Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Email Security

Scammers Grab $2.5 Million From North Carolina County in BEC Scam

Cybercriminals managed to divert $2.5 million in a business email compromise (BEC) scam targeting Cabarrus County, North Carolina. $1.7 million of that has not been recovered and remains missing.

Cybercriminals managed to divert $2.5 million in a business email compromise (BEC) scam targeting Cabarrus County, North Carolina. $1.7 million of that has not been recovered and remains missing.

The attack started at the end of November 2018, when employees of Cabarrus County Schools and Cabarrus County Government received emails pretending to be from Roanoke, Virginia-based Branch and Associates, Inc., the general contractor for construction of West Cabarrus High, a new school for the Cabarrus County Schools District.

Posing as representatives of Branch and Associates, the conspirators sent a series of emails to request the update of bank account information. The attackers provided new banking information, seemingly valid documentation and signed approvals.

Next, the conspirators simply waited for Cabarrus County to make the next vendor payment, which was of $2,504,601. As soon as the funds arrived in their account, the scammers started diverting them through multiple different accounts.

The scam was discovered on January 8, when Branch and Associates sent a courtesy notification of a missed payment. SunTrust, the bank from which the funds were transferred, and Bank of America, the bank to which funds were transferred, were notified. 

While $776,518.40 of the funds remained in traceable accounts and were recovered, $1,728,082.60 of the total remains missing.

Authorities were also notified on the scam, and the investigation into the incident continues. Cabarrus County says that construction of the new high school has not been impacted. 

Both the number and sophistication of socially engineered BEC scams have increased over the past several years, reports published by the FBI’s Internet Crime Complaint Center (IC3) earlier in 2019 show. 

Advertisement. Scroll to continue reading.

Losses associated with BEC scams in the U.S. reached $1.3 billion last year alone, and the number of received complaints also went up, the FBI revealed. Between October 2013 and May 2018, this type of fraud caused potential losses of more than $12 billion globally.

Earlier this year, Agari detailed a new type of BEC fraud, where scammers attempt to divert funds by adding fictional accounts to company payrolls. This allows attackers to siphon off smaller, but continuous, amounts of money.

The fight against BEC has intensified as well, with authorities worldwide joining forces to dismantle large networks of scammers

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Cloud Security

Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.

Compliance

Government agencies in the United States have made progress in the implementation of the DMARC standard in response to a Department of Homeland Security...

Email Security

Many Fortune 500, FTSE 100 and ASX 100 companies have failed to properly implement the DMARC standard, exposing their customers and partners to phishing...

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Fraud & Identity Theft

Famed hacker Kevin Mitnick has died after a battle with pancreatic cancer.  At the time of his death, he was Chief Hacking Officer at...

Fraud & Identity Theft

A team of researchers has demonstrated a new attack method that affects iPhone owners who use Apple Pay and Visa payment cards. The vulnerabilities...

Cybercrime

Enterprise users have been warned that cybercriminals may be trying to phish their credentials by luring them with fake emails that appear to be...