A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a look-alike "pearson.quest" domain.
Reviewed by the Social Engineering Examples team.
In March 2024, fraudsters impersonating a Pearson account representative emailed the Johnson County (TN) school district's finance director. Pearson was a real, standing vendor the district paid regularly, so the request looked routine. Over a month of email exchanges, the impostors said Pearson had "transitioned to a new merchant" and now required ACH or wire payment, and supplied fraudulent Wells Fargo banking details on a forged bank letterhead. On April 18, 2024, the finance director initiated two wires totaling $3,362,215.55 to an account titled "7 Oaks Training LLC," believing she was paying for online curriculum. The theft was discovered nearly two weeks later when a downstream bank flagged suspicious activity; by then the money had been dispersed across a web of mule accounts. The U.S. Secret Service traced the funds, and a federal civil-forfeiture complaint filed Sept. 5, 2024 in the Eastern District of Tennessee documented the scheme and named the alleged perpetrators. This is a real, court-documented incident.
The core deception was a look-alike sender domain hidden behind a trusted display name. Earlier legitimate emails from the rep "Brian Leap" came from brian.leap@pearson.com; the fraudulent messages came from brian.leap@pearson.quest. Because the email client showed only the sender's name and hid the full address, the ".quest" domain went unnoticed. The attackers rode an existing vendor relationship (real contract, prior monthly payments), used a believable operational pretext (a "new merchant" requiring updated payment details), and reinforced legitimacy with a forged Wells Fargo bank letter. No account compromise or malware was needed; the manipulation was social. Once received, funds were rapidly layered through checks, online transfers, and multiple accounts held by money mules to frustrate recovery.
Lure: an email from a familiar-looking vendor contact ("Brian Leap" of Pearson) announcing a switch to a "new merchant" and asking to update payment to a supplied bank account. Tell: the sender's real address was brian.leap@pearson.quest, not pearson.com, a look-alike domain hidden behind the display name; plus an unsolicited change to banking/payment details, a classic BEC red flag that should have triggered out-of-band verification.
Two wires totaling $3,362,215.55 left the district. Discovered ~two weeks later via a bank fraud alert. The Secret Service traced and moved to seize funds across several bank accounts; $742,000 was recovered and to be returned as of the Sept. 5, 2024 affidavit. John Crowson and Janet Browning were named in the federal civil-forfeiture filing on wire-fraud and money-laundering theories. The district said its cyber insurance through the Tennessee Risk Management Trust was assisting.
This shows how a single hidden-domain trick can redirect millions from a small public agency with limited security staff. The attack exploited a legitimate vendor relationship and normal accounts-payable workflow rather than any technical vulnerability, and targeted public education funds. It underscores why any change to vendor banking details must be verified out-of-band, and why display-name-only email views are dangerous. BEC caused $2.9B in reported U.S. losses in 2023 per the FBI, and school districts are frequent targets.
Verify any vendor banking-detail or payment-method change via a known, trusted phone number (never contact info from the request email). Enforce dual authorization and a callback step for wire transfers above a threshold. Configure email clients/gateways to display full sender addresses and flag external or newly-registered look-alike domains; deploy DMARC/DKIM/SPF and impersonation-detection filtering. Maintain a verified vendor payment-details record and reconcile against it. Train finance staff on vendor-impersonation BEC and the "new merchant / updated bank account" pretext. Report suspected fraud immediately to the bank and FBI IC3 to maximize the recovery/"kill chain" window.
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into…
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M…
Impersonators posing as two School District of Philadelphia vendors switched payments from paper check to ACH and diverted nearly $700,000…