Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread, spoofed the vendor to swap in their own bank account, and diverted about $6M in city funds.
Reviewed by the Social Engineering Examples team.
In late May 2023, attackers gained access to the email account of New Haven Public Schools Chief Operating Officer Thomas Lamb. For roughly a month they silently monitored ongoing correspondence between the COO, vendors, and the city budget office. In June, focusing on a real, outstanding ~$5.9M payment owed to school bus contractor First Student, they registered a look-alike email domain impersonating the bus company, used the compromised COO account to run test messages, and then posed as the vendor to get the payment/beneficiary details changed to accounts they controlled. New Haven's finance office processed six fraudulent electronic transfers (four to a fake First Student account totaling ~$5.9M, two to a fake law-firm account totaling ~$76K). A seventh attempt in early July impersonating cleaning vendor S.J. Services was denied. The fraud surfaced on June 23 when the real First Student asked why it had not been paid. The city stopped electronic transfers and notified New Haven police, the FBI, and the U.S. Attorney's Office. Officials stayed publicly quiet until August 10, 2023 at the FBI's request. About $3.6M was quickly clawed back through JPMorgan Chase's ACH hold-harmless process, and in November 2023 the U.S. Attorney for Connecticut filed a civil forfeiture complaint over an additional ~$1.187M traced to TD Bank accounts (some funds had been shuttled through cashier's checks and into a crypto exchange). This is documented in local and national press and in U.S. Department of Justice / U.S. Attorney (District of Connecticut) releases, making it a confirmed, real incident.
This was a vendor thread-hijack business email compromise (BEC). Because the attackers were inside a legitimate executive mailbox, they saw the exact real invoice, amount, timing, and personalities of an in-flight transaction, so their impersonation required no invented pretext. They exploited the trust of an existing vendor relationship and the routine nature of a budget-approved payment: the COO had authority to authorize transfers already approved in the budget, so requests appeared normal. By registering a near-identical look-alike domain for the bus company, they controlled both sides of the conversation and could authoritatively request that the vendor's banking/beneficiary details be updated just before payment, redirecting funds to mule accounts. The lack of an out-of-band verification step for changing vendor payment information is what let the swapped account details flow straight through to disbursement.
Lure: emails that appeared to come from the trusted district COO and the district's own bus contractor, referencing a genuine outstanding invoice, asking to update the vendor's payment/bank details before an imminent large payment. Tells: a subtly different look-alike sender domain impersonating the vendor, a mid-transaction request to change established banking details, and pressure tied to a real deadline. The decisive missed check was that no one verified the new payment instructions with the vendor through a known, independent channel (a phone call to First Student would have exposed the swap).
Roughly $6M was diverted. About $3.6M was recovered through bank ACH recall, and federal authorities seized/forfeited an additional ~$1.187M, bringing expected recovery to about $4.7M-4.8M, with roughly $1.2M still missing; a portion had been converted to cryptocurrency and could not be recovered. No arrests were reported in the coverage reviewed. New Haven halted all electronic transfers except payroll, moved to paper checks, put budget-office and IT staff on administrative leave (officials stressed no city employee was believed complicit, and the employee was later cleared and reinstated), hired outside cybersecurity and financial-controls consultants (including Surefire) funded partly by cyber insurance, and pursued insurance coverage for the outstanding loss. The FBI, U.S. Marshals Service, and U.S. Attorney's Office (AUSA David C. Nelson) handled the investigation and forfeiture.
It shows how a single compromised executive mailbox turns generic phishing into a high-precision, low-suspicion fraud: the attackers never had to fabricate a scenario because they used a real invoice and real relationships, defeating "does this seem plausible?" instincts. It underscores that public entities (school districts, municipalities) are lucrative BEC targets, that the critical control is out-of-band verification of any change to vendor banking details, and that look-alike vendor domains plus mid-thread payment-change requests are the recurring signature of this attack. Rapid detection and immediate bank/FBI engagement are what enabled the partial clawback.
Require out-of-band, callback verification (using a known phone number on file, not one in the email) for any new or changed vendor bank/beneficiary details, and for large transfers. Enforce phishing-resistant MFA and monitor executive/finance mailboxes for suspicious logins and auto-forwarding or inbox rules. Flag inbound mail from newly registered or look-alike domains and enable external-sender banners. Separate duties so no single role can both approve and change payment instructions; add dual authorization and a mandatory hold/verification window on high-value transfers. Maintain a documented vendor-master-change process with confirmation to a second, previously verified contact. Report suspected BEC immediately to the bank and the FBI/IC3 to maximize the ACH/wire recall window.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into…