Case Library / Phishing / New Haven Public Schools $6M COO-email vendor thread-hijack BEC
Phishing Confirmed

New Haven Public Schools $6M COO-email vendor thread-hijack BEC

Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread, spoofed the vendor to swap in their own bank account, and diverted about $6M in city funds.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In late May 2023, attackers gained access to the email account of New Haven Public Schools Chief Operating Officer Thomas Lamb. For roughly a month they silently monitored ongoing correspondence between the COO, vendors, and the city budget office. In June, focusing on a real, outstanding ~$5.9M payment owed to school bus contractor First Student, they registered a look-alike email domain impersonating the bus company, used the compromised COO account to run test messages, and then posed as the vendor to get the payment/beneficiary details changed to accounts they controlled. New Haven's finance office processed six fraudulent electronic transfers (four to a fake First Student account totaling ~$5.9M, two to a fake law-firm account totaling ~$76K). A seventh attempt in early July impersonating cleaning vendor S.J. Services was denied. The fraud surfaced on June 23 when the real First Student asked why it had not been paid. The city stopped electronic transfers and notified New Haven police, the FBI, and the U.S. Attorney's Office. Officials stayed publicly quiet until August 10, 2023 at the FBI's request. About $3.6M was quickly clawed back through JPMorgan Chase's ACH hold-harmless process, and in November 2023 the U.S. Attorney for Connecticut filed a civil forfeiture complaint over an additional ~$1.187M traced to TD Bank accounts (some funds had been shuttled through cashier's checks and into a crypto exchange). This is documented in local and national press and in U.S. Department of Justice / U.S. Attorney (District of Connecticut) releases, making it a confirmed, real incident.

How the Attack Worked

This was a vendor thread-hijack business email compromise (BEC). Because the attackers were inside a legitimate executive mailbox, they saw the exact real invoice, amount, timing, and personalities of an in-flight transaction, so their impersonation required no invented pretext. They exploited the trust of an existing vendor relationship and the routine nature of a budget-approved payment: the COO had authority to authorize transfers already approved in the budget, so requests appeared normal. By registering a near-identical look-alike domain for the bus company, they controlled both sides of the conversation and could authoritatively request that the vendor's banking/beneficiary details be updated just before payment, redirecting funds to mule accounts. The lack of an out-of-band verification step for changing vendor payment information is what let the swapped account details flow straight through to disbursement.

The Lure & the Tell

Lure: emails that appeared to come from the trusted district COO and the district's own bus contractor, referencing a genuine outstanding invoice, asking to update the vendor's payment/bank details before an imminent large payment. Tells: a subtly different look-alike sender domain impersonating the vendor, a mid-transaction request to change established banking details, and pressure tied to a real deadline. The decisive missed check was that no one verified the new payment instructions with the vendor through a known, independent channel (a phone call to First Student would have exposed the swap).

Outcome

Roughly $6M was diverted. About $3.6M was recovered through bank ACH recall, and federal authorities seized/forfeited an additional ~$1.187M, bringing expected recovery to about $4.7M-4.8M, with roughly $1.2M still missing; a portion had been converted to cryptocurrency and could not be recovered. No arrests were reported in the coverage reviewed. New Haven halted all electronic transfers except payroll, moved to paper checks, put budget-office and IT staff on administrative leave (officials stressed no city employee was believed complicit, and the employee was later cleared and reinstated), hired outside cybersecurity and financial-controls consultants (including Surefire) funded partly by cyber insurance, and pursued insurance coverage for the outstanding loss. The FBI, U.S. Marshals Service, and U.S. Attorney's Office (AUSA David C. Nelson) handled the investigation and forfeiture.

Why It Matters

It shows how a single compromised executive mailbox turns generic phishing into a high-precision, low-suspicion fraud: the attackers never had to fabricate a scenario because they used a real invoice and real relationships, defeating "does this seem plausible?" instincts. It underscores that public entities (school districts, municipalities) are lucrative BEC targets, that the critical control is out-of-band verification of any change to vendor banking details, and that look-alike vendor domains plus mid-thread payment-change requests are the recurring signature of this attack. Rapid detection and immediate bank/FBI engagement are what enabled the partial clawback.

Defenses

Require out-of-band, callback verification (using a known phone number on file, not one in the email) for any new or changed vendor bank/beneficiary details, and for large transfers. Enforce phishing-resistant MFA and monitor executive/finance mailboxes for suspicious logins and auto-forwarding or inbox rules. Flag inbound mail from newly registered or look-alike domains and enable external-sender banners. Separate duties so no single role can both approve and change payment instructions; add dual authorization and a mandatory hold/verification window on high-value transfers. Maintain a documented vendor-master-change process with confirmation to a second, previously verified contact. Report suspected BEC immediately to the bank and the FBI/IC3 to maximize the ACH/wire recall window.

Sources
  • Forfeiture Complaint Seeks to Return to New Haven More Than $1.1 Million Seized From Email Scammers. U.S. Department of Justice, U.S. Attorney's Office, District of Connecticut Primary. Nov 2023 DOJ/USAO release describing the compromised Board of Education management email, the fake bus-company domain, the beneficiary-account swap, and the $1.187M civil forfeiture. Confirmed live via direct HTTP fetch (200 OK) but serves an Akamai bot-protection interstitial to automated readers; content is quoted verbatim by, and cross-verified against, the New Haven Independent's Nov 2023 reporting on the same complaint.
  • Connecticut school district lost more than $6 million in cyber attack, so far gotten about half back. Associated Press Secondary. Fetched and confirmed live; corroborates victim, ~$6M loss, COO email compromise, vendor impersonation, $3.6M recovered, FBI involvement, no arrests.
  • Hackers Steal $6M Meant For School Bus Contract. New Haven Independent Secondary. Fetched and confirmed live. Local reporting from Mayor Elicker/police press conference; names COO Thomas Lamb, First Student, Shipman & Goodwin, S.J. Services, six successful plus one failed transfer, June 23 discovery, all verified against the fetched text.
  • Feds Seize Another $1.2M In Stolen City Funds. New Haven Independent Secondary. Fetched and confirmed live. Details the federal forfeiture complaint, the ~1-month mailbox dwell time, the look-alike bus-company domain, test emails, beneficiary swap, and the full money-laundering trail (JPMorgan Chase, OM Mobile Care LLC/Malcolm K. O'Shane, TD Bank accounts, Michael Harrison, cashier's checks, Crypto.com); all names and figures verified directly against fetched text.
  • Feds recover $2.28 million for New Haven-based victims of email scam. New Haven Register Secondary. Fetched and confirmed live. April 2024 update; note this article reports a combined $2,288,235 recovery across TWO separate BEC cases (New Haven BOE plus an unrelated New Haven health-care company's insurance-wire scam). Confirmed the New-Haven-BOE-specific figures ($1,187,691 forfeited, $3.6M ACH-recovered, ~$4.79M total) match the case file's numbers and are not conflated with the second, unrelated company's ~$1.65M loss.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Initial access: Attackers gained unauthorized access to NHPS COO Thomas Lamb's email account. The exact method was not disclosed in public reporting, but this is consistent with typical BEC intrusion vectors such as targeted phishing, credential theft, or reuse of a previously breached password against a mailbox with weak authentication.
Countering Stage 1: Phishing-resistant MFA (e.g. hardware security keys) and conditional-access/anomalous-login monitoring on executive and finance mailboxes would make a stolen or guessed password insufficient on its own to achieve account takeover.
2
Silent dwell time and mailbox surveillance: Per the federal civil forfeiture complaint, the attackers reviewed traffic inside the compromised mailbox for at least about a month before acting, using that window to identify a real, high-value, in-flight transaction (the outstanding ~$5.9M owed to bus contractor First Student) and to absorb the real tone, timing, and personalities of the thread.
Countering Stage 2: Mailbox-activity analytics that flag sustained silent access, unusual read patterns, or new auto-forwarding/inbox rules on privileged accounts can surface a dwell-time intrusion before the attacker acts on what they learned.
3
Look-alike infrastructure setup: The attackers registered a domain designed to closely resemble First Student's real domain, a standard BEC technique that lets an attacker impersonate a known vendor by mail alone, without needing to compromise the vendor's own systems.
Countering Stage 3: Domain-monitoring or typosquat-detection services, plus DMARC enforcement and external-sender warning banners, can flag inbound mail from newly registered or look-alike vendor domains before staff treat it as legitimate correspondence.
4
Test communications: Using the already-compromised COO account, the attackers reportedly sent test emails to the newly registered fake bus-company address, per the forfeiture complaint, to confirm the spoofed correspondence would pass as legitimate before initiating the actual fraud request.
Countering Stage 4: This step occurs entirely within the attacker's already-compromised mailbox and freshly registered domain, so it is not independently observable by the victim; the realistic control is closing off Stage 1 (account compromise) and Stage 3 (domain impersonation) before this calibration step becomes possible.
5
Vendor impersonation and payment-detail change request: Posing as First Student through the look-alike domain, and backed by the credibility of an active real invoice thread, the attackers requested that the vendor's bank/beneficiary details be updated in the city's vendor-payment system ahead of the imminent payment.
Countering Stage 5: A documented vendor-master-change process that requires out-of-band callback verification, using a phone number already on file rather than one supplied in the email, to a second, previously known contact would catch swapped bank details before they are entered into the payment system.
6
Fraudulent transfer execution: New Haven's finance office processed six fraudulent electronic transfers (four totaling about $5.9M to the fake First Student account, two totaling about $76K to a fake Shipman & Goodwin account) using the COO's standing authority to approve budget-approved payments, until First Student's inquiry about a missing payment exposed the fraud on June 23, 2023; a seventh attempt impersonating cleaning vendor S.J. Services was denied after the breach was already known.
Countering Stage 6: Separation of duties so no single role can both change payment instructions and approve the transfer, combined with dual authorization and a mandatory hold/verification window on large or newly changed vendor payments, creates a second checkpoint that can catch the fraud before funds leave the organization.
7
Money laundering and cash-out: Per the federal forfeiture complaint, the stolen funds landed in a JPMorgan Chase account held by a Florida-registered holding company (OM Mobile Care LLC, controlled by Malcolm K. O'Shane), were then moved via cashier's checks and wire transfers into TD Bank accounts (including one controlled by Michael Harrison), with a portion further routed into a Crypto.com-linked account to convert and obscure the proceeds before law enforcement could trace and freeze them.
Countering Stage 7: Once funds have left the victim's control, the realistic backstops are rapid fraud reporting to the sending bank and to the FBI/IC3 within the ACH/wire recall window (which enabled New Haven's ~$3.6M hold-harmless recovery), and law-enforcement asset tracing and civil forfeiture against mule accounts (which recovered a further ~$1.187M); stronger KYC and transaction monitoring at receiving banks on newly opened shell-company accounts is the upstream control that would slow this stage industry-wide.
Quick Facts
Victim
City of New Haven, New Haven Public Schools Board of Education, Connecticut (vendor First Student and law firm Shipman & Goodwin were impersonated)
Location
New Haven, Connecticut, USA
Date
2023-05 to 2023-06 (attack), disclosed 2023-08-10
Impact
~$6M diverted (about $5.9M in four transfers intended for bus contractor First Student, plus ~$76K in two payments meant for law firm Shipman & Goodwin); ~$3.6M recovered via bank ACH hold-harmless, plus ~$1.187M seized via federal civil forfeiture (about $4.7M-4.8M total recovered/expected); roughly $1.2M remained missing
Status
Confirmed
Case Type
Real-World Incident
Sector
Education, Government & Public Sector
Related

Related Cases

Retool smishing + deepfake vishing breach (2023)

A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…

Incident 2023Read →

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…

Incident 2022Read →

RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud

A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into…

Incident 2024Read →