Summary: How did a scammer steal over $545,000 from a South Carolina town using nothing but an email?
A scammer quietly inserted themselves into a normal email thread about a contractor payment and asked to switch it from a check to an electronic transfer, no malware and no hacked network required, just a lookalike email address and a believable request. This is business email compromise, now one of the costliest cybercrimes in the country, and it worked because everyone involved trusted the thread instead of verifying the request. This article breaks down how the scam worked and the specific controls that stop it.
There was no alarm. No warning screen. No obvious red flag.
A small South Carolina beach town was in the middle of paying a contractor for underground utility work. It was the fourth payment on the project. Routine. The kind of thing that happens in every finance department, every day.
Then someone quietly stepped into the email thread.
Posing as the contractor, they asked to switch the payment from a check to an electronic transfer. The request came from an address that looked right — close enough to pass a quick glance. The town made the change. More than $545,000 went to a fraudulent account. Weeks passed before anyone realized the real contractor never got paid.
This is business email compromise. And it is not rare.
Here is what makes BEC so dangerous: there is often no malware, no ransomware, and no break-in.
In this case, investigators found no evidence that the town's own email systems were breached. The attack worked through the conversation itself. Someone was watching a real email thread, waiting for a payment discussion, and jumped in at the exact right moment with the exact right ask.
That is the whole trick. Attackers do not fight your firewall. They impersonate someone you already trust and make one small, believable request.
The scam used a lookalike domain — an address nearly identical to the legitimate one, with a single character changed. Security researchers call this subtle enough to pass the human eyeball test. Because it does.
Attackers who gain access to an email thread tend to work in the background. They set quiet rules that alert them the moment a payment message appears. They divert the real replies out of sight, so the only version of the conversation anyone sees is the one the scammer is writing.
By the time the money moved, everything looked legitimate: a familiar thread, a reasonable request, a professional-looking form. None of it stopped the payment.
The FBI attributes roughly $3 billion in losses to this exact category of fraud in a single year. It is one of the most financially damaging cybercrimes in the country, and it targets organizations of every size — municipalities, contractors, healthcare providers, law firms, and manufacturers alike.
The losses are rarely recovered. And the fallout does not stop at the dollar amount. There are legal fees, insurance disputes, damaged vendor relationships, and internal blame that can take months to settle.
BEC is a process problem, not just a technology problem. The controls that prevent it are unglamorous and highly effective:
The town did not get hit because someone was careless. They got hit because the attack was designed to look normal. That is the entire point of business email compromise — it hides inside the ordinary.
The organizations that avoid this are not the ones with the most technology. They are the ones with the right verification habits built into how money moves.