Summary: How did a scammer steal over $545,000 from a South Carolina town using nothing but an email?
A scammer quietly inserted themselves into a normal email thread about a contractor payment and asked to switch it from a check to an electronic transfer, no malware and no hacked network required, just a lookalike email address and a believable request. This is business email compromise, now one of the costliest cybercrimes in the country, and it worked because everyone involved trusted the thread instead of verifying the request. This article breaks down how the scam worked and the specific controls that stop it.
The $545,000 Email That Looked Completely Normal
There was no alarm. No warning screen. No obvious red flag.
A small South Carolina beach town was in the middle of paying a contractor for underground utility work. It was the fourth payment on the project. Routine. The kind of thing that happens in every finance department, every day.
Then someone quietly stepped into the email thread.
Posing as the contractor, they asked to switch the payment from a check to an electronic transfer. The request came from an address that looked right — close enough to pass a quick glance. The town made the change. More than $545,000 went to a fraudulent account. Weeks passed before anyone realized the real contractor never got paid.
This is business email compromise. And it is not rare.

No Hacking Required
Here is what makes BEC so dangerous: there is often no malware, no ransomware, and no break-in.
In this case, investigators found no evidence that the town's own email systems were breached. The attack worked through the conversation itself. Someone was watching a real email thread, waiting for a payment discussion, and jumped in at the exact right moment with the exact right ask.
That is the whole trick. Attackers do not fight your firewall. They impersonate someone you already trust and make one small, believable request.

The Details That Fooled Everyone
The scam used a lookalike domain — an address nearly identical to the legitimate one, with a single character changed. Security researchers call this subtle enough to pass the human eyeball test. Because it does.
Attackers who gain access to an email thread tend to work in the background. They set quiet rules that alert them the moment a payment message appears. They divert the real replies out of sight, so the only version of the conversation anyone sees is the one the scammer is writing.
By the time the money moved, everything looked legitimate: a familiar thread, a reasonable request, a professional-looking form. None of it stopped the payment.
Why This Should Worry Every Business
The FBI attributes roughly $3 billion in losses to this exact category of fraud in a single year. It is one of the most financially damaging cybercrimes in the country, and it targets organizations of every size — municipalities, contractors, healthcare providers, law firms, and manufacturers alike.
The losses are rarely recovered. And the fallout does not stop at the dollar amount. There are legal fees, insurance disputes, damaged vendor relationships, and internal blame that can take months to settle.
What Actually Stops It
BEC is a process problem, not just a technology problem. The controls that prevent it are unglamorous and highly effective:
-
Verify payment changes out of band.
Any request to change bank details or switch payment methods gets confirmed by a phone call to a known number — never a number in the email.
-
Require dual approval for payment changes.
One person should never be able to redirect funds alone.
-
Turn on email authentication and monitoring.
Lookalike-domain detection and layered email security catch what the human eye misses.
-
Train the people who touch money.
Finance and ops staff are the real front line. They need to know exactly what these requests look like.
-
Have a plan before it happens.
Fast detection and a rehearsed response are the difference between a scare and a six-figure loss.

The Real Lesson
The town did not get hit because someone was careless. They got hit because the attack was designed to look normal. That is the entire point of business email compromise — it hides inside the ordinary.
The organizations that avoid this are not the ones with the most technology. They are the ones with the right verification habits built into how money moves.
Not sure whether a request like this would get caught before the money left your accounts? A short payment-security review will show you where the gaps are.