The town of Surfside Beach in South Carolina has reportedly lost US$545,598 (approximately ₹4.69 crore) in a sophisticated Business Email Compromise (BEC) cyber fraud. The payment was intended for Wildcat Construction, the contractor executing an underground utility project for the town. However, cybercriminals allegedly used email spoofing and fraudulent banking details to divert the funds into a bank account under their control. An independent forensic investigation has since been launched, while the contractor’s Chief Executive Officer (CEO) has challenged parts of the findings, accusing the town administration of ignoring critical warning signs.
According to investigators, the incident occurred during routine email communications between the town administration and Wildcat Construction regarding payment for completed project work. During the exchange, fraudsters allegedly impersonated a company employee and requested that the payment method be changed from a paper cheque to an Automated Clearing House (ACH) transfer. Believing the request to be genuine, town officials transferred the payment to a bank account in Utah, which investigators say did not belong to the contractor.
The forensic investigation found that the attackers had created fraudulent email domains closely resembling the official domains used by both Surfside Beach and Wildcat Construction. These spoofed email addresses were allegedly used to send the fake payment instructions. Investigators found no evidence that the town’s internal computer systems or its Microsoft 365 accounts had been hacked or compromised, indicating that the fraud relied on social engineering and email impersonation rather than a direct cyber intrusion.
According to the forensic report, the fraudulent payment request arrived while the construction project was active and a legitimate payment was already expected, making the request appear authentic. The forged documents reportedly included updated bank account details, a callback telephone number and a signature resembling that of Wildcat Construction CEO Alyssa Bowker. Before processing the payment, a town employee reportedly attempted to verify the instructions by sending an email to the contractor’s legitimate address. However, investigators said it remains unclear whether the response was received from an authorised company representative or from the fraudsters themselves.
Wildcat Construction CEO Alyssa Bowker has publicly disputed several conclusions of the forensic report. She alleged that the town selectively released emails supporting its own position without establishing whether those messages had actually originated from Wildcat’s servers. Bowker further claimed that no town official directly confirmed the ACH payment change with her or any authorised company representative over the telephone. According to her, verbal confirmation is a standard and essential business safeguard before processing high-value financial transactions.
Town officials, however, maintain that the purpose of the independent forensic investigation was solely to determine whether Surfside Beach’s systems had been compromised. The investigation concluded that there had been no unauthorised access to the municipality’s network. While officials acknowledged that additional verification measures could have been taken before releasing the payment, they described those observations as lessons identified after the incident. Meanwhile, Wildcat Construction stated that it has still not received payment for the completed project and hopes the dispute will be resolved soon.
Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said that Business Email Compromise (BEC) has become one of the most dangerous forms of financial cybercrime worldwide. Criminals often infiltrate legitimate business communications by using spoofed email addresses, lookalike domains and fraudulent banking instructions to redirect payments. He emphasised that organisations should adopt multi-layer verification procedures, independently verify payment changes through authorised telephone calls, implement digital signatures and strengthen payment approval controls to effectively prevent such sophisticated financial cyber fraud.
