A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into a mule account, part of a broader roughly $220,000 fraud scheme that produced a federal wire fraud guilty plea.
Reviewed by the Social Engineering Examples team.
In October 2024, the Ohio Valley Industrial & Business Development Corporation d/b/a Regional Economic Development Partnership (RED), a private nonprofit economic development organization in Wheeling, West Virginia, received a message from a compromised email address requesting payment for solar panels that had purportedly been installed on the former Horne's Department Store building in Wheeling, a property tied to a real redevelopment project RED was involved with. Trusting the request, RED paid $30,750 to a bank account whose routing number had been supplied by the sender; that account belonged to Terry Pierce, 48, of Muskogee, Oklahoma. Two days after the funds arrived, Pierce moved them into another account he controlled and depleted the balance. A subsequent investigation by the West Virginia State Police found that Pierce had been involved in additional fraudulent activity beyond the RED incident, bringing the total actual or intended loss attributed to him to approximately $220,000. On or around July 14-15, 2026, U.S. Attorney Matthew L. Harvey (Northern District of West Virginia) announced that Pierce had pled guilty to wire fraud before U.S. Magistrate Judge James P. Mazzone; Assistant U.S. Attorney Jarod Douglas is prosecuting. Pierce faces up to 20 years in federal prison, with sentencing pending.
An unknown perpetrator gained control of, or otherwise used, a compromised email address to contact RED and request payment for solar panel installation work purportedly performed on the former Horne's Department Store building in Wheeling, a real redevelopment property RED was involved with, which lent the request plausibility. The message directed RED to send the $30,750 payment to a bank account for which the sender supplied a checking-account routing number belonging to Terry Pierce, a 48-year-old Muskogee, Oklahoma resident who was recruited or agreed to receive the funds. RED wired the $30,750, and two days after the money landed in his account, Pierce transferred it to another account he controlled and depleted the balance, a classic mule-account layering step meant to frustrate recovery and tracing. The subsequent investigation, led by the West Virginia State Police, uncovered that Pierce was involved in additional fraudulent activity beyond the RED payment, bringing his total actual/intended fraud loss to roughly $220,000. The identity and method of the original email compromise (i.e., whose account was hijacked, or whether it was a lookalike/spoofed domain versus a genuinely hijacked mailbox) was not detailed in the available court reporting; DOJ's language ("compromised email address") indicates account takeover rather than simple domain spoofing.
The lure was a routine-looking vendor payment request tied to a real, active capital project (solar panel installation at the former Horne's Department Store building), which RED was actually redeveloping, making the invoice request contextually credible rather than a generic cold phish. The tell that should have triggered scrutiny was a change in payment destination: the routing/account number the "vendor" supplied belonged to a Muskogee, Oklahoma individual (Terry Pierce), not the actual solar installer, a mismatch a phone-verified callback to the known vendor contact would likely have caught. No details on visual spoofing (lookalike domains, altered PDF invoices) were disclosed in available reporting.
Terry Pierce, 48, of Muskogee, Oklahoma, pled guilty to wire fraud (18 U.S.C. § 1343) in the U.S. District Court for the Northern District of West Virginia; the plea was announced by U.S. Attorney Matthew L. Harvey around July 14-15, 2026. U.S. Magistrate Judge James P. Mazzone presided over the plea proceeding; Assistant U.S. Attorney Jarod Douglas is prosecuting; the West Virginia State Police investigated. Pierce faces up to 20 years in federal prison, with sentencing to be determined by a federal district court judge under the U.S. Sentencing Guidelines; no sentencing date/outcome had been reported as of the available sources. The person who actually compromised the email account and initiated the fraudulent request was not identified/charged in the reporting reviewed, only Pierce (the receiving/mule-account holder) faced charges.
This case shows how business email compromise reaches beyond large corporations to small nonprofit and government-adjacent economic development organizations that manage real capital-project vendor payments, and that plausible project context (a real solar installation on a real redevelopment building) is often enough to get a payment approved without a verification callback. It also illustrates the money-mule layer of BEC economics: the person prosecuted was not the (unidentified) email-compromise operator but the individual who supplied a personal bank account to receive and immediately launder the stolen funds, showing how law enforcement can build a federal wire fraud case around the domestic financial end of a scheme even when the actual intrusion/spoofing actor is never identified.
Call-back verification of any changed payment/banking instructions using an independently sourced (not emailed) phone number for the vendor; mandatory dual-approval and out-of-band confirmation for wire transfers tied to capital projects; treating any request to route payment to a new or unfamiliar bank account as a hard stop requiring verification; vendor-side email account hardening (MFA, login-anomaly monitoring) since the compromise reportedly originated in a legitimate email account rather than a spoofed lookalike domain; staff training for nonprofit/finance-office personnel on BEC red flags around known ongoing projects; bank-side monitoring for mule-account patterns (rapid inbound transfer followed by rapid outbound sweep and account depletion), which is what ultimately exposed Pierce's role.
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M…
Impersonators posing as two School District of Philadelphia vendors switched payments from paper check to ACH and diverted nearly $700,000…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…