SUMMARYSurfside Beach, South Carolina, lost $545,598.30 in a payment scam tied to a contractor invoice for underground utility work. Investigators said fraudsters used spoofed and typo-squatted email domains, including a fake town domain created on March 9, to impersonate officials and steer the ACH transfer to a fraudulent bank account. The town is working with the FBI, state investigators, and insurance partners to recover the money and has added stronger payment verification measures.

It started with some underground utility work for the South Carolina town of Surfside Beach (population: 4,155). "Public records confirm that a payment of $545,598.30 was issued," according to a local news station - but the CEO of Wildcat Contractors "stated that the account that received the money is a scammer account and that his company has an overdue invoice for underground utility work completed in Surfside Beach."

Yahoo picks up the story:

After the payment issue surfaced, Wildcat said Surfside Beach sent over the email thread containing the payment confirmation. The company told WMBF it noticed multiple red flags in the chain. One involved an email address where "Wildcat" appeared with an extra "i." Another involved documents that the company said included a forged signature taken from a prior notarized document. Wildcat said the money was sent to a spoofing account claiming to be the contractor.

More local reports are unraveling what happened: According to the Wall Street Journal, the town's finance director said a town employee called Wildcat's project manager on March 13, the day the payment was sent. The project manager referred the caller to [Wildcat CEO] Bowker. The town then called Bowker's mobile phone and left a voicemail about the ACH transfer. Bowker told the Wall Street Journal she does not recall the voicemail but acknowledged she may have missed it.

Now a new report released by a law firm hired by the town to investigate "shows it did make an attempt to verify before sending $545,000 to a fraudulent bank account," according to local news reports:

According to the report, the town sent an email to Wildcat's legitimate email domain on March 13 requesting a callback for verbal verification before sending the payment. Surfside received a response to that email with a phone number, though it remains unclear whether that response came from a real Wildcat employee or from the scammers. The report found that the fake town domain was used in communications between both parties throughout the process, which the law firm overseeing the investigation said was likely created to facilitate the fraud and delay its discovery.

That seems to be the case in a nutshell:

Investigators determined the fraudsters used spoofed and typo-squatted email domains, including surfsidesbeach.org, to impersonate town officials and redirect the payment. The fraudulent domain was created March 9 and was used to help conceal the scheme, according to investigators. Town officials said they are continuing to work with the FBI, South Carolina Law Enforcement Division, and their insurance partners to recover the funds.

"The town has also implemented additional security measures to strengthen payment verification procedures and reduce the risk of similar incidents."