A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
Social Engineering Examples·4 sources
In October 2024, the Ohio Valley Industrial & Business Development Corporation d/b/a Regional Economic Development Partnership (RED), a private nonprofit economic development organization in Wheeling, West Virginia, received a message from a compromised email address requesting payment for solar panels that had purportedly been installed on the former Horne's Department Store building in Wheeling, a property tied to a real redevelopment project RED was involved with.
Trusting the request, RED paid $30,750 to a bank account whose routing number had been supplied by the sender; that account belonged to Terry Pierce, 48, of Muskogee, Oklahoma. Two days after the funds arrived, Pierce moved them into another account he controlled and depleted the balance. A subsequent investigation by the West Virginia State Police found that Pierce had been involved in additional fraudulent activity beyond the RED incident, bringing the total actual or intended loss attributed to him to approximately $220,000. On or around July 14-15, 2026, U.S. Attorney Matthew L. Harvey (Northern District of West Virginia) announced that Pierce had pled guilty to wire fraud before U.S. Magistrate Judge James P. Mazzone; Assistant U.S. Attorney Jarod Douglas is prosecuting.
Pierce faces up to 20 years in federal prison, with sentencing pending.
An unknown perpetrator gained control of, or otherwise used, a compromised email address to contact RED and request payment for solar panel installation work purportedly performed on the former Horne's Department Store building in Wheeling, a real redevelopment property RED was involved with, which lent the request plausibility. The message directed RED to send the $30,750 payment to a bank account for which the sender supplied a checking-account routing number belonging to Terry Pierce, a 48-year-old Muskogee, Oklahoma resident who was recruited or agreed to receive the funds.
RED wired the $30,750, and two days after the money landed in his account, Pierce transferred it to another account he controlled and depleted the balance, a classic mule-account layering step meant to frustrate recovery and tracing. The subsequent investigation, led by the West Virginia State Police, uncovered that Pierce was involved in additional fraudulent activity beyond the RED payment, bringing his total actual/intended fraud loss to roughly $220,000. The identity and method of the original email compromise (i.e., whose account was hijacked, or whether it was a lookalike/spoofed domain versus a genuinely hijacked mailbox) was not detailed in the available court reporting; DOJ's language ("compromised email address") indicates account takeover rather than simple domain spoofing.
The lure was a routine-looking vendor payment request tied to a real, active capital project (solar panel installation at the former Horne's Department Store building), which RED was actually redeveloping, making the invoice request contextually credible rather than a generic cold phish. The tell that should have triggered scrutiny was a change in payment destination: the routing/account number the "vendor" supplied belonged to a Muskogee, Oklahoma individual (Terry Pierce), not the actual solar installer, a mismatch a phone-verified callback to the known vendor contact would likely have caught.
No details on visual spoofing (lookalike domains, altered PDF invoices) were disclosed in available reporting.
Terry Pierce, 48, of Muskogee, Oklahoma, pled guilty to wire fraud (18 U.S.C. § 1343) in the U.S. District Court for the Northern District of West Virginia; the plea was announced by U.S. Attorney Matthew L. Harvey around July 14-15, 2026. U.S. Magistrate Judge James P. Mazzone presided over the plea proceeding; Assistant U.S. Attorney Jarod Douglas is prosecuting; the West Virginia State Police investigated.
Pierce faces up to 20 years in federal prison, with sentencing to be determined by a federal district court judge under the U.S. Sentencing Guidelines; no sentencing date/outcome had been reported as of the available sources. The person who actually compromised the email account and initiated the fraudulent request was not identified/charged in the reporting reviewed, only Pierce (the receiving/mule-account holder) faced charges.
This case shows how business email compromise reaches beyond large corporations to small nonprofit and government-adjacent economic development organizations that manage real capital-project vendor payments, and that plausible project context (a real solar installation on a real redevelopment building) is often enough to get a payment approved without a verification callback.
It also illustrates the money-mule layer of BEC economics: the person prosecuted was not the (unidentified) email-compromise operator but the individual who supplied a personal bank account to receive and immediately launder the stolen funds, showing how law enforcement can build a federal wire fraud case around the domestic financial end of a scheme even when the actual intrusion/spoofing actor is never identified.
Call-back verification of any changed payment/banking instructions using an independently sourced (not emailed) phone number for the vendor; mandatory dual-approval and out-of-band confirmation for wire transfers tied to capital projects; treating any request to route payment to a new or unfamiliar bank account as a hard stop requiring verification; vendor-side email account hardening (MFA, login-anomaly monitoring) since the compromise reportedly originated in a legitimate email account rather than a spoofed lookalike domain; staff training for nonprofit/finance-office personnel on BEC red flags around known ongoing projects; bank-side monitoring for mule-account patterns (rapid inbound transfer followed by rapid outbound sweep and account depletion), which is what ultimately exposed Pierce's role.
Social Engineering Examples. “RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud”. Accessed 19 September 2026. https://socialengineeringexamples.com/red-wheeling-bec-solar-panel-vendor-fraud-2024
RED's active capital projects, including the Horne's Department Store redevelopment and its solar-panel installation, are the kind of detail typically visible through board minutes, grant announcements, and local press, information a perpetrator likely drew on to make a fraudulent invoice request tied to that specific project sound credible.
A nonprofit's active capital projects are hard to keep fully private since they typically surface in board minutes, grant announcements, or local coverage. The realistic control is to assume project details are knowable to outsiders and require verification on any payment request tied to a known project, rather than trying to suppress the information.
the perpetrator gained control of, or otherwise obtained the ability to send from, a compromised email address associated with RED or its vendor relationship. DOJ's language ("compromised email address") points to account takeover, consistent with typical BEC techniques like credential phishing or password reuse against a mailbox, rather than a spoofed lookalike domain.
Vendor and partner email-account hardening, including mandatory MFA, conditional access policies, and login-anomaly alerting, reduces the odds that an outside party can take over or convincingly use a legitimate mailbox to originate fraudulent requests.
separately, the perpetrator recruited or arranged for Terry Pierce to supply a personal checking account's routing number to receive the fraudulent payment, a standard BEC pattern of routing stolen funds through a domestic money mule to distance the scheme's operator from the money trail.
Bank account-opening and know-your-customer checks can catch some mule accounts early, but recruitment of willing or coerced mules is difficult to prevent upstream. The more reliable control sits downstream at Stage 6, where transaction-pattern monitoring can flag mule behavior after the account is already in use.
using the compromised email address, the attacker sent RED a payment request for solar panel installation work purportedly completed on the Horne's building, tying the ask to genuine ongoing project work and directing that funds be sent to Pierce's account rather than the real vendor's.
Staff training for finance-office personnel on BEC red flags, specifically treating any request to introduce or change payment or banking details as suspicious regardless of how plausible the surrounding project context is, would have flagged this message before payment was processed.
RED processed the request as routine vendor correspondence and wired $30,750 without an independent, phone-based confirmation call to the vendor, completing the fraudulent redirect.
Mandatory call-back verification of any new or changed banking instructions, using an independently sourced phone number for the vendor rather than any contact information in the email itself, combined with dual-approval for wire transfers, would likely have caught the mismatch between the purported vendor and Pierce's personal account before the money moved.
within two days of receiving the funds, Pierce moved them into another account he controlled and depleted the balance, a typical mule-account layering step meant to frustrate bank recall attempts and complicate tracing.
Bank-side transaction monitoring for classic mule patterns, a rapid large inbound transfer followed quickly by an outbound sweep that empties the account, can flag and potentially freeze funds before they are fully dispersed, and is what ultimately helped expose Pierce's role here.
the funds were extracted, and the West Virginia State Police investigation subsequently tied Pierce's account to additional fraudulent activity beyond the RED payment, totaling roughly $220,000 in actual or intended loss, indicating the same mule infrastructure was likely reused across multiple schemes before it was shut down.
Once funds are dispersed and a mule's account is tied to multiple schemes, the realistic control shifts from prevention to detection and prosecution. Cross-case fraud-pattern investigation by law enforcement, as the West Virginia State Police carried out here, is what identifies a repeat mule before further victims are hit.
Browse by what this case has in common with others in the library.
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
Impersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
Impersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to…
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.
Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".