Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread.
Social Engineering Examples·5 sources
In late May 2023, attackers gained access to the email account of New Haven Public Schools Chief Operating Officer Thomas Lamb. For roughly a month they silently monitored ongoing correspondence between the COO, vendors, and the city budget office. In June, focusing on a real, outstanding ~$5.9M payment owed to school bus contractor First Student, they registered a look-alike email domain impersonating the bus company, used the compromised COO account to run test messages, and then posed as the vendor to get the payment/beneficiary details changed to accounts they controlled.
New Haven's finance office processed six fraudulent electronic transfers (four to a fake First Student account totaling ~$5.9M, two to a fake law-firm account totaling ~$76K). A seventh attempt in early July impersonating cleaning vendor S.J. Services was denied. The fraud surfaced on June 23 when the real First Student asked why it had not been paid.
The city stopped electronic transfers and notified New Haven police, the FBI, and the U.S. Attorney's Office. Officials stayed publicly quiet until August 10, 2023 at the FBI's request. About $3.6M was quickly clawed back through JPMorgan Chase's ACH hold-harmless process, and in November 2023 the U.S. Attorney for Connecticut filed a civil forfeiture complaint over an additional ~$1.187M traced to TD Bank accounts (some funds had been shuttled through cashier's checks and into a crypto exchange).
This is documented in local and national press and in U.S. Department of Justice / U.S. Attorney (District of Connecticut) releases, making it a confirmed, real incident.
This was a vendor thread-hijack business email compromise (BEC). Because the attackers were inside a legitimate executive mailbox, they saw the exact real invoice, amount, timing, and personalities of an in-flight transaction, so their impersonation required no invented pretext. They exploited the trust of an existing vendor relationship and the routine nature of a budget-approved payment: the COO had authority to authorize transfers already approved in the budget, so requests appeared normal.
By registering a near-identical look-alike domain for the bus company, they controlled both sides of the conversation and could authoritatively request that the vendor's banking/beneficiary details be updated just before payment, redirecting funds to mule accounts. The lack of an out-of-band verification step for changing vendor payment information is what let the swapped account details flow straight through to disbursement.
Lure: emails that appeared to come from the trusted district COO and the district's own bus contractor, referencing a genuine outstanding invoice, asking to update the vendor's payment/bank details before an imminent large payment. Tells: a subtly different look-alike sender domain impersonating the vendor, a mid-transaction request to change established banking details, and pressure tied to a real deadline.
The decisive missed check was that no one verified the new payment instructions with the vendor through a known, independent channel (a phone call to First Student would have exposed the swap).
Roughly $6M was diverted. About $3.6M was recovered through bank ACH recall, and federal authorities seized/forfeited an additional ~$1.187M, bringing expected recovery to about $4.7M-4.8M, with roughly $1.2M still missing; a portion had been converted to cryptocurrency and could not be recovered. No arrests were reported in the coverage reviewed. New Haven halted all electronic transfers except payroll, moved to paper checks, put budget-office and IT staff on administrative leave (officials stressed no city employee was believed complicit, and the employee was later cleared and reinstated), hired outside cybersecurity and financial-controls consultants (including Surefire) funded partly by cyber insurance, and pursued insurance coverage for the outstanding loss.
The FBI, U.S. Marshals Service, and U.S. Attorney's Office (AUSA David C. Nelson) handled the investigation and forfeiture.
It shows how a single compromised executive mailbox turns generic phishing into a high-precision, low-suspicion fraud: the attackers never had to fabricate a scenario because they used a real invoice and real relationships, defeating "does this seem plausible?" instincts. It underscores that public entities (school districts, municipalities) are lucrative BEC targets, that the critical control is out-of-band verification of any change to vendor banking details, and that look-alike vendor domains plus mid-thread payment-change requests are the recurring signature of this attack.
Rapid detection and immediate bank/FBI engagement are what enabled the partial clawback.
Require out-of-band, callback verification (using a known phone number on file, not one in the email) for any new or changed vendor bank/beneficiary details, and for large transfers. Enforce phishing-resistant MFA and monitor executive/finance mailboxes for suspicious logins and auto-forwarding or inbox rules. Flag inbound mail from newly registered or look-alike domains and enable external-sender banners.
Separate duties so no single role can both approve and change payment instructions; add dual authorization and a mandatory hold/verification window on high-value transfers. Maintain a documented vendor-master-change process with confirmation to a second, previously verified contact. Report suspected BEC immediately to the bank and the FBI/IC3 to maximize the ACH/wire recall window.
Social Engineering Examples. “New Haven Public Schools $6M COO-email vendor thread-hijack BEC”. Accessed 19 September 2026. https://socialengineeringexamples.com/new-haven-public-schools-bec-2023
Attackers gained unauthorized access to NHPS COO Thomas Lamb's email account. The exact method was not disclosed in public reporting, but this is consistent with typical BEC intrusion vectors such as targeted phishing, credential theft, or reuse of a previously breached password against a mailbox with weak authentication.
Phishing-resistant MFA (e.g. hardware security keys) and conditional-access/anomalous-login monitoring on executive and finance mailboxes would make a stolen or guessed password insufficient on its own to achieve account takeover.
Per the federal civil forfeiture complaint, the attackers reviewed traffic inside the compromised mailbox for at least about a month before acting, using that window to identify a real, high-value, in-flight transaction (the outstanding ~$5.9M owed to bus contractor First Student) and to absorb the real tone, timing, and personalities of the thread.
Mailbox-activity analytics that flag sustained silent access, unusual read patterns, or new auto-forwarding/inbox rules on privileged accounts can surface a dwell-time intrusion before the attacker acts on what they learned.
The attackers registered a domain designed to closely resemble First Student's real domain, a standard BEC technique that lets an attacker impersonate a known vendor by mail alone, without needing to compromise the vendor's own systems.
Domain-monitoring or typosquat-detection services, plus DMARC enforcement and external-sender warning banners, can flag inbound mail from newly registered or look-alike vendor domains before staff treat it as legitimate correspondence.
Using the already-compromised COO account, the attackers reportedly sent test emails to the newly registered fake bus-company address, per the forfeiture complaint, to confirm the spoofed correspondence would pass as legitimate before initiating the actual fraud request.
This step occurs entirely within the attacker's already-compromised mailbox and freshly registered domain, so it is not independently observable by the victim; the realistic control is closing off Stage 1 (account compromise) and Stage 3 (domain impersonation) before this calibration step becomes possible.
Posing as First Student through the look-alike domain, and backed by the credibility of an active real invoice thread, the attackers requested that the vendor's bank/beneficiary details be updated in the city's vendor-payment system ahead of the imminent payment.
A documented vendor-master-change process that requires out-of-band callback verification, using a phone number already on file rather than one supplied in the email, to a second, previously known contact would catch swapped bank details before they are entered into the payment system.
New Haven's finance office processed six fraudulent electronic transfers (four totaling about $5.9M to the fake First Student account, two totaling about $76K to a fake Shipman & Goodwin account) using the COO's standing authority to approve budget-approved payments, until First Student's inquiry about a missing payment exposed the fraud on June 23, 2023; a seventh attempt impersonating cleaning vendor S.J. Services was denied after the breach was already known.
Separation of duties so no single role can both change payment instructions and approve the transfer, combined with dual authorization and a mandatory hold/verification window on large or newly changed vendor payments, creates a second checkpoint that can catch the fraud before funds leave the organization.
Per the federal forfeiture complaint, the stolen funds landed in a JPMorgan Chase account held by a Florida-registered holding company (OM Mobile Care LLC, controlled by Malcolm K. O'Shane), were then moved via cashier's checks and wire transfers into TD Bank accounts (including one controlled by Michael Harrison), with a portion further routed into a Crypto.com-linked account to convert and obscure the proceeds before law enforcement could trace and freeze them.
Once funds have left the victim's control, the realistic backstops are rapid fraud reporting to the sending bank and to the FBI/IC3 within the ACH/wire recall window (which enabled New Haven's ~$3.6M hold-harmless recovery), and law-enforcement asset tracing and civil forfeiture against mule accounts (which recovered a further ~$1.187M); stronger KYC and transaction monitoring at receiving banks on newly opened shell-company accounts is the upstream control that would slow this stage industry-wide.
Browse by what this case has in common with others in the library.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
Scammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect.
A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders.
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…
California's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured.