City Hall's Most Expensive Email

In March 2026, the town of Surfside Beach, South Carolina sent a $545,598 payment to a contractor burying utility lines along Ocean Boulevard. The money never arrived. It landed in a bank account in Utah instead, redirected by someone who did nothing more sophisticated than send a convincing email.
Nobody broke into the town's network. An independent review found no evidence the town's email or Microsoft accounts were ever compromised. The criminals simply registered two lookalike web domains, one that added an "s" to the town's name and one that misspelled the contractor's, and used them to slip fake payment instructions into a routine construction invoice. The town didn't notice for 45 days, until the real contractor called to ask where its money was.
That is what a modern attack on local government usually looks like. Not ransomware freezing the water department, and not a hooded figure in a server room. Just an email and a changed account number, moving money that clears before anyone thinks to check.
Why city hall is an easy mark
Local governments make near-perfect targets, and not because their people are careless. It is the way public agencies are built.
Almost everything a city does is public record. Council agendas name the vendors. Meeting minutes list the contracts and the amounts. Budgets and bid awards sit on the website for anyone to read. A criminal researching a target does not have to hack anything to learn that your public works department owes a paving contractor $600,000 next month. You published it.
On top of that, cities run on large, scheduled payments to a handful of familiar vendors, moved by small finance teams trained to process what looks official. A wire to a known vendor rarely raises an eyebrow. One well-timed email is all it takes to move real money through that system.
The three ways it happens
The version that hit Surfside Beach, Harpswell, and Cabarrus County is vendor payment fraud, often called business email compromise. Someone impersonates a known vendor, claims the banking details have changed, and the payment goes to the criminal's account. Harpswell, Maine lost $189,199 this way in May 2026. Cabarrus County, North Carolina lost $1.7 million. Arlington, Massachusetts lost $446,000 after criminals quietly read its email for weeks before sending the fake request.
A second version turns the payroll system into the target. An employee's login gets phished, the direct deposit account is changed inside the real system, and the paycheck lands in a stranger's account. The employee is still owed their wages, so the city pays twice.
The third version flips the scheme around and impersonates the city to defraud residents. In March 2026, the FBI's Internet Crime Complaint Center warned that criminals are posing as city and county permit offices, emailing people with active planning applications and billing them for fake zoning fees. The messages carry the right letterhead and cite real case numbers and property addresses, pulled straight from public records, and they push for payment before anyone calls to verify.
Why you rarely hear about it
For every case that reaches the news, more are quietly absorbed. Reporting a stolen payment means admitting that public money walked out the door on someone's watch, and that is a hard thing for any manager or elected official to say out loud. Losses get folded into insurance claims, investigations run without headlines, and the next town over never learns what almost happened to it. The pattern stays invisible right up until it is your invoice.
It is recoverable, if you move
Here is the part that should change how a finance office reacts. In September 2022, Boulder County, Colorado sent $237,241 to a fraudulent vendor account. Unlike most victims, the county got all of it back. A sheriff's detective traced the funds while they still sat in the criminal's account, froze it, and recovered the money with help from the Secret Service and the receiving bank. As the county administrator put it afterward, they thwart these attempts several times a year and simply did not catch this one in time.
The difference was speed. The FBI reports that when these frauds are caught within about three days, roughly three out of four victims recover their money. Surfside Beach's 45-day gap is why its money is likely gone. Boulder County's fast catch is why its money came home. The recovery window is measured in days.
The fix costs almost nothing
This is not really a technology problem, which is why it does not require a bigger IT budget. It is a question of process and authority, and three controls stop most of it.
Any change to a vendor's or employee's banking information gets verified by a phone call to a number already on file, never a number or link from the email requesting the change. No single person can both approve a payment and change where it goes, so a redirected payment has to get past two people instead of one. And urgency gets treated as a warning sign rather than a reason to hurry, because the entire scheme depends on a payment clearing before anyone verifies it.
A clerk can put all three in place starting Monday. That is the uncomfortable and useful truth about city hall's most expensive email. The trusted routine that makes the fraud work is the same routine you can fix without spending a dollar.

