City Sent $913,839 to Fake Vendor Before Anyone Realized It Was a Scam

E-mail spam phishing scammer concept
Image Credit: Shutterstock.

A California city sent nearly $1 million to a fraudulent bank account after scammers impersonated one of its known vendors, turning what appeared to be a routine payment into an international cybercrime investigation.

The City of Pittsburg made an unauthorized ACH payment of $913,839.81 on February 12. According to CBS News Bay Area, the receiving account had been made to appear as though it belonged to a vendor the city already knew.

City staff discovered the payment was fraudulent on February 17, five days after the money was sent. Pittsburg police moved to freeze the receiving account, helping recover $696,241 before all of the money disappeared.

The investigation has since stretched well beyond California. City officials say the primary suspect believed to have compromised Pittsburg’s email system is based in Nigeria, while investigators have identified at least two suspected associates in the United States.

Police Recovered More Than $696,000

Police Officer
Image Credit: Shutterstock.

The scheme relied on one of the most damaging forms of business email fraud, making a fraudulent payment request appear to involve an organization the victim already does business with.

In Pittsburg’s case, officials said the $913,839.81 ACH payment went to a fraudulent account spoofing a known city vendor. The money left the city’s control on February 12, and staff did not recognize the transaction as fraudulent until February 17.

Once city employees identified the payment as fraudulent, Pittsburg police were notified. The department contacted Contra Costa County authorities and the FBI. Police Chief Phil Galer said the receiving account was immediately frozen after the fraud was discovered.

That response helped authorities recover $696,241 of the original payment. The city is pursuing an insurance claim for the approximately $217,598 that remains unrecovered. Whether Pittsburg ultimately absorbs that remaining loss will depend in part on the outcome of its cyber and crime insurance claim.

The Investigation Reached Nigeria and U.S. Suspects

Investigators have obtained 18 search warrants involving 116 accounts associated with technology companies, financial institutions and telecommunications providers as they attempt to trace the people and infrastructure behind the scheme.

City officials said evidence points to a primary suspect in Nigeria who was responsible for compromising Pittsburg’s email system. Investigators have also identified at least two people in the United States suspected of being criminally connected to the operation. The FBI and U.S. Attorney’s Office have accepted the case, and officials said the investigation remains active.

The City Waited Nearly Six Months to Disclose the Fraud

Officials said investigators had reached a point by early August where releasing information about the fraud would no longer jeopardize the investigation. The city disclosed the incident on August 5.

Following the loss, Pittsburg implemented stronger internal controls for financial transactions. Officials said the changes included improvements to ACH payment verification, modifications to financial workflows and changes to IT staffing.

Mayor Dionne Adams described the fraud as an upsetting lesson for the city and said criminals had been able to exploit its systems. Investigators are still working to identify everyone behind the operation and determine whether the remaining money can be recovered.

Verify Every Change to Vendor Payment Instructions

A familiar vendor name or an email that appears to come from an existing business relationship should not be enough to authorize a change in banking information. The FBI’s Internet Crime Complaint Center recommends using a secondary communication channel to verify requests involving changes to account information. Employees should contact the vendor through a telephone number already on file rather than a number supplied in the email requesting the change.

Organizations can also require approval from a second employee before large payments or changes to vendor banking details are processed. Email accounts used by finance employees should have multifactor authentication, and unusual login activity or changes to mailbox rules should be investigated.

If a fraudulent ACH or wire payment has already been sent, the FBI says speed is critical. The sending financial institution should be contacted immediately and asked to recall or freeze the funds, while the incident should be reported to law enforcement and IC3.gov. Emails, invoices, account information and transaction records should be preserved for investigators.