A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an "imposter scam executed in conjunction with bank fraud," recovering only $336,299 by the following quarter despite same-day bank, FBI, and insurer engagement.
Reviewed by the Social Engineering Examples team.
On February 10, 2026, SCI Engineered Materials, Inc. (OTCQB: SCIA), a small Columbus, Ohio-based manufacturer of physical-vapor-deposition thin-film materials, filed a Form 8-K (and a same-day 8-K/A correcting only an exhibit title) disclosing under Item 8.01 that it "was subjected to an imposter scam of $898,325 executed in conjunction with bank fraud." Per the filing, management contacted the company's financial institution and filed a report with the FBI's Internet Crime Complaint Center (IC3) immediately upon recognizing the event, and began working with its insurance carrier to pursue recovery. SCI stated it found no evidence of additional fraudulent activity and did not believe the incident led to unauthorized access to company data or systems, though an investigation into the incident's impact on internal controls remained ongoing. The company's subsequent Form 10-Q for Q1 2026 disclosed that $336,299 of the $898,325 had been recovered as of April 30, 2026, leaving a net fraud expense of $562,026 recognized in that quarter's results, a sum large enough to materially distort the quarter's operating-expense comparison versus the prior year.
SCI's own disclosures use only the phrase "imposter scam ... executed in conjunction with bank fraud" and do not name the impersonated party, the specific lure, the payment rail, or the receiving bank/account. That phrasing is the standard shorthand smaller issuers use for the classic BEC fact pattern in which a fraudster poses as a trusted counterparty (a company executive authorizing an urgent transfer, a vendor announcing new remittance/bank details, or a bank representative "verifying" account information) to induce finance staff to redirect an outbound wire or ACH payment to an attacker-controlled account, with the "bank fraud" element indicating the fraudulent instructions were carried out through the banking/wire system itself. Because SCI has not published forensic details (no indictment, no FBI press release specific to this case, no named suspect), the exact impersonation channel and pretext cannot be verified beyond the company's own characterization. This record treats the executive-impersonation/vendor-impersonation mechanism as the standard interpretation of "imposter scam plus bank fraud," not as a confirmed, itemized fact.
Not itemized in any primary source: SCI did not disclose the actual email, invoice, or call script used, nor the "tell" that led it to recognize the fraud. In the equivalent, well-documented BEC pattern this label describes, the lure is typically a spoofed or lookalike email from a "CEO"/finance executive or a hijacked vendor thread announcing urgent, confidential, or after-hours payment instructions with new/changed bank details; the giveaway is usually a payment-detail change delivered only by email with no verified callback, unusual urgency/secrecy language, or a slightly altered sender domain. None of these specifics have been confirmed for the SCI incident by SEC filings, the company's press release, or contemporaneous news coverage, all of which repeat the same short disclosure paragraph verbatim.
SCI reported it contacted its bank and filed an FBI IC3 report immediately upon discovering the fraud, and engaged its insurance carrier to pursue recovery. As of the Q1 2026 Form 10-Q (period ended March 31, 2026, filed May 1, 2026), the company had recovered $336,299 of the $898,325, recording a net fraud expense of $562,026 that quarter (versus $770,275 in total operating expenses for the year-earlier quarter), showing the fraud's material weight on a small-cap issuer's results. SCI stated it found no evidence of additional fraudulent activity or unauthorized access to its data/systems, and that day-to-day business and operations were unaffected. An investigation into the incident's effect on internal controls remained open as of the most recent filing reviewed; no insurance payout, law-enforcement case outcome, or arrest has been publicly reported.
This case is a clean, primary-sourced example of how a routine, high-volume fraud technique (an "imposter scam plus bank fraud," the SEC-filing shorthand for business email compromise / payment-redirection fraud) can materially hit even a small, thinly staffed public company almost $900,000 in a single event, enough to require its own disclosure paragraph and line item in quarterly financial statements. It also shows the limits of a fast, textbook incident response: same-day bank notification, an FBI IC3 report, and insurer engagement recovered only about 37% of the stolen funds by the time the next quarterly report was filed, illustrating that once BEC/imposter-scam funds clear through the banking system, recovery is neither fast nor assured even when every recommended step is taken quickly. For an educational site, it is also a good illustration of what public disclosure of BEC actually reveals (and does not reveal): SEC Item 8.01 filings for this fraud type are frequently short and non-forensic, giving investors a dollar figure and a response summary without naming the impersonated party, the lure, or the destination account, information a rigorous case record has to flag as unconfirmed rather than infer.
SCI's public response (the only defensive detail it disclosed): immediate notification of its bank, an FBI IC3 report, and engagement of its insurance carrier, followed by an ongoing internal-controls investigation. Standard BEC countermeasures relevant to this pattern (not stated as SCI's own program, offered as sector guidance): dual-control/dual-approval on outbound wires above a threshold, mandatory callback verification of any payment-instruction change using an independently sourced phone number (never one supplied in the request), positive-pay and same-day debit alerts with the bank, out-of-band confirmation for any executive request to rush or keep a payment confidential, and cyber-crime insurance riders that explicitly cover social-engineering-induced wire fraud (recovery here was partial even with fast law-enforcement and bank engagement, underscoring that post-fraud recall requests often fail once funds clear).
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…
Scammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect, then used a lookalike…