Case Library / Phishing / School District of Philadelphia $700K Vendor-ACH Diversion BEC (2024)
Phishing Confirmed

School District of Philadelphia $700K Vendor-ACH Diversion BEC (2024)

Impersonators posing as two School District of Philadelphia vendors switched payments from paper check to ACH and diverted nearly $700,000 into fraud accounts; the loss surfaced only during the annual city audit.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

During the Fiscal Year 2024 annual audit of the School District of Philadelphia, City Controller Christy Brady's office was informed of four fraudulent Automated Clearing House (ACH) payments made in early 2024 to individuals or entities impersonating legitimate district vendors. On March 12, 2024, a $563,151 payment intended for a flood-damage repair contractor was diverted; separately, $126,056 intended for a special-education compensatory-services vendor was diverted across three transfers on Feb. 6, Feb. 27, and March 8, 2024. In both cases the real vendors had completed the work but never received payment. The district normally pays vendors by paper check, but impersonators requested a switch to electronic ACH payment; reporting indicates the legitimate vendors' emails had been compromised. On May 22, 2025, Brady referred the matter to the Pennsylvania Attorney General; Superintendent Tony Watlington said the district also reported it to the FBI, its Office of Inspector General, and Office of General Counsel. The incident is confirmed by the Controller's press release, her referral letter to the AG, and multiple news outlets; funds had not been recovered at disclosure.

How the Attack Worked

The scheme exploited the routine, low-suspicion business process of updating a vendor's payment details. Attackers (working from compromised vendor email accounts, per district officials) contacted the district posing as the real contractors and requested that outstanding invoices be paid electronically via ACH rather than by the district's default paper check. Because the request appeared to come from a known, legitimate vendor with a genuine outstanding balance for work actually performed, the payment-change request looked ordinary. The money was routed to bank accounts controlled by the fraud actors. The Controller noted the actors either gained unauthorized access to banking data or manipulated existing payment workflows. The theft was not caught in real time by transaction controls; it surfaced only when auditors and the vendors reconciled unpaid invoices, and later when the annual district audit examined the ACH activity.

The Lure & the Tell

Lure: a request, appearing to come from a trusted existing vendor with a real outstanding invoice, to change the payment method from paper check to ACH direct deposit. Tells: an unsolicited change of banking/payment details, a switch away from the organization's default payment method, and requests to expedite payment. The reliable defense signal is any change to vendor bank details, which should be verified out-of-band using a known-good phone number rather than contact details supplied in the request.

Outcome

Nearly $700,000 was diverted and remained unrecovered as of the May 2025 public disclosure; the legitimate vendors had not been paid. The matter was referred to the Pennsylvania Attorney General and reported to the FBI and district oversight offices, with the investigation ongoing. The district said no student data or its financial data system was compromised and that it did not pay more than owed. It reported implementing corrective measures: revised bank-confirmation processes, improved validation of vendor payment changes, and strengthened internal controls.

Why It Matters

Public-sector bodies process large, predictable vendor payments and are attractive BEC targets, especially when payment-change controls are weak. This case shows how vendor-impersonation ACH diversion can succeed through an entirely mundane request, and how such fraud can go undetected for a year until an audit or vendor reconciliation reveals it. It also echoes an earlier 2022 attempted fraud at the same district (roughly $503,580, mostly recovered) flagged by its Inspector General, underscoring that unremediated vendor-payment weaknesses invite repeat attacks.

Defenses

Verify every vendor bank-detail or payment-method change out-of-band using a phone number already on file, never one supplied in the request. Require dual authorization and a mandatory callback for changes to ACH/direct-deposit information. Use a bank prenote/test-transaction to validate new account details before releasing funds. Do not host fillable ACH change forms on public websites, and follow NACHA guidance. Train accounts-payable staff on vendor-impersonation social engineering and its indicators. Reconcile vendor payments promptly so diverted funds are caught within the ~72-hour window when recovery is most feasible, and report suspected BEC immediately to the bank and to the FBI IC3.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and vendor targeting: Attackers likely identified the two victim vendors, a flood-damage repair contractor and a special-education compensatory-services provider, as School District of Philadelphia suppliers with genuine, sizeable outstanding invoices, consistent with either monitoring public procurement or invoice-related records, or already having access to the vendors' own email accounts and reading prior correspondence with the district.
Countering Stage 1: Vendor participation in public procurement and the resulting paper trail is difficult to hide and is not itself the gap to close. The realistic control assumes an attacker can learn real invoice details and hardens the payment-change process those details later get used against, see Stage 4, rather than trying to keep vendor relationships secret.
2
Vendor email compromise: Per reporting from the Philadelphia Inquirer, the real vendors' email accounts had been compromised, typically achieved through a phishing or credential-theft attack against vendor staff, a common precursor in vendor-impersonation BEC that lets attackers see real invoice numbers, amounts, and correspondence style.
Countering Stage 2: A vendor's own email security sits outside the district's direct control, but contracts can require vendors to use multi-factor authentication on financial-communication accounts, and the district can treat every vendor email, even from a known and correct address, as unverified until confirmed by phone.
3
Pretext outreach to district accounts payable: Posing as the legitimate, already-known vendor and referencing a genuine outstanding invoice, the attacker contacted the district's accounts-payable function by email and reportedly by phone, requesting that payment be switched from the district's default paper check to electronic ACH transfer.
Countering Stage 3: Train accounts-payable staff to flag any unsolicited request to change a vendor's payment method or banking details as inherently high-risk, regardless of how legitimate the accompanying invoice details appear.
4
Exploiting the payment-change verification gap: The attacker supplied fraudulent bank-account details through the district's vendor payment-change process. Because the request matched a real invoice and known vendor details, it was accepted without an out-of-band callback to a verified phone number, consistent with the Controller's finding that bad actors either gained unauthorized access to banking data or manipulated the district's existing payment workflow.
Countering Stage 4: Require mandatory out-of-band verification of any bank-detail or payment-method change, using a phone number already on file rather than one supplied in the request, plus dual authorization and a bank prenote or test transaction before releasing funds. Do not host fillable ACH change forms on a public website, per NACHA guidance.
5
ACH transfer execution: Between February 6 and March 12, 2024, the district's accounts-payable system processed four ACH transfers totaling approximately $689,207 to bank accounts the attackers controlled rather than to the actual vendors.
Countering Stage 5: Apply transaction-level controls such as temporary holds, dollar-threshold review, or an added approval step on the first payment run to a newly changed vendor bank account before large sums are released.
6
Fund extraction before recall: The diverted funds were moved out of the receiving accounts before the district or its bank identified the fraud, standard practice in ACH-diversion schemes and consistent with why, as of the May 2025 disclosure, none of the money had been recovered.
Countering Stage 6: Reconcile vendor payments promptly and report suspected fraud to the bank and FBI IC3 immediately, since recovery is realistically only feasible within roughly the first 72 hours after an ACH transfer, a window that closes fast once funds move onward.
7
Detection deferred to the annual audit: The diversion was not caught by real-time transaction controls. It surfaced only when the vendors' unpaid invoices failed to reconcile and the City Controller's office reviewed ACH activity during its Fiscal Year 2024 annual audit of the district, more than a year after the first fraudulent transfer.
Countering Stage 7: Shorten the detection cycle by having accounts-payable staff and vendors reconcile invoices and payments on a routine, frequent schedule rather than relying on an annual external audit to surface discrepancies.
Quick Facts
Victim
School District of Philadelphia (and two of its contracted vendors, who completed work but were not paid)
Location
Philadelphia, Pennsylvania, USA
Date
2024-02 to 2024-03 (fraud); disclosed 2025-05-22
Impact
Approximately $689,207 diverted across four ACH transfers (a $563,151 payment for flood-damage repair on March 12, 2024, plus $126,056 for special-education compensatory services across Feb. 6, Feb. 27, and March 8, 2024). Funds not recovered as of the May 2025 disclosure; district stated it did not pay more than contractually owed.
Status
Confirmed
Case Type
Real-World Incident
Sector
Education, Government & Public Sector
Related

Related Cases

RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud

A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into…

Incident 2024Read →

Orion S.A. $60M fraudulently induced wire transfers (2024)

A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M…

Incident 2024Read →

PROMPTSTEAL/LAMEHUG: APT28's LLM-Powered Malware Against Ukraine

Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…

Incident 2025Read →