers State Bank to the Wells Fargo account held in the name 7 Oaks Training LLC, completing the payment redirection.
Countering Stage 6: Enforce dual authorization and a callback verification step for wire transfers above a set threshold before funds are released, so a single employee's decision cannot move millions unchecked.
7
Layering and cash-out: Once received, the funds were rapidly moved through checks, online transfers, and multiple mule-held accounts to frustrate tracing, achieving the Perpetrators' objective of converting the stolen wire into dispersed, harder-to-recover cash before the fraud was discovered roughly two weeks later.
Countering Stage 7: Report suspected fraud immediately to the originating bank and FBI IC3 to trigger the interbank recall and asset-freeze process while funds can still be traced, as happened here through the Secret Service investigation and civil forfeiture, which recovered $742,000 of the total.
Quick Facts
Victim
Johnson County Board of Education (Johnson County Schools), a rural district of ~4,500 students based in Mountain City, Tennessee; finance director Tina Lipford initiated the wires.
Location
Johnson County (Mountain City), Tennessee, USA
Date
2024-03-18 to 2024-04-18 (attack); federal civil-forfeiture complaint filed 2024-09-05
Impact
$3,362,215.55 fraudulently wired in two transfers ($2,000,000 and $1,362,215.55); $742,000 recovered as of the Sept. 5, 2024 affidavit; drawn from Tennessee Investment in Student Achievement (TISA) state education funds.
Status
Confirmed
Case Type
Real-World Incident
Sector
Education, Government & Public Sector
Threat Actor
Unaffiliated Individual
Related

Related Cases

RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud

A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into…

Incident 2024Read →

Orion S.A. $60M fraudulently induced wire transfers (2024)

A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M…

Incident 2024Read →

School District of Philadelphia $700K Vendor-ACH Diversion BEC (2024)

Impersonators posing as two School District of Philadelphia vendors switched payments from paper check to ACH and diverted nearly $700,000…

Incident 2024Read →