Forensic investigators found no intrusion into Surfside Beach's systems. Attackers registered two lookalike domains and inserted themselves into a payment thread already underway.
What happened
The town of Surfside Beach, South Carolina, sent $545,598.30 to a fraudulent account on March 13, 2026, in what was meant to be the fourth payment to Wildcat Contractors for burying overhead power and fiber-optic lines along Ocean Boulevard. Scammers registered a fake domain impersonating the town on March 9, four days before the transfer, and a second domain typo-squatting the contractor's name, according to WBTW. Holding both allowed them to sit between the two parties and control what each side saw. The funds went to an account at American Express National Bank routed through Salt Lake City, Utah. Neither the town nor the contractor noticed for 45 days.
Going deeper
The town did attempt to verify the payment change, which is what makes the case instructive rather than simply careless. Surfside Beach emailed Wildcat's legitimate domain on March 13 requesting a callback for verbal confirmation before releasing the funds, and received a reply containing a phone number, according to a report released by the town and overseen by an outside law firm working with forensic investigators approved by the town's insurer. Whether that reply came from a real Wildcat employee or from the scammers remains unresolved. Investigators found no evidence that anyone compromised the town's Microsoft 365 accounts or internal systems. The report concluded the fake town domain was used in communications with both parties throughout, likely to facilitate the fraud and delay its discovery. Requesting verbal verification was the right instinct, and routing that request back through the same compromised thread undid it.
What was said
"The situation is that the town paid an invoice based on instructions from a legitimate email address," Mayor Robert Krouse said in a weekly newsletter to residents, as reported by WBTW. He maintained that town processes were followed. Wildcat's leadership has disputed the town's account of the verification effort, and four months on, the contractor remains unpaid and has drawn on its own reserves to cover the shortfall.
In the know
The insurance dispute may prove as instructive as the fraud. The town's insurer initially declined to cover the loss because the town had not been found liable, and the town's own attorney later clarified that coverage would apply only if Surfside Beach is found at fault, Insurance Business Magazine reported. Most organizations assume cyber fraud coverage responds to the loss itself rather than to an eventual determination of fault. Because the fraud sat between two parties and compromised neither one's systems, establishing whose failure caused it has become the precondition for any payout, and the two sides are still arguing it in public. Organizations should read their own policy language on funds transfer fraud specifically, since it often sits separate from the main cyber coverage and carries its own sublimits and conditions.
The big picture
Recovery depends almost entirely on speed, and 45 days put this case well past the window. The FBI recovers funds roughly 75% of the time when a fraudulent transfer is reported within 72 hours, and business email compromise generated $3.046 billion in reported losses during 2025, second only to investment fraud in the FBI Internet Crime Complaint Center's annual report. Healthcare organizations run the same workflow that failed here, paying construction contractors, equipment vendors, billing companies, and staffing agencies against emailed invoices, often through finance staff who never meet the counterparty. The defensible control is narrow and cheap. Verification of any banking change must go to a phone number from the signed contract or an existing record, never one supplied inside the thread requesting the change, and the call has to reach a person the organization has spoken to before. Social engineering that inserts an attacker into an existing conversation removes every contextual signal staff normally rely on, since the project, the invoice number, and the payment history are all genuine.
FAQs
What is the FBI's Financial Fraud Kill Chain and how do organizations use it?
It is a process the FBI can initiate to freeze fraudulent domestic wire transfers, generally requiring the transfer to exceed a threshold amount, to be reported quickly, and to involve an international destination or a domestic account tied to one. Victims trigger it by filing with the Internet Crime Complaint Center and contacting their local field office immediately rather than waiting for an internal investigation.
How do attackers learn about a payment relationship without breaching anyone?
Public procurement records, contract awards, council meeting minutes, and permit filings name vendors, project scopes, and payment schedules. For a municipality, most of that is published by law, which gives an attacker enough detail to write a convincing message without touching either party's network.
What is a typo-squatted domain and why do people miss them?
A domain registered to closely resemble a legitimate one through a substituted, added, or omitted character, such as a capital I in place of a lowercase L. Email clients display sender names rather than full addresses by default, and the substitution is often invisible in common fonts.
Does DMARC protect against lookalike domains?
No. DMARC, DKIM, and SPF authenticate messages sent from your own domain and prevent direct spoofing of it. A separate domain registered by an attacker passes those checks legitimately because the attacker controls it, which is why domain monitoring and display-name warnings address a gap authentication cannot.
What should finance teams change after reading a case like this?
Require dual authorization for any change to vendor banking details, verify by outbound call to a number held on file rather than one received, document the verification in the payment record, and set an expectation that no urgency justifies skipping the step. Confirming receipt with the vendor within days rather than at the next invoice cycle also shortens the discovery window.
