Typo-Squatting Scammers Con South Carolina Town Out of $545K (wpde.com)
(Sunday July 26, 2026 @11:39AM (EditorDavid)
from the you-can-fight-city-hall dept.)
- Reference: 0184693480
- News link: https://yro.slashdot.org/story/26/07/26/0138257/typo-squatting-scammers-con-south-carolina-town-out-of-545k
- Source link: https://wpde.com/news/local/surfside-beach-releases-findings-from-fraud-investigation-microsoft-365-wildcat-contractors-constangy-brooks-smith-prophete-llp
It started with some underground utility work for the South Carolina town of Surfside Beach (population: 4,155). "Public records confirm that a payment of $545,598.30 was issued," according to [1]a local news station — but the CEO of Wildcat Contractors "stated that the account that received the money is a scammer account and that his company has an overdue invoice for underground utility work completed in Surfside Beach."
[2]Yahoo picks up the story :
> After the payment issue surfaced, Wildcat said Surfside Beach sent over the email thread containing the payment confirmation. The company [3]told WMBF it noticed multiple red flags in the chain. One involved an email address where "Wildcat" appeared with an extra "i." Another involved documents that the company said included a forged signature taken from a prior notarized document. Wildcat said the money was sent to a spoofing account claiming to be the contractor.
More [4]local reports are unraveling what happened :
> According to the Wall Street Journal, the town's finance director said a town employee called Wildcat's project manager on March 13, the day the payment was sent. The project manager referred the caller to [Wildcat CEO] Bowker. The town then called Bowker's mobile phone and left a voicemail about the ACH transfer. Bowker told the Wall Street Journal she does not recall the voicemail but acknowledged she may have missed it.
Now a new report released by a law firm hired by the town to investigate "shows it did [5]make an attempt to verify before sending $545,000 to a fraudulent bank account," according to local news reports:
> According to the report, the town sent an email to Wildcat's legitimate email domain on March 13 requesting a callback for verbal verification before sending the payment. Surfside received a response to that email with a phone number, though it remains unclear whether that response came from a real Wildcat employee or from the scammers. The report found that the fake town domain was used in communications between both parties throughout the process, which the law firm overseeing the investigation said was likely created to facilitate the fraud and delay its discovery.
That [6]seems to be the case in a nutshell :
> Investigators determined the fraudsters used spoofed and typo-squatted email domains, including surfsidesbeach.org, to impersonate town officials and redirect the payment. The fraudulent domain was created March 9 and was used to help conceal the scheme, according to investigators. Town officials said they are continuing to work with the FBI, South Carolina Law Enforcement Division, and their insurance partners to recover the funds.
"The town has also implemented additional security measures to strengthen payment verification procedures and reduce the risk of similar incidents."
[1] https://www.wbtw.com/news/grand-strand/surfside-beach/retired-fbi-agent-says-surfside-beach-potential-cybersecurity-threat-isnt-typical-phishing-attack/
[2] https://www.yahoo.com/news/us/articles/real-contractor-waiting-surfside-beach-194255795.html
[3] https://www.wmbfnews.com/2026/05/14/sled-investigating-after-surfside-beach-sent-more-than-500k-fraudulent-account/
[4] https://www.wmbfnews.com/2026/07/24/wildcat-construction-ceo-disputes-surfside-beach-forensic-report-findings-545000-fraud-case/
[5] https://www.wmbfnews.com/2026/07/22/surfside-beach-did-make-verification-attempt-before-sending-545000-payment-report-shows/
[6] https://wpde.com/news/local/surfside-beach-releases-findings-from-fraud-investigation-microsoft-365-wildcat-contractors-constangy-brooks-smith-prophete-llp
[2]Yahoo picks up the story :
> After the payment issue surfaced, Wildcat said Surfside Beach sent over the email thread containing the payment confirmation. The company [3]told WMBF it noticed multiple red flags in the chain. One involved an email address where "Wildcat" appeared with an extra "i." Another involved documents that the company said included a forged signature taken from a prior notarized document. Wildcat said the money was sent to a spoofing account claiming to be the contractor.
More [4]local reports are unraveling what happened :
> According to the Wall Street Journal, the town's finance director said a town employee called Wildcat's project manager on March 13, the day the payment was sent. The project manager referred the caller to [Wildcat CEO] Bowker. The town then called Bowker's mobile phone and left a voicemail about the ACH transfer. Bowker told the Wall Street Journal she does not recall the voicemail but acknowledged she may have missed it.
Now a new report released by a law firm hired by the town to investigate "shows it did [5]make an attempt to verify before sending $545,000 to a fraudulent bank account," according to local news reports:
> According to the report, the town sent an email to Wildcat's legitimate email domain on March 13 requesting a callback for verbal verification before sending the payment. Surfside received a response to that email with a phone number, though it remains unclear whether that response came from a real Wildcat employee or from the scammers. The report found that the fake town domain was used in communications between both parties throughout the process, which the law firm overseeing the investigation said was likely created to facilitate the fraud and delay its discovery.
That [6]seems to be the case in a nutshell :
> Investigators determined the fraudsters used spoofed and typo-squatted email domains, including surfsidesbeach.org, to impersonate town officials and redirect the payment. The fraudulent domain was created March 9 and was used to help conceal the scheme, according to investigators. Town officials said they are continuing to work with the FBI, South Carolina Law Enforcement Division, and their insurance partners to recover the funds.
"The town has also implemented additional security measures to strengthen payment verification procedures and reduce the risk of similar incidents."
[1] https://www.wbtw.com/news/grand-strand/surfside-beach/retired-fbi-agent-says-surfside-beach-potential-cybersecurity-threat-isnt-typical-phishing-attack/
[2] https://www.yahoo.com/news/us/articles/real-contractor-waiting-surfside-beach-194255795.html
[3] https://www.wmbfnews.com/2026/05/14/sled-investigating-after-surfside-beach-sent-more-than-500k-fraudulent-account/
[4] https://www.wmbfnews.com/2026/07/24/wildcat-construction-ceo-disputes-surfside-beach-forensic-report-findings-545000-fraud-case/
[5] https://www.wmbfnews.com/2026/07/22/surfside-beach-did-make-verification-attempt-before-sending-545000-payment-report-shows/
[6] https://wpde.com/news/local/surfside-beach-releases-findings-from-fraud-investigation-microsoft-365-wildcat-contractors-constangy-brooks-smith-prophete-llp
$545k? (Score:2)
by PPH ( 736903 )
Pikers.
Just take a look at the KCRHA.
Terrible (Score:3)
by LindleyF ( 9395567 )
Someone should report this to fbi.org!
It's amazing this doesn't happen more often (Score:5, Insightful)
If I was going to transfer over half a million dollars, the sensible thing to do would be to first transfer and verify a small sum to make sure the account numbers are correct.
Aside from typo-squatting, even under the best of circumstances, wire/ACH transfers seem extremely error prone. They rely on somebody transcribing a long series of numbers and lack any kind of robust authentication. There should be a more reliable way to transfer these large sums, but with the current system one should always verify by first transferring a small sum.
Re: (Score:2)
Yep. Even using "positive pay" isn't 100% helpful, if you enter a bad/scam account number. No matter what, some due diligence is needed on the part of accounts payable.
Usually when working with a new vendor, the vendor will send instructions for payment (often ACH). I suppose it should be possible to contact that bank (or maybe your own bank) and verify the owner of the account, making sure it matches the corporate name/address, before setting up the vendor in the AP system and sending money.
Re: (Score:3)
The reliable way was always to write a paper check that is handed between the two parties in person. Both get to verify the amount and destination is correct.
With digital numbers it is so much easier and safer to be a faceless thief.
Re: (Score:2)
Yes, paper check if the vendor will accept it. And paper checking still a free service (Chase will create the check for you, you only have to put vendor address and contact info). ACH charges 1 percent.
Re: (Score:2)
> If I was going to transfer over half a million dollars, the sensible thing to do would be to first transfer and verify a small sum to make sure the account numbers are correct.
The town has a population of around 4200. I would guess the entire town staff is small in number and likely long term employees. I would not be surprised that being scammed was not even on their radar (that is what happens in the big city, not our safe small town). This should be a wake up call that all towns, no matter how small, need to make sure they follow the best practices.
Re: (Score:2)
> Aside from typo-squatting, even under the best of circumstances, wire/ACH transfers seem extremely error prone.
Are they actually that error-prone (based on volume), or is this yet another one of those systems that was reliable when a lot more IQ points were being carried around by the average meatsack needing to use them? Is it now too much to ask for a test transfer to verify authenticity and integrity, or are lazy people too lazy to do it now, and we're supposed to blame the system for that human ignorance?
If humanity has proven anything in our idiot-proof era of design..we know how to build a bigger, better idio