Cyber crime

10 jaw-dropping BEC scams that cost US local governments millions

Catherine Chipeta
3 Min
10 jaw-dropping BEC scams that cost US local governments millions

Business email compromise (BEC) scams are siphoning millions from US local governments, and fraudsters are only getting smarter. Cybercriminals impersonate vendors, officials, and even government employees to divert taxpayer funds straight into their own pockets. If you think your city or county is immune, think again—these jaw-dropping cases prove otherwise.

Here’s how hackers tricked officials into handing over millions.

1. Arlington, Massachusetts: A sophisticated BEC attack

Arlington officials fell prey to a sophisticated cybercrime operation. Criminals compromised an official email account and sent convincingly real wire transfer instructions to city staff. Before anyone realized what had happened, the funds had been rerouted into fraudulent accounts. Officials are now working with law enforcement to tighten their security protocols.

2. Lexington, Kentucky: $4 million lost in fake housing payments

Lexington’s finance team wired $4 million to a fraudster after receiving fake payment instructions. The scam only came to light when the intended recipient flagged the missing funds. While the city managed to recover part of the money, the breach exposed gaps in its verification process, leading to stricter protocols.

3. Madison County, Mississippi: $2.7 million vendor fraud

A fraudulent vendor payment scheme tricked Mississippi officials into wiring $2.7 million to criminals posing as a legitimate contractor. The scam exploited weak internal verification processes, prompting the county to ramp up employee training and security reviews.

4. Peterborough, New Hampshire: $2.3 million gone overnight

Scammers manipulated email conversations to impersonate a trusted contractor, convincing officials in Peterborough to send $2.3 million meant for a school and bridge project to fraudulent accounts. Despite efforts to recover the funds, the money was never retrieved, leaving taxpayers to foot the bill. Read more on the fraudulent payment request.

5. North Carolina county: $1.7 million vendor scam

Cabarrus County transferred $1.7 million to fraudsters posing as a known vendor. Attackers altered bank details in official invoices and sent them via compromised email accounts. By the time authorities realized what had happened, most of the money was gone.

6. Blaine, Minnesota: $1 million lost to vendor impersonation

City officials in Blaine mistakenly wired $1 million to BEC scammers who impersonated a vendor. The fraudsters gained access to email conversations, changed payment instructions, and convinced staff to process the transfer. The city later admitted it lacked cyber insurance to cover the loss.

7. Portland, Oregon: Fraudsters reroute city payments

Portland fell victim to a BEC attack that allowed scammers to redirect a city payment to their own account. Officials have not disclosed the exact amount lost, but the incident forced them to implement stricter authentication protocols to prevent future breaches.

8. Fort Lauderdale, Florida: Phishing attack on city funds

Officials in Fort Lauderdale transferred funds to fraudsters after falling for a phishing email. The city ultimately recovered $1.2 million, but the attack exposed significant security vulnerabilities, leading to new phishing awareness training and fraud detection investments.

9. Lake City, Minnesota: $1 million sewage project fraud

Cybercriminals targeted a Minnesota city’s sewage project, tricking officials into wiring $1 million to fraudulent accounts. The attack took advantage of weak internal controls, prompting a city-wide review of vendor verification procedures.

10. Eagle Mountain, Utah: $1 million vanishes in cyber scam

Eagle Mountain officials were caught in a cyber scam that drained $1 million from city accounts. Fraudsters leveraged sophisticated email impersonation techniques to alter financial transactions. The city is now collaborating with cybersecurity experts to prevent future incidents.

Preventing BEC scams: A guide for CFOs
Learn how finance leaders can safeguard payments and stop fraud before it happens.

Related articles

The new security standard for business payments

End-to-end B2B payment protection software to mitigate the risk of payment error, fraud and cyber-crime.