Case Library / Phishing / SCI Engineered Materials $898,325 Imposter Scam / Bank Fraud (2026)
Phishing Confirmed

SCI Engineered Materials $898,325 Imposter Scam / Bank Fraud (2026)

A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an "imposter scam executed in conjunction with bank fraud," recovering only $336,299 by the following quarter despite same-day bank, FBI, and insurer engagement.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On February 10, 2026, SCI Engineered Materials, Inc. (OTCQB: SCIA), a small Columbus, Ohio-based manufacturer of physical-vapor-deposition thin-film materials, filed a Form 8-K (and a same-day 8-K/A correcting only an exhibit title) disclosing under Item 8.01 that it "was subjected to an imposter scam of $898,325 executed in conjunction with bank fraud." Per the filing, management contacted the company's financial institution and filed a report with the FBI's Internet Crime Complaint Center (IC3) immediately upon recognizing the event, and began working with its insurance carrier to pursue recovery. SCI stated it found no evidence of additional fraudulent activity and did not believe the incident led to unauthorized access to company data or systems, though an investigation into the incident's impact on internal controls remained ongoing. The company's subsequent Form 10-Q for Q1 2026 disclosed that $336,299 of the $898,325 had been recovered as of April 30, 2026, leaving a net fraud expense of $562,026 recognized in that quarter's results, a sum large enough to materially distort the quarter's operating-expense comparison versus the prior year.

How the Attack Worked

SCI's own disclosures use only the phrase "imposter scam ... executed in conjunction with bank fraud" and do not name the impersonated party, the specific lure, the payment rail, or the receiving bank/account. That phrasing is the standard shorthand smaller issuers use for the classic BEC fact pattern in which a fraudster poses as a trusted counterparty (a company executive authorizing an urgent transfer, a vendor announcing new remittance/bank details, or a bank representative "verifying" account information) to induce finance staff to redirect an outbound wire or ACH payment to an attacker-controlled account, with the "bank fraud" element indicating the fraudulent instructions were carried out through the banking/wire system itself. Because SCI has not published forensic details (no indictment, no FBI press release specific to this case, no named suspect), the exact impersonation channel and pretext cannot be verified beyond the company's own characterization. This record treats the executive-impersonation/vendor-impersonation mechanism as the standard interpretation of "imposter scam plus bank fraud," not as a confirmed, itemized fact.

The Lure & the Tell

Not itemized in any primary source: SCI did not disclose the actual email, invoice, or call script used, nor the "tell" that led it to recognize the fraud. In the equivalent, well-documented BEC pattern this label describes, the lure is typically a spoofed or lookalike email from a "CEO"/finance executive or a hijacked vendor thread announcing urgent, confidential, or after-hours payment instructions with new/changed bank details; the giveaway is usually a payment-detail change delivered only by email with no verified callback, unusual urgency/secrecy language, or a slightly altered sender domain. None of these specifics have been confirmed for the SCI incident by SEC filings, the company's press release, or contemporaneous news coverage, all of which repeat the same short disclosure paragraph verbatim.

Outcome

SCI reported it contacted its bank and filed an FBI IC3 report immediately upon discovering the fraud, and engaged its insurance carrier to pursue recovery. As of the Q1 2026 Form 10-Q (period ended March 31, 2026, filed May 1, 2026), the company had recovered $336,299 of the $898,325, recording a net fraud expense of $562,026 that quarter (versus $770,275 in total operating expenses for the year-earlier quarter), showing the fraud's material weight on a small-cap issuer's results. SCI stated it found no evidence of additional fraudulent activity or unauthorized access to its data/systems, and that day-to-day business and operations were unaffected. An investigation into the incident's effect on internal controls remained open as of the most recent filing reviewed; no insurance payout, law-enforcement case outcome, or arrest has been publicly reported.

Why It Matters

This case is a clean, primary-sourced example of how a routine, high-volume fraud technique (an "imposter scam plus bank fraud," the SEC-filing shorthand for business email compromise / payment-redirection fraud) can materially hit even a small, thinly staffed public company almost $900,000 in a single event, enough to require its own disclosure paragraph and line item in quarterly financial statements. It also shows the limits of a fast, textbook incident response: same-day bank notification, an FBI IC3 report, and insurer engagement recovered only about 37% of the stolen funds by the time the next quarterly report was filed, illustrating that once BEC/imposter-scam funds clear through the banking system, recovery is neither fast nor assured even when every recommended step is taken quickly. For an educational site, it is also a good illustration of what public disclosure of BEC actually reveals (and does not reveal): SEC Item 8.01 filings for this fraud type are frequently short and non-forensic, giving investors a dollar figure and a response summary without naming the impersonated party, the lure, or the destination account, information a rigorous case record has to flag as unconfirmed rather than infer.

Defenses

SCI's public response (the only defensive detail it disclosed): immediate notification of its bank, an FBI IC3 report, and engagement of its insurance carrier, followed by an ongoing internal-controls investigation. Standard BEC countermeasures relevant to this pattern (not stated as SCI's own program, offered as sector guidance): dual-control/dual-approval on outbound wires above a threshold, mandatory callback verification of any payment-instruction change using an independently sourced phone number (never one supplied in the request), positive-pay and same-day debit alerts with the bank, out-of-band confirmation for any executive request to rush or keep a payment confidential, and cyber-crime insurance riders that explicitly cover social-engineering-induced wire fraud (recovery here was partial even with fast law-enforcement and bank engagement, underscoring that post-fraud recall requests often fail once funds clear).

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: Not itemized by SCI, but consistent with the standard BEC/imposter-scam pattern this filing describes, attackers targeting a small public issuer would typically research the company through its SEC filings, corporate website, and staff LinkedIn profiles to identify finance-team members, executives, and vendor relationships, and to infer the company's banking and payment-approval routines.
Countering Stage 1: Public-company and employee-facing OSINT exposure (SEC filings, corporate websites, LinkedIn roles) is very hard to eliminate, especially for a small issuer required to disclose officer names and financial detail; the realistic control assumes attackers already have this information and hardens the downstream payment-approval process rather than trying to hide it.
2
Pretext and infrastructure setup: Likely precursor steps for this fraud type include registering a look-alike domain or compromising/spoofing an email account belonging to an executive, vendor, or bank contact, so that outreach appears to come from a trusted source; SCI's use of the phrase 'bank fraud' suggests the payment or banking channel itself was also spoofed or manipulated, though the exact method is not disclosed.
Countering Stage 2: Domain-monitoring and brand-protection services to catch look-alike domain registrations, plus enforced email-authentication controls (SPF, DKIM, DMARC) and external-sender warning banners, reduce the odds a spoofed or lookalike message reaches finance staff undetected.
3
Initial contact and lure delivery: A fraudulent communication impersonating a trusted counterparty (a company executive, a known vendor, or a bank representative) was delivered to SCI finance staff, consistent with the classic BEC lure though the specific channel and script were not disclosed.
Countering Stage 3: Regular social-engineering and phishing-recognition training for finance and executive-support staff, paired with technical email filtering, is the standard control against a fraudulent impersonation message actually landing and being acted on.
4
Urgency and secrecy framing: Typical of this fraud pattern, the pretext likely applied pressure through urgency and/or confidentiality framing (e.g., an urgent, time-sensitive payment or a request to keep the transaction quiet) to discourage independent verification, though SCI did not itemize this element for its own case.
Countering Stage 4: A firm-wide policy that urgency or confidentiality framing on a payment request is itself a red flag, not a reason to skip verification, removes the psychological lever this fraud pattern typically relies on.
5
Fraudulent payment authorization: SCI finance staff authorized an outbound wire or ACH transfer totaling $898,325 to an attacker-controlled account, executed through the banking system, which SCI's filings characterize as the 'bank fraud' component of the incident.
Countering Stage 5: Dual-control/dual-approval requirements on outbound wires above a set threshold and mandatory callback verification of any new or changed payment instructions, using a phone number sourced independently rather than one supplied in the request itself, are the standard controls that stop this exact step before funds leave the company.
6
Fund movement and layering: Once received, the funds were likely moved rapidly through intermediary or mule accounts, a common step in this fraud type intended to outrun bank recall requests and law-enforcement freezes; this would help explain why only $336,299 (about 37%) had been recovered by the time SCI's Q1 2026 10-Q was filed months later.
Countering Stage 6: Positive-pay and same-day debit alerts with the bank, plus immediate fraud reporting to the bank and FBI IC3 (which SCI did do), can trigger a recall or freeze before funds fully clear through intermediary accounts, though recovery is not guaranteed even with fast action, as this case shows.
7
Objective completion: The unrecovered balance, a net fraud expense of $562,026 as of the most recent filing, represents funds the attacker(s) appear to have successfully retained, completing the theft objective; no arrest, indictment, or full recovery has been publicly reported.
Countering Stage 7: Cyber-crime insurance riders that explicitly cover social-engineering-induced wire fraud, and continued law-enforcement engagement for asset tracing and prosecution, are the realistic backstops for the portion of funds that intermediary-account layering has already placed out of reach; SCI engaged its insurer for this purpose, though no payout has been publicly disclosed.
Quick Facts
Victim
SCI Engineered Materials, Inc. (OTCQB: SCIA), a Columbus, Ohio-based global supplier and manufacturer of advanced materials for physical vapor deposition (PVD) thin-film applications serving aerospace, defense, automotive, semiconductor, and solar customers.
Location
Columbus, Ohio, USA (SCI Engineered Materials headquarters)
Date
2026-02-10
Impact
$898,325 gross loss disclosed February 10, 2026 ("imposter scam ... executed in conjunction with bank fraud"). SCI's Q1 2026 Form 10-Q reports $336,299 recovered as of April 30, 2026, leaving a net fraud expense of $562,026 recognized in Q1 2026 operating expenses. No insurance payout amount, additional recovery, or final loss figure has been publicly disclosed as of the most recent filing reviewed.
Status
Confirmed
Case Type
Real-World Incident
Sector
Defense & Aerospace, Manufacturing & Industrial
Related

Related Cases

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…

Incident 2026Read →

PROMPTSTEAL/LAMEHUG: APT28's LLM-Powered Malware Against Ukraine

Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…

Incident 2025Read →

Pine Bluff School District $3.2M Construction-Payment BEC (Thread-Hijack via Lookalike Vendor Domain)

Scammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect, then used a lookalike…

Incident 2025Read →