Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

An “official” email knows your case number. That is not enough reason to pay

Criminals can use public details about an application, property or business and add a fraudulent fee. Confirm the payment outside the message you received.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
15 September 2026
READING TIME
8 min read
TOPIC
Human Security
An “official” email knows your case number. That is not enough reason to pay

You are waiting for a permit, planning decision or registry update. An email arrives with your name, the property address and a genuine application number. It says the process will stop unless a fee is paid immediately. The document feels credible precisely because some of its information is true.

A case number is not a secret password. Information about applications, tenders, properties and projects may come from public records, notices, correspondence shared by several parties or a data breach. A scammer can combine the correct context with their own bank account.

Accurate details do not prove a new charge

Do not judge the message solely by its logo, seal, official’s name or polished language. All can be copied. The useful questions are whether the fee belongs to the known process, appears in the official portal and is payable to the correct institution.

The pressure may refer to a real deadline: a hearing, decision, tender or construction schedule. That is still no reason to use the contact details inside the new email. The more serious the claimed consequence, the more important an independent check becomes.

Confirm the fee outside the message

Open the authority’s portal from your own bookmark or an address you entered yourself. Call a number published on the official website or contained in an earlier acknowledgement or paper letter. If you already know the case officer, use the contact saved previously, not the signature in the new message.

Ask for the fee name, legal or procedural basis, amount, deadline and correct payment account. Compare both the beneficiary name and account details with official instructions. A personal or intermediary account does not become legitimate because the email knows your case number.

Do not open an attachment that asks you to enable additional features, and do not sign in through the supplied link. A genuine payment can be confirmed without following the claimant’s instructions.

If the transfer has already been sent

Contact your bank immediately and ask whether the payment can be stopped or recovered. Provide the beneficiary account, amount, time and authorisation method. Speed matters, although recovery cannot be guaranteed.

Keep the email with its full sender details, attachments, transfer receipt and website addresses. Alert the real authority because other people in similar proceedings may receive the same story. Report the fraud to police and the suspicious message or site through your national cybercrime reporting channel.

If you disclosed sign-in details, change the password on the official site and end unfamiliar sessions. Correcting the payment alone does not address possible access to email or the authority’s portal.

For a business, this is a process problem

Finance staff should not be expected to authenticate a seal or writing style alone. A company can require a business owner for every new official fee, confirmation in the relevant portal or a call to an established case officer. A new beneficiary account should trigger another check.

Maintain a simple list of active proceedings, responsible employees and expected payments. The scammer exploits fragmented knowledge: one person knows the project, another the invoice and somebody else the deadline. A shared record brings those facts together before money moves.

What the source confirms and what Breachroad recommends

On 9 March 2026, the FBI warned about emails impersonating US city and county planning and zoning officials. Criminals used public permit information, application numbers and property addresses before requesting fraudulent fees by wire or other payment methods. The FBI advises confirming charges through a number found on the authority’s official website. The alert concerns cases in the United States and does not establish an identical campaign elsewhere.

Breachroad draws a wider lesson: accurate context from a public source does not authenticate the sender or payment account. The exact process must be verified with the relevant authority in your jurisdiction. Businesses need the same independent check for every unexpected payment; our analysis of cloned company websites and B2B advance-payment fraud covers a related pattern. Teams can rehearse these scenarios through cybersecurity awareness training.

SHARE / COPY