Case Library / Phishing / RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud
Phishing Confirmed

RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud

A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into a mule account, part of a broader roughly $220,000 fraud scheme that produced a federal wire fraud guilty plea.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In October 2024, the Ohio Valley Industrial & Business Development Corporation d/b/a Regional Economic Development Partnership (RED), a private nonprofit economic development organization in Wheeling, West Virginia, received a message from a compromised email address requesting payment for solar panels that had purportedly been installed on the former Horne's Department Store building in Wheeling, a property tied to a real redevelopment project RED was involved with. Trusting the request, RED paid $30,750 to a bank account whose routing number had been supplied by the sender; that account belonged to Terry Pierce, 48, of Muskogee, Oklahoma. Two days after the funds arrived, Pierce moved them into another account he controlled and depleted the balance. A subsequent investigation by the West Virginia State Police found that Pierce had been involved in additional fraudulent activity beyond the RED incident, bringing the total actual or intended loss attributed to him to approximately $220,000. On or around July 14-15, 2026, U.S. Attorney Matthew L. Harvey (Northern District of West Virginia) announced that Pierce had pled guilty to wire fraud before U.S. Magistrate Judge James P. Mazzone; Assistant U.S. Attorney Jarod Douglas is prosecuting. Pierce faces up to 20 years in federal prison, with sentencing pending.

How the Attack Worked

An unknown perpetrator gained control of, or otherwise used, a compromised email address to contact RED and request payment for solar panel installation work purportedly performed on the former Horne's Department Store building in Wheeling, a real redevelopment property RED was involved with, which lent the request plausibility. The message directed RED to send the $30,750 payment to a bank account for which the sender supplied a checking-account routing number belonging to Terry Pierce, a 48-year-old Muskogee, Oklahoma resident who was recruited or agreed to receive the funds. RED wired the $30,750, and two days after the money landed in his account, Pierce transferred it to another account he controlled and depleted the balance, a classic mule-account layering step meant to frustrate recovery and tracing. The subsequent investigation, led by the West Virginia State Police, uncovered that Pierce was involved in additional fraudulent activity beyond the RED payment, bringing his total actual/intended fraud loss to roughly $220,000. The identity and method of the original email compromise (i.e., whose account was hijacked, or whether it was a lookalike/spoofed domain versus a genuinely hijacked mailbox) was not detailed in the available court reporting; DOJ's language ("compromised email address") indicates account takeover rather than simple domain spoofing.

The Lure & the Tell

The lure was a routine-looking vendor payment request tied to a real, active capital project (solar panel installation at the former Horne's Department Store building), which RED was actually redeveloping, making the invoice request contextually credible rather than a generic cold phish. The tell that should have triggered scrutiny was a change in payment destination: the routing/account number the "vendor" supplied belonged to a Muskogee, Oklahoma individual (Terry Pierce), not the actual solar installer, a mismatch a phone-verified callback to the known vendor contact would likely have caught. No details on visual spoofing (lookalike domains, altered PDF invoices) were disclosed in available reporting.

Outcome

Terry Pierce, 48, of Muskogee, Oklahoma, pled guilty to wire fraud (18 U.S.C. § 1343) in the U.S. District Court for the Northern District of West Virginia; the plea was announced by U.S. Attorney Matthew L. Harvey around July 14-15, 2026. U.S. Magistrate Judge James P. Mazzone presided over the plea proceeding; Assistant U.S. Attorney Jarod Douglas is prosecuting; the West Virginia State Police investigated. Pierce faces up to 20 years in federal prison, with sentencing to be determined by a federal district court judge under the U.S. Sentencing Guidelines; no sentencing date/outcome had been reported as of the available sources. The person who actually compromised the email account and initiated the fraudulent request was not identified/charged in the reporting reviewed, only Pierce (the receiving/mule-account holder) faced charges.

Why It Matters

This case shows how business email compromise reaches beyond large corporations to small nonprofit and government-adjacent economic development organizations that manage real capital-project vendor payments, and that plausible project context (a real solar installation on a real redevelopment building) is often enough to get a payment approved without a verification callback. It also illustrates the money-mule layer of BEC economics: the person prosecuted was not the (unidentified) email-compromise operator but the individual who supplied a personal bank account to receive and immediately launder the stolen funds, showing how law enforcement can build a federal wire fraud case around the domestic financial end of a scheme even when the actual intrusion/spoofing actor is never identified.

Defenses

Call-back verification of any changed payment/banking instructions using an independently sourced (not emailed) phone number for the vendor; mandatory dual-approval and out-of-band confirmation for wire transfers tied to capital projects; treating any request to route payment to a new or unfamiliar bank account as a hard stop requiring verification; vendor-side email account hardening (MFA, login-anomaly monitoring) since the compromise reportedly originated in a legitimate email account rather than a spoofed lookalike domain; staff training for nonprofit/finance-office personnel on BEC red flags around known ongoing projects; bank-side monitoring for mule-account patterns (rapid inbound transfer followed by rapid outbound sweep and account depletion), which is what ultimately exposed Pierce's role.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: RED's active capital projects, including the Horne's Department Store redevelopment and its solar-panel installation, are the kind of detail typically visible through board minutes, grant announcements, and local press, information a perpetrator likely drew on to make a fraudulent invoice request tied to that specific project sound credible.
Countering Stage 1: A nonprofit's active capital projects are hard to keep fully private since they typically surface in board minutes, grant announcements, or local coverage. The realistic control is to assume project details are knowable to outsiders and require verification on any payment request tied to a known project, rather than trying to suppress the information.
2
Email account compromise: the perpetrator gained control of, or otherwise obtained the ability to send from, a compromised email address associated with RED or its vendor relationship. DOJ's language ("compromised email address") points to account takeover, consistent with typical BEC techniques like credential phishing or password reuse against a mailbox, rather than a spoofed lookalike domain.
Countering Stage 2: Vendor and partner email-account hardening, including mandatory MFA, conditional access policies, and login-anomaly alerting, reduces the odds that an outside party can take over or convincingly use a legitimate mailbox to originate fraudulent requests.
3
Mule recruitment: separately, the perpetrator recruited or arranged for Terry Pierce to supply a personal checking account's routing number to receive the fraudulent payment, a standard BEC pattern of routing stolen funds through a domestic money mule to distance the scheme's operator from the money trail.
Countering Stage 3: Bank account-opening and know-your-customer checks can catch some mule accounts early, but recruitment of willing or coerced mules is difficult to prevent upstream. The more reliable control sits downstream at Stage 6, where transaction-pattern monitoring can flag mule behavior after the account is already in use.
4
Pretext invoice request: using the compromised email address, the attacker sent RED a payment request for solar panel installation work purportedly completed on the Horne's building, tying the ask to genuine ongoing project work and directing that funds be sent to Pierce's account rather than the real vendor's.
Countering Stage 4: Staff training for finance-office personnel on BEC red flags, specifically treating any request to introduce or change payment or banking details as suspicious regardless of how plausible the surrounding project context is, would have flagged this message before payment was processed.
5
Payment execution: RED processed the request as routine vendor correspondence and wired $30,750 without an independent, phone-based confirmation call to the vendor, completing the fraudulent redirect.
Countering Stage 5: Mandatory call-back verification of any new or changed banking instructions, using an independently sourced phone number for the vendor rather than any contact information in the email itself, combined with dual-approval for wire transfers, would likely have caught the mismatch between the purported vendor and Pierce's personal account before the money moved.
6
Mule-account layering and cash-out: within two days of receiving the funds, Pierce moved them into another account he controlled and depleted the balance, a typical mule-account layering step meant to frustrate bank recall attempts and complicate tracing.
Countering Stage 6: Bank-side transaction monitoring for classic mule patterns, a rapid large inbound transfer followed quickly by an outbound sweep that empties the account, can flag and potentially freeze funds before they are fully dispersed, and is what ultimately helped expose Pierce's role here.
7
Objective completion and scheme continuation: the funds were extracted, and the West Virginia State Police investigation subsequently tied Pierce's account to additional fraudulent activity beyond the RED payment, totaling roughly $220,000 in actual or intended loss, indicating the same mule infrastructure was likely reused across multiple schemes before it was shut down.
Countering Stage 7: Once funds are dispersed and a mule's account is tied to multiple schemes, the realistic control shifts from prevention to detection and prosecution. Cross-case fraud-pattern investigation by law enforcement, as the West Virginia State Police carried out here, is what identifies a repeat mule before further victims are hit.
Quick Facts
Victim
Ohio Valley Industrial & Business Development Corporation, doing business as Regional Economic Development Partnership (RED), a private nonprofit economic development corporation based in Wheeling, West Virginia
Location
Wheeling, West Virginia, USA (Northern District of West Virginia); defendant resided in Muskogee, Oklahoma
Date
October 2024 (fraudulent payment occurred); guilty plea entered/announced July 14-15, 2026; sentencing pending as of research date
Impact
$30,750 paid directly on the fraudulent solar-panel-installation invoice request; approximately $220,000 in total actual/intended loss once investigators traced Pierce's broader fraudulent activity (figures per DOJ-sourced reporting, not independently itemized in available sources)
Status
Confirmed
Case Type
Real-World Incident
Sector
Construction & Engineering, Critical Infrastructure, Energy & Utilities, Government & Public Sector, Nonprofit & NGO
Related

Related Cases

Orion S.A. $60M fraudulently induced wire transfers (2024)

A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M…

Incident 2024Read →

School District of Philadelphia $700K Vendor-ACH Diversion BEC (2024)

Impersonators posing as two School District of Philadelphia vendors switched payments from paper check to ACH and diverted nearly $700,000…

Incident 2024Read →

PROMPTSTEAL/LAMEHUG: APT28's LLM-Powered Malware Against Ukraine

Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…

Incident 2025Read →