A Phishing Email Changed a Company’s Payment Info, Then $63,599 Was Sent to Her Accounts, Police Say

Kiyah Ashante Holman
Image Credit: Midland Police Department.

A phishing email that appeared to come from a real business client led an employee to change payment information, and police say the mistake ultimately redirected more than $63,000 toward bank accounts linked to a Michigan woman.

Kiyah Ashante Holman, 50, of Ypsilanti, Michigan, has been arrested in connection with the theft investigation in Midland, Texas. Authorities say the case began with a fraudulent email months before police were notified.

According to an arrest affidavit, 10 electronic payments totaling $63,599.38 were redirected after an employee changed the payment information associated with a business client. Later bank records identified nine deposits totaling $62,042.05 going into an account police say belonged solely to Holman, creating a discrepancy the affidavit does not publicly explain.

First Alert 7 reported that Holman is charged with theft of property valued at $30,000 or more but less than $150,000. The charge is pending, and the allegations against her have not been established by a conviction.

An Email Appeared to Come From a Business Client

 

The payment problem traced back to Oct. 31, 2025. According to the affidavit, a company employee received what appeared to be an email from one of the business’s clients asking for changes to the account information used to receive payments.

The employee believed the request was legitimate and changed the account receiving the client’s payments. Current and future electronic payments were then directed using the new banking information supplied through the email.

The problem was not discovered immediately. The company learned something was wrong only after receiving a call on Feb. 11 from a business saying it had not received outstanding payments, according to the affidavit. That prompted a closer look at where the money had actually been going.

The theft was reported to Midland police on Feb. 24, nearly four months after the original payment-information change. Investigators then began tracing the electronic transfers and identifying the account or accounts that had received them.

Ten Payments Added Up to $63,599.38

The arrest affidavit initially lists 10 electronic payments totaling $63,599.38. The transactions were not all large. They ranged from a payment of just $30 to another exceeding $17,600. The payments listed in the affidavit were $10,360, $747, $16,710.77, $17,607.33, $30, $3,296.33, $3,116.69, $9,925.34, $248.59 and $1,557.33. Together, those 10 transactions total exactly $63,599.38.

Bank Records Showed Nine Deposits Totaling $62,042.05

Midland police subpoenaed financial records as they tried to determine where the diverted payments went. According to First Alert 7’s account of the affidavit, investigators ultimately identified a bank account that was solely owned by Holman.

Those records showed nine deposits from Permiacare totaling $62,042.05. The nine amounts correspond with nine of the 10 payments initially identified in the case.

The difference between the two totals is $1,557.33, which is also the amount of the tenth payment listed in the affidavit. The affidavit, as described by First Alert 7, does not explain why the initial loss calculation contains 10 transactions totaling $63,599.38 while the later bank-record review identifies nine deposits totaling $62,042.05.

Investigators Used Subpoenas to Follow the Payment Trail

Investigators followed the banking trail after the business discovered the diverted payments and reported the case. The affidavit says police initially subpoenaed records from a mortgage company while searching for the relevant financial information. That subpoena did not produce the bank-account information investigators were seeking.

Authorities then issued another subpoena seeking banking records. Those records led investigators to the account they say was solely owned by Holman and showed the nine deposits totaling $62,042.05. Investigators also obtained what First Alert 7 described as a comprehensive report on Holman in May. According to the affidavit, the report identified four email addresses, with one matching an email address associated with the bank account under investigation.

The report also contained two Social Security numbers, one of which matched information associated with the bank account, as well as multiple mailing addresses and eight driver’s licenses. The affidavit cites those identifying details as part of the investigative trail connecting Holman to the account.

Holman Was Arrested After the Lengthy Investigation

After months of subpoenas and record analysis, authorities arrested Holman in connection with the diverted payments. NewsWest 9 also reported that the Michigan woman had been arrested following the investigation.

First Alert 7 reported that she faces a charge of theft of property valued at $30,000 or more but less than $150,000. Under Texas law, theft within that value range is generally classified as a third-degree felony.

A third-degree felony in Texas can carry a prison term of two to 10 years and a fine of up to $10,000 if a person is convicted, although statutory maximums do not predict what sentence any individual defendant would receive.

Holman has been arrested and charged, not convicted. The allegations in the arrest affidavit remain accusations, and prosecutors would still need to establish the charge through a guilty plea or proof in court.

Businesses Should Never Change Payment Details Based on Email Alone

The FBI specifically advises businesses to verify changes in account numbers or payment procedures with the person or company making the request rather than relying solely on email. That verification should happen through a separate, trusted channel.

If an email says a longtime client’s bank account has changed, employees should call a telephone number already stored in company records or obtained independently from the client’s legitimate website. Companies can also require a second employee to approve changes to vendor or client banking information before the new details become active. 

A business that discovers money has been sent to fraudulent account information should contact its financial institution immediately. The FBI’s Internet Crime Complaint Center advises victims of business email compromise to ask the originating financial institution about a recall or reversal as soon as the fraud is recognized.

The receiving financial institution may also need to be alerted so that any remaining funds can potentially be frozen. Recovery is not guaranteed, particularly after money has been transferred onward, but rapid reporting can improve the chance that some or all of the funds remain accessible. The incident should be reported to the FBI through IC3.gov