Search Everything in One Place

Explore the web, images, videos, news, and more – all in one place.

News

The South Carolina town in turmoil over a $545,000 email phishing scam

The South Carolina Town in Turmoil Over a $545,000 Email Phishing Scam
The South Carolina Town in Turmoil Over a $545,000 Email Phishing Scam

Surfside Beach sent money to a scammer’s account—and the fight over who’s to blame is dividing the ‘Family Beach.’

The South Carolina Town in Turmoil Over a $545,000 Email Phishing Scam
Surfside Beach Mayor Robert Krouse, center, has defended the town’s actions amid a costly cyber cam.

SURFSIDE BEACH, S. C.—The trap began with a routine bureaucratic ritual: the head of a family-run contracting company and a small town public-works director trading emails about when the municipality would cut a six-figure check for utility work.

But lurking online, a cybercriminal pounced with staggering ease. Someone posing as a company employee emailed the director to request an electronic transfer instead. Days later, the town sent $545,598.30 to a Utah bank account that wasn’t the company’s.

Surfside Beach had fallen victim to a “business email compromise” scam, a cyber-swindle that cost $3 billion nationally last year, the Federal Bureau of Investigation says.

In such ruses, fraudsters fool people with malicious software, phishing emails or tweaked digital addresses. Once in, they can spot legitimate email threads about invoices and business matters.

In Surfside Beach, a probe is under way to determine how the breach occurred. The money is still missing, and the fallout is rippling through the tourist enclave of about 4,300 year-rounders, a place known as the “Family Beach” for its laid-back contrast to nearby Myrtle Beach.

Rumors, recently debunked, spread that the town fired two workers over the foul-up, though neither processed payments. Locals are speaking out at Town Council meetings, and residents such as Cecilia Horne, 67 years old, are questioning the competence of their leaders. “Where’s the professionals?” she said from the seat of her golf cart.

The company, Wildcat Contractors, has yet to be paid and has had to tap reserves to help cover the errant $545,000 it dearly wants. “I didn’t get scammed, they got scammed,” CEO Alyssa Bowker said of the town. “Why should I not be paid?”

Surfside Beach Mayor Robert Krouse said the emailed payment request appeared genuine. “We don’t see where the town erred,” he said, so he didn’t see “why we should be paying double.”

The South Carolina Town in Turmoil Over a $545,000 Email Phishing Scam
Wildcat Contractors chief executive Alyssa Bowker, with her husband and company president, Kyle Bowker, and their daughter.

The South Carolina Law Enforcement Division is investigating, and the town’s insurer is doing a forensic analysis. But one thing is clear: The ploy was designed to trick.

‘Perfectly tailored’ attack

The fraudster set up dummy websites and email addresses. One domain reads “wiidcatcontractors.com”—with the third letter in the email address a capital I, visually identical to a lowercase L in some fonts. Another tacked an “s” on Surfside to create surfsidesbeach.org. Such “typosquatting” led town and Wildcat employees to communicate unwittingly with the scammer, emails viewed by The Wall Street Journal show.

The trick is so subtle it can “pass the human eyeball test,” said Ben Bernstein, a cybersecurity expert at Huntress Labs.

While the details of the breach in Surfside Beach are still being scrutinized, cyber intruders have a typical toolbox for such crimes. To time their strikes, they set up flags on infiltrated email systems so they see when payment-related messages land. They also route legitimate emails to trash so only the fraudster’s voice gets through.

The Surfside Beach fraud seemed to follow a standard playbook, said Dave Burg, global head of cyber and data resilience at risk and financial advisory firm Kroll.

“You’re in the middle of this conversation, you make your attack perfectly tailored,” he said, referring to the scammer.

Surfside Beach joins a growing list of municipalities hit by the scam. Peterborough, N.H., lost $2.3 million in 2021 and recovered just $650,000, prompting officials to dip into reserves and cut spending. Insurance didn’t pay. Lexington, Ky., was conned out of $3.9 million a year later, but authorities seized all of it from a private bank account. The crime has led to five federal convictions so far.

Artificial intelligence is empowering scammers, said Timothy Lynch, chief of the FBI’s Cyber Enabled Fraud and Money Laundering Unit. In years past, he said, they overused “kindly,” a word seen in at least one Surfside Beach email. AI smooths syntax and diction, polish that helps overseas crooks with poor English.

Of all the anti-scam safeguards, none beats human verification. “Call a known number to ensure a request is authentic,” Lynch said.

Surfside Beach has had its share of fierce debates, including over a budget-busting pier replacement and a new ban on feeding wildlife. But nobody expected a cyber invasion.

‘It looked legit to us’

At the time of the debacle, Wildcat was well into a project to bury overhead lines on two-lane Ocean Boulevard.

The South Carolina Town in Turmoil Over a $545,000 Email Phishing Scam
A Wildcat Contractors crew on Ocean Boulevard earlier this month in Surfside Beach.

On March 9, Wildcat’s Bowker received an email from Surfside Beach’s public-works director about the job’s fourth payment. She owns the 130-employee company, based in Gastonia, N.C. Her husband, Kyle Bowker, is president.

“I will keep an eye out for the check,” she replied at 10:51 a.m., though the town says the director doesn’t recall getting that message.

About 90 minutes later, someone posing as Wildcat’s project manager emailed the director, asking that the money be sent electronically instead. It said Wildcat was “prioritizing electronic transfers.”

That day, the scammer filled out Surfside Beach’s ACH form, short for Automated Clearing House, an electronic bank network used to pay vendors. It had what Alyssa Bowker calls multiple red flags. The contact name isn’t her employee, and it lists a Los Angeles phone number, though the email address is her project manager’s. The bank is in Utah, and her signature, she says, appears blurry and lifted from elsewhere.

Another warning sign, she said: a project manager overruling the CEO about the payment method.

But town Finance Director Melanie Gruber said the ACH form didn’t raise suspicions. Companies sometimes use different contact names and numbers, the Utah bank is real, and the CEO’s signature matched town files, she said.

“It looked legit to us,” Gruber said.

The South Carolina Town in Turmoil Over a $545,000 Email Phishing Scam
Surfside Beach is tourist enclave of about 4,300 year-round residents.

It isn’t unusual for a vendor to switch from check to ACH, Town Administrator Gerry Vincent noted.

The town tried to reach Wildcat before authorizing the transfer on Friday, March 13. Gruber said a town employee called the project manager that afternoon. Kyle Bowker confirms this. He said he was with the project manager, who referred the caller to Alyssa Bowker.

Gruber said the town next called Alyssa Bowker’s mobile phone and left a message about the ACH transfer, but no one called back. Bowker said she doesn’t recall the voicemail but that it is possible she missed it.

Twice that day, the town emailed Bowker and the project manager at what looked to be their correct email addresses, Gruber said. But the emails didn’t go through, Bowker said.

The following Monday, the town was still emailing Bowker and the project manager, or at least trying. By then, the money was gone. “I do show it as a completed transaction to the account you provided,” a town employee wrote—yet another email Bowker says she never got.

The fraud was unmasked April 27 after Bowker heard from town officials following her payment inquiries. Their message: We paid you. When the town sent Bowker the ACH form and emails, she spotted “wiidcat” in some emails.

To her, it doesn’t matter if the scammer wormed into the email exchange from the town’s side or the company’s, because the town never spoke with her. “The onus is definitely on them to confirm,” she said. “You can’t just change payment terms and say, Whoops.”

Krouse, the mayor, said the town’s IT department found no breach of its network—the same conclusion Bowker said Wildcat’s IT consultants initially made about its network—and that the ACH request came from a valid Wildcat email. Krouse added he awaits the investigative findings.

‘Loosey-goosey’

The town has bolstered its financial controls, and now requires passwords for large contracts and closer scrutiny of ACH transfers. Historically, authorities have clawed back pilfered funds about 75% of the time when scams were reported within 72 hours, said the FBI’s Lynch. Because it took 45 days for this heist to come to light, recovery is “highly unlikely,” he said.

Around Surfside Beach, many locals blame the town for not catching the scam in time. “It just feels like gross negligence,” said Rachel White, 31, at the site of the farmers market she manages. People need to “slow down and breathe and look at what they’re doing.”

The South Carolina Town in Turmoil Over a $545,000 Email Phishing Scam
Rachel White, who manages a farmers market, blames the town for the scam.

At a pancake house, Judy Henion, 76, called the town’s handling of taxpayer money “loosey goosey.”

“Even when I go to Costco and spend $30 on gasoline, they verify the account before they do the transaction,” she said. Henion attended that evening’s Town Council meeting, where she stepped to the microphone to demand answers about what she called “the elephant in the room.”

Every council member present weighed in on the scam. “The most important thing, other than trying to get as much money back as we possibly can,” said Councilor Rick Lawhorn, “is to get it right so that we never have this happen again.”

Write to Scott Calvert at [email protected]

Read full story on The Wall Street Journal
Top