Impersonators posing as two School District of Philadelphia vendors switched payments from paper check to ACH and diverted nearly $700,000 into fraud accounts; the loss surfaced only during the annual city audit.
Reviewed by the Social Engineering Examples team.
During the Fiscal Year 2024 annual audit of the School District of Philadelphia, City Controller Christy Brady's office was informed of four fraudulent Automated Clearing House (ACH) payments made in early 2024 to individuals or entities impersonating legitimate district vendors. On March 12, 2024, a $563,151 payment intended for a flood-damage repair contractor was diverted; separately, $126,056 intended for a special-education compensatory-services vendor was diverted across three transfers on Feb. 6, Feb. 27, and March 8, 2024. In both cases the real vendors had completed the work but never received payment. The district normally pays vendors by paper check, but impersonators requested a switch to electronic ACH payment; reporting indicates the legitimate vendors' emails had been compromised. On May 22, 2025, Brady referred the matter to the Pennsylvania Attorney General; Superintendent Tony Watlington said the district also reported it to the FBI, its Office of Inspector General, and Office of General Counsel. The incident is confirmed by the Controller's press release, her referral letter to the AG, and multiple news outlets; funds had not been recovered at disclosure.
The scheme exploited the routine, low-suspicion business process of updating a vendor's payment details. Attackers (working from compromised vendor email accounts, per district officials) contacted the district posing as the real contractors and requested that outstanding invoices be paid electronically via ACH rather than by the district's default paper check. Because the request appeared to come from a known, legitimate vendor with a genuine outstanding balance for work actually performed, the payment-change request looked ordinary. The money was routed to bank accounts controlled by the fraud actors. The Controller noted the actors either gained unauthorized access to banking data or manipulated existing payment workflows. The theft was not caught in real time by transaction controls; it surfaced only when auditors and the vendors reconciled unpaid invoices, and later when the annual district audit examined the ACH activity.
Lure: a request, appearing to come from a trusted existing vendor with a real outstanding invoice, to change the payment method from paper check to ACH direct deposit. Tells: an unsolicited change of banking/payment details, a switch away from the organization's default payment method, and requests to expedite payment. The reliable defense signal is any change to vendor bank details, which should be verified out-of-band using a known-good phone number rather than contact details supplied in the request.
Nearly $700,000 was diverted and remained unrecovered as of the May 2025 public disclosure; the legitimate vendors had not been paid. The matter was referred to the Pennsylvania Attorney General and reported to the FBI and district oversight offices, with the investigation ongoing. The district said no student data or its financial data system was compromised and that it did not pay more than owed. It reported implementing corrective measures: revised bank-confirmation processes, improved validation of vendor payment changes, and strengthened internal controls.
Public-sector bodies process large, predictable vendor payments and are attractive BEC targets, especially when payment-change controls are weak. This case shows how vendor-impersonation ACH diversion can succeed through an entirely mundane request, and how such fraud can go undetected for a year until an audit or vendor reconciliation reveals it. It also echoes an earlier 2022 attempted fraud at the same district (roughly $503,580, mostly recovered) flagged by its Inspector General, underscoring that unremediated vendor-payment weaknesses invite repeat attacks.
Verify every vendor bank-detail or payment-method change out-of-band using a phone number already on file, never one supplied in the request. Require dual authorization and a mandatory callback for changes to ACH/direct-deposit information. Use a bank prenote/test-transaction to validate new account details before releasing funds. Do not host fillable ACH change forms on public websites, and follow NACHA guidance. Train accounts-payable staff on vendor-impersonation social engineering and its indicators. Reconcile vendor payments promptly so diverted funds are caught within the ~72-hour window when recovery is most feasible, and report suspected BEC immediately to the bank and to the FBI IC3.
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into…
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…