Scammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect, then used a lookalike "easthardings.com" domain to redirect a $3.2M construction payment to accounts they controlled.
Reviewed by the Social Engineering Examples team.
In December 2025 the Pine Bluff School District was finalizing a routine monthly construction payment to East Harding Construction for its ~$74M new high school project. The payment "pay application" flowed on a legitimate email thread: the architect (Lewis Architects Engineers) sent it to East Harding, which forwarded it to district finance director Jamie Reid. Attackers, who had compromised email access on the vendor/thread side and had accessed Reid's Google account from a device in Lekki, Nigeria (as early as Dec. 12 per a login screenshot in FOIA records), inserted themselves into the thread using a lookalike domain, "easthardings.com" (an added "s"), mimicking the real "eastharding.com." Posing as an East Harding executive, they introduced fraudulent electronic payment instructions, justified by an accurate, known year-end audit. Reid initiated a $3,204,639.55 wire through Simmons Bank on Dec. 17, approved by the superintendent. On Dec. 18, while checking an unrelated vendor request, Reid spotted the wrong domain, contacted East Harding directly by phone, and confirmed the fraud at ~2:10 p.m. She filed an FBI IC3 complaint on Dec. 19. The incident is well documented via Arkansas FOIA-released district records (including annotated printouts of the emails and Reid's IC3 complaint), superintendent board-meeting statements, and reporting; confirmed real.
This was a thread-hijack / vendor-email-compromise BEC that weaponized trust in an ongoing, legitimate business relationship rather than a cold approach. The attackers rode an authentic invoice conversation that all parties expected, so nothing about the topic, timing, amount, or participants looked out of place. Two moves made it convincing: (1) a lookalike domain (extra "s") that reads as correct at a glance, and (2) reference to a real, known year-end audit as the reason to shift from the normal check pickup to an electronic transfer. Handwritten annotations in the FOIA records indicate the intruders manipulated Reid's mailbox to hide the genuine contractor email so the fraudulent version would stand unchallenged. When Reid said she could not pay by ACH, the actors adapted and offered wire instructions instead, showing operational familiarity with the district-vendor relationship. Because the request arrived inside a trusted thread and matched a routine monthly process, the usual "does this look like phishing?" instincts were bypassed. The absence of out-of-band phone verification against a previously known number was the single control that would have caught it.
Lure: a fraudulent message inside a genuine, expected invoice/pay-application thread, appearing to come from a familiar East Harding executive, asking to pay the already-approved amount electronically because of a (real) year-end audit. Tells: sender domain was "easthardings.com" instead of "eastharding.com" (an added letter); an unusual switch from the normal in-person check pickup to a wire/ACH; and payment-instruction changes delivered only over email. The decisive detection was noticing the incorrect domain and then calling the vendor on a known number to verify, which confirmed the vendor had never requested a wire.
The $3,204,639.55 wire routed through Citibank to multiple downstream accounts. Simmons Bank's fraud team submitted a recall request; roughly $1,120,051.51 was recovered as of April 30, 2026, with the investigation ongoing. The district had to make a second, legitimate payment to East Harding for the amount owed. The FBI opened a federal investigation. The district filed a claim with the Arkansas Cyber Response Board. Finance director Jamie Reid was later placed on paid administrative leave. East Harding stated its own systems were not breached. No arrests were publicly reported.
This is a textbook vendor-email-compromise/thread-hijack BEC against a public entity: the money moved not because anyone clicked a crude phishing link, but because a legitimate, routine payment conversation was quietly hijacked and a single character was added to a trusted domain. K-12 districts and other organizations that make large, recurring vendor payments are attractive targets precisely because the transactions are expected and staff are conditioned to process them. It also shows how a real, verifiable fact (a genuine year-end audit) can be turned into a persuasive pretext, and how mailbox manipulation can hide the authentic message. The case underlines that the reliable defense against payment-redirection fraud is out-of-band verification on a previously known phone number, not visual inspection of an email.
Verify any new or changed payment instructions (wire/ACH details, or a switch in payment method) out-of-band by calling the vendor on a previously known, verified phone number, never a number or address supplied in the email. Require dual authorization with separation of duties so no single person can both initiate and approve a wire. Treat method changes (check to wire) and urgency framed by audits/deadlines as red flags requiring escalation. Enforce MFA and monitor for anomalous mailbox logins (foreign geolocations) and suspicious inbox rules that hide or move messages. Carefully inspect sender domains for lookalike alterations and consider blocking/flagging near-match domains. Use test transfers with a waiting period and confirmation before releasing large sums to new or updated banking details. Report suspected fraud immediately to the bank and FBI IC3; fast recall requests improve recovery odds. (These match the post-incident controls Pine Bluff adopted.)
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…
A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an…