Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

A company sent scammers over $800,000. Authorities recovered $375,000

A fraudster impersonated a vendor and redirected invoice payments. The case shows how to prevent BEC and what to do immediately after a mistaken transfer.

PUBLIC RESEARCH
AUTHOR
/ CEO Breachroad · OSCP · PNPT
PUBLISHED
25 September 2026
READING TIME
10 min read
TOPIC
Threats and Incidents
A company sent scammers over $800,000. Authorities recovered $375,000

A company in the US state of Iowa paid more than $800,000 into an account controlled by a scammer because an employee believed they were paying legitimate vendor invoices. On 24 September 2026, the US Department of Justice announced a court judgment forfeiting roughly $375,000 in proceeds from the fraud.

That is good and difficult news at the same time. Authorities traced a substantial amount, but the case concerns payments made in mid-2022 and the recovered sum is smaller than the total sent. It shows that law enforcement action can produce results, while the best protection for a business remains stopping a fraudulent bank-account change before a transfer is approved.

What happened in this case

According to the prosecutors’ release, the scammer impersonated the company’s vendors and instructed an employee to direct payment to a bank account under the scammer’s control. Believing it was paying real invoices, the company sent more than $800,000 in total in mid-2022. The money was then transferred between accounts to make the stolen funds harder to trace.

Authorities seized $372,583.77 from a Wells Fargo account, among other seizures. The court found that the funds were involved in a crime and were subject to forfeiture. The release describes the United States as recovering roughly $375,000; the date of that judgment should not be confused with confirmation that the entire amount has already reached the victim company’s account.

The scheme is known as Business Email Compromise, or BEC. It does not require a malicious attachment or a dramatic network intrusion. A deceptively similar sender address, a compromised mailbox or a convincing request to “update our banking details” can be enough.

The most important control is not inside the inbox

Spam filtering, DMARC and account protection are necessary, but none should be the only safeguard for a large payment. A finance process must assume that a message can look genuine and still be fraudulent.

Every change to a vendor’s bank account should be confirmed outside the message that introduced it. The employee should use a previously known phone number or a contact from the contract, not a number included in the suspicious email. For larger amounts, a second person should approve the change after seeing both the request and the result of independent verification.

Culture matters too: pausing a payment until it is confirmed must not be treated as obstructing the business. A scammer relies on time pressure, seniority and the employee’s fear of asking a “stupid question.” A sound process gives people permission to stop.

What to do in the first hour after a mistaken transfer

When a company discovers that money may have gone to a fraudster, speed matters. It should not wait for the internal investigation to finish or for the next business day.

  1. Contact the bank through an official channel. Ask it to urgently stop, recall or trace the transfer and contact the receiving bank. The procedures and terminology differ by payment type and country.
  2. Report the incident to law enforcement. For US cases, the DOJ also points to the FBI Internet Crime Complaint Center. A company in another country should use the relevant local channel rather than assuming a foreign form replaces domestic reporting.
  3. Preserve evidence. Keep messages with full headers, invoices, the history of vendor-detail changes, payment confirmations, mailbox logs and a precise timeline. Do not delete suspicious mail rules before documenting them.
  4. Contact the real vendor. Use a previously known number. Establish whether its mailbox was compromised or a lookalike domain was used, and identify any other payments or conversations at risk.
  5. Limit further loss. Pause unsettled instructions involving that vendor, review recent account changes and inspect active email sessions. Changing every password in a panic is not a substitute for establishing which account and process were compromised.

One person should maintain the timeline and the list of contacts with banks and law enforcement. That prevents duplicate calls and gives each institution consistent information.

How to prevent BEC without slowing every payment

Controls can be matched to risk. A new bank account, a new beneficiary, an unusual country, a large amount or an urgent instruction should trigger extra verification. Routine payments to an approved account do not need to follow exactly the same path.

Keep a record of vendor-detail changes: who requested the change, who confirmed it through a known channel, when they did so and who approved the first payment. The finance system should make a new account conspicuous rather than silently replacing the previous one.

A BEC exercise should include finance, procurement, sales and management. It is not a quiz about spotting a typo in a domain. It should rehearse a decision: how to interrupt an urgent request, where to find the trusted contact and how to report a mistake without fear of punishment.

Do not blame the employee — fix the conditions around the decision

If one message and one person can both change a bank account and release a large amount, the problem is in the process. Publicly blaming an individual encourages others to conceal mistakes, while every minute of delay reduces the chance of stopping the money.

The post-incident review should establish why the message was credible, what information the offender knew, whether a mailbox was compromised and why the payment control did not catch the change. “Employees must be more careful” is not an adequate conclusion.

Source facts and Breachroad’s conclusions

The US Department of Justice describes the vendor impersonation, payments exceeding $800,000, the seizure of $372,583.77 from one account and the court’s forfeiture judgment for roughly $375,000. Prosecutors recommend checking sender addresses, independently confirming payment changes and promptly reporting the incident to the bank and law enforcement.

The first-hour model, risk-based control thresholds, verification record and no-blame approach are Breachroad recommendations. The exact process depends on the bank, country, payment value and company authorities. Our guides cover more Business Email Compromise scenarios and explain how to verify a vendor’s change of bank account. Finance and procurement teams can rehearse these decisions in employee cybersecurity training.

SHARE / COPY