top of page
Search

Business Email Compromise in Accounts Payable: What the $545,598 Surfside Beach Fraud Teaches Every Organization

A single request to change a vendor’s payment method can expose an organization to a six-figure loss.


That is the central lesson from the Business Email Compromise incident that struck the Town of Surfside Beach, South Carolina, in 2026.


The municipality issued a $545,598.30 Automated Clearing House payment intended for Wildcat Contractors. The money was instead redirected to an account controlled by fraudsters. According to the Town, fraudulent communications began on March 9, 2026, and the payment was issued on March 13. The loss was not discovered until the contractor notified the Town on April 28 that it had not received the money.


The incident illustrates a critical weakness in many Accounts Payable departments:

Payment fraud does not necessarily require criminals to defeat the accounting system. They may only need to defeat the vendor-change process.


On Friday, September 4, 2026, Corporate Compliance Seminars will present the live online CPE event Business Email Compromise—Accounts Payable. The two-CPE program is designed to help Accounts Payable, finance, procurement, audit, compliance, and vendor-management professionals strengthen the controls used to authenticate vendors, process bank-account changes, and prevent fraudulent payments.


The course is taught by Debra R. Richardson, MBA, CFE, APM, APPM, CPRS, a recognized specialist in vendor setup, vendor maintenance, payment fraud prevention, and Accounts Payable internal controls.


What Happened at Surfside Beach?

Surfside Beach was making a legitimate payment to a legitimate contractor for legitimate work.


That is precisely what made the fraud so dangerous.


This was not an obviously suspicious invoice from an unknown company. The attackers inserted themselves into an existing commercial relationship and created communications that appeared connected to a real payment.


According to reporting by The Wall Street Journal, someone posing as an employee of Wildcat Contractors requested that the expected payment be changed from a check to an electronic transfer. The Town subsequently sent $545,598.30 to a Utah bank account that did not belong to the contractor.


The Town’s subsequent forensic review reported that:

  • The payment was issued on March 13, 2026.

  • Wildcat Contractors notified the Town on April 28 that it had not received the payment.

  • Fraudulent communications had begun on March 9.

  • Spoofed and typo-squatted domains were used.

  • One fraudulent domain added an “s” to the Town’s legitimate domain name.

  • Communications involving legitimate and fraudulent contractor domains contributed to the deception.

  • Investigators found no evidence that the Town’s Microsoft 365 accounts had been accessed without authorization.


The distinction is important.


A Business Email Compromise incident does not always require the victim organization’s email account to be hacked. Fraudsters may instead use:

  • Look-alike domains

  • Spoofed addresses

  • Compromised vendor accounts

  • Conversation hijacking

  • Social engineering

  • Fabricated banking forms

  • Information gathered from prior correspondence


This means that multifactor authentication, spam filters, cybersecurity awareness training, and endpoint security—although essential—are not sufficient by themselves.


The payment process must contain controls that operate outside the email conversation.


The Fraud Used Typosquatting to Defeat Visual Review

Typosquatting occurs when a criminal registers a domain that closely resembles a legitimate domain.


The difference may involve:

  • One added letter

  • One deleted letter

  • Two transposed letters

  • A capital “I” substituted for a lowercase “l”

  • A numeral substituted for a letter

  • A slightly different domain extension

  • An added hyphen or word


In the Surfside Beach incident, the Town reported that criminals created a domain adding an extra “s” to the legitimate Surfside Beach domain. The forensic findings also identified fraudulent communications involving look-alike Wildcat Contractor domains.


These domains can be extremely difficult to detect when employees:

  • Read email on mobile devices

  • Work under deadline pressure

  • Trust an existing email thread

  • See a familiar display name

  • Expect the underlying payment

  • Assume another employee already performed verification


The fraudulent message does not need to be perfect.

It only needs to appear sufficiently credible for the payment process to continue.


Why the Surfside Beach Incident Was a Business Process Failure—not Merely an Email Problem

Business Email Compromise is often classified as a cybersecurity risk.


That classification is incomplete.


BEC is also an:

  • Accounts Payable risk

  • Vendor-management risk

  • Procurement risk

  • Treasury risk

  • Internal-control risk

  • Fraud risk

  • Governance risk

  • Training risk


Cybersecurity personnel may block malicious attachments, identify suspicious logins, or detect compromised accounts. They ordinarily do not decide whether a vendor’s new bank account should be entered into the vendor master file.


That decision belongs to the business process.


The central control question is not simply:

Did the email look genuine?

The better questions are:

  • Was the change requested through an authorized channel?

  • Was the requester authenticated?

  • Was the vendor independently contacted?

  • Was a known telephone number used?

  • Was the bank account validated?

  • Did a second employee approve the change?

  • Was the vendor notified through a separate communication channel?

  • Was the first payment to the new account reviewed?

  • Did the payment file receive a final fraud-focused review?


A payment can be technically authorized within the accounting system while still being fraudulently redirected.


The Confirmation Call Must Be Truly Independent

Many organizations believe they have an effective control because employees make a confirmation call before changing vendor banking information.


The effectiveness of that control depends on how the telephone number is obtained.

An employee should not confirm a bank-account change by calling:

  • A number in the change-request email

  • A number on an attached banking form

  • A number supplied by the person requesting the change

  • A number found in the signature block of the suspicious message

  • A number included in a newly submitted vendor form


Those sources may all be controlled by the fraudster.


A more reliable confirmation call uses a telephone number obtained from an independently maintained source, such as:

  • The existing vendor master record

  • The original contract

  • A previously validated onboarding file

  • An established vendor portal

  • A known company representative

  • A reliable external validation source


The employee should also speak with a person authorized to approve payment-instruction changes—not merely whoever answers the telephone.


The CCS course directly addresses both the problem with email and the potential weakness in poorly designed confirmation calls. It provides a confirmation-call script, a call log, authentication references, vendor-validation resources, and desktop procedures for vendor inquiries.


The 45-Day Detection Delay Increased the Loss

The payment was made on March 13. The Town learned on April 28 that the contractor had not received it.


That delay reveals another important control issue.


Many organizations focus on preventing fraudulent payments but devote less attention to detecting them immediately after release.


Detective controls may include:

  • Vendor notification when banking data changes

  • Vendor notification when a payment is issued

  • Review of the first payment sent to a new account

  • Positive Pay or ACH debit and credit controls

  • Daily reconciliation of payment exceptions

  • Independent review of high-value electronic payments

  • Verification of unusual payment-method changes

  • Rapid escalation when a vendor reports nonpayment


The longer a fraudulent payment remains undetected, the more time criminals have to move the funds through additional accounts.


The control environment should therefore be designed around three objectives:

  1. Prevent unauthorized vendor changes.

  2. Detect suspicious payments immediately.

  3. Respond rapidly enough to improve the possibility of recovery.


Business Email Compromise Exploits Normal Activity

Many frauds begin with obviously abnormal conduct.


BEC often does not.


The transaction may involve:

  • A real vendor

  • A real invoice

  • A real project

  • A real payment amount

  • A real payment deadline

  • A familiar employee name

  • A familiar email conversation


Only one element may have changed:


Where the money is sent.


This makes BEC especially dangerous because most traditional Accounts Payable controls are designed to verify that:

  • Goods or services were received.

  • The invoice is valid.

  • The amount is accurate.

  • The purchase was authorized.

  • The invoice was approved.

  • The payment is not a duplicate.


All of those conditions may be satisfied in a payment-redirection fraud.

The invoice is legitimate. The vendor is legitimate. The expense is legitimate. The payment is approved.


The bank account is fraudulent.


The Vendor Master File Is a Financial Control

The vendor master file is sometimes treated as an administrative database.


It should be treated as a high-risk financial asset.


The vendor master file determines:

  • Who can be paid

  • Where payments are sent

  • Which tax classifications apply

  • Which addresses are used

  • Which payment methods are authorized

  • Which banking instructions control disbursement


An unauthorized change to a vendor record can redirect every future payment, not just one transaction.


Effective vendor-master controls may include:

  • Restricted access

  • Segregation of duties

  • Required documentation

  • Independent vendor authentication

  • Bank-account validation

  • Duplicate-vendor testing

  • Change reports

  • Supervisory approval

  • Audit trails

  • Periodic data cleansing

  • Inactive-vendor reviews

  • Post-change notifications

  • Monitoring of the first payment after a change


The CCS program teaches participants how to implement up to six steps for reducing BEC and other payment fraud risks when remittance information is changed through email, fax, or paper-based requests.


Six Control Steps for Vendor Banking Changes

The appropriate process will depend on the organization’s systems, size, industry, and risk profile. A controlled vendor-bank-change process generally includes the following elements.


1. Separate the request from the approval

The employee receiving the request should not be able to complete the entire change without review.


Segregation may involve:

  • One employee receiving the request

  • Another authenticating the vendor

  • A third approving the master-file change

  • Treasury or Accounts Payable reviewing the payment


Smaller organizations may use compensating controls when staffing limits prevent complete segregation.


2. Authenticate the requester

Authentication asks: Is this person actually associated with the vendor and authorized to request the change?


Authentication may use:

  • Previously established contacts

  • Known telephone numbers

  • Secure portal credentials

  • Contract records

  • Preset passcodes

  • Challenge questions

  • Internal vendor ownership records


An email address alone is not sufficient authentication.


3. Validate the new information

Validation asks: Does the submitted information correspond to a real organization, bank, address, registration, or tax record?


Potential validation procedures include:

  • Confirming legal entity information

  • Reviewing tax documentation

  • Checking business registrations

  • Validating bank-routing information

  • Comparing country and geographic indicators

  • Investigating inconsistencies

  • Screening against internal and external watchlists


Authentication verifies the person. Validation evaluates the data.


Both are necessary.


4. Perform an independent confirmation

The vendor should be contacted using a trusted communication channel that was not supplied in the current change request.


The employee should confirm:

  • That the vendor requested the change

  • The effective date

  • The new payment method

  • The financial institution

  • The authorized requester

  • Any unusual differences in location or account ownership


The confirmation should be documented.


5. Approve and record the change

The approval should identify:

  • Who requested the change

  • Who authenticated the vendor

  • What sources were used

  • Who approved the change

  • When the change was entered

  • What record was changed

  • What exceptions were identified

  • How exceptions were resolved


The process should be auditable from beginning to end.


6. Monitor the first payment

A first payment sent to new banking information deserves heightened scrutiny.


The organization may:

  • Require a second approval

  • Limit the initial payment amount

  • Notify the vendor before release

  • Confirm receipt afterward

  • Review the payment against the approved change documentation

  • Hold unusually large changes for additional verification


The CCS course provides templates and resources intended to help participants implement these types of controls, including banking forms, validation references, confirmation-call tools, vendor notifications, payment-file reviews, and desktop procedures.


Why Cybersecurity Awareness Training Is Not Enough

Employees are often told to:

  • Avoid clicking unfamiliar links

  • Inspect email addresses

  • Watch for grammatical errors

  • Report suspicious attachments

  • Use strong passwords

  • Enable multifactor authentication


These practices remain important.


However, the Surfside Beach incident shows why Accounts Payable teams need specialized process training.


A fraudster may:

  • Avoid sending an attachment

  • Avoid requesting login credentials

  • Use polished language

  • Reference a real invoice

  • Know the project details

  • Participate in an existing conversation

  • Use a domain that appears nearly identical

  • Submit a realistic banking form

  • Request an operationally plausible change


The Vendor Process Training Center created by Debra Richardson emphasizes that vendor teams require training that begins where general cybersecurity awareness ends.


Its programs focus on authentication techniques, internal controls, best practices, and vendor validations designed to reduce fraudulent payments, compliance failures, and inaccurate vendor data.


Artificial Intelligence Is Making BEC More Convincing

Older phishing messages were often recognizable because they contained unusual grammar, awkward wording, or inconsistent formatting.


Generative AI can help fraudsters produce:

  • Professionally written emails

  • Plausible payment explanations

  • Industry-specific terminology

  • Realistic executive messages

  • Tailored vendor communications

  • Rapid responses during an active conversation

  • Messages written in the style of a known employee


AI can also assist criminals with open-source research, translation, impersonation, and social-engineering preparation.


The practical consequence is clear: Organizations cannot rely on spelling errors as a fraud-control system.


The strength of the control must come from the process, not from the employee’s ability to identify imperfect writing.


AI may also support fraud prevention by helping organizations:

  • Detect look-alike domains

  • Analyze unusual email patterns

  • Prioritize suspicious vendor changes

  • Identify abnormal payment behavior

  • Review duplicate bank accounts

  • Flag inconsistent addresses

  • Generate fraud-risk dashboards


However, technology should supplement—not replace—independent authentication and human review.


Internal Auditors Should Test the Entire Vendor-Change Process

Internal Audit should evaluate more than whether a policy exists.


Testing should determine whether the process works under realistic conditions.


Relevant audit questions include:

  • Can banking information be changed through ordinary email?

  • Who has access to modify vendor records?

  • Is access periodically reviewed?

  • Are requester identities authenticated?

  • Are independent telephone numbers required?

  • Are calls documented?

  • Can the person making the change also release the payment?

  • Are all changes reviewed?

  • Are vendor notifications sent?

  • Are high-value payments subject to additional controls?

  • Are the first payments to changed accounts monitored?

  • Are exception reports produced?

  • Are dormant vendors reviewed?

  • Are duplicate bank accounts identified?

  • Are vendor-change records retained?

  • Are incidents escalated immediately?

  • Has the process been tested using a simulated BEC scenario?


An audit that reviews only written procedures may miss the difference between a control that is documented and a control that is actually effective.


The Surfside Beach Case Demonstrates Why Every Organization Is Vulnerable

Municipalities are attractive BEC targets because they may:

  • Process large public-works payments

  • Publish contracts and project information

  • Work with numerous vendors

  • Operate with limited cybersecurity resources

  • Use decentralized approval processes

  • Face staffing constraints

  • Rely heavily on email

  • Maintain public employee contact information


The same vulnerabilities exist in:

  • School districts

  • Universities

  • Healthcare systems

  • Nonprofits

  • Construction companies

  • Manufacturers

  • Banks

  • Insurance companies

  • Government agencies

  • Professional-services firms

  • Public companies

  • Privately held businesses


Any organization that pays vendors can become a target.


Learn from Debra R. Richardson’s Accounts Payable and Vendor-Management Experience

The September 4 CPE event is taught by Debra R. Richardson, an Accounts Payable and vendor-process specialist with more than 20 years of experience at Fortune 500 organizations, including Verizon, General Motors, and Aramark. Her experience covers Accounts Payable, Accounts Receivable, general ledger, financial reporting, vendor maintenance, vendor onboarding, and vendor self-registration systems.


Debra’s professional credentials include:

  • Master of Business Administration

  • Certified Fraud Examiner

  • Accredited Payables Manager

  • Accredited Procure-to-Pay Manager

  • Certified Payments Risk Specialist


She has experience with widely used enterprise-resource-planning platforms, including SAP, PeopleSoft, NetSuite, Intacct, and Munis. She serves on the Nacha ACH Network Advisory Board, provides vendor-master-file expertise for the Institute of Finance & Management, and has been recognized repeatedly as a leading Accounts Payable influencer.


Her Vendor Process Training Center focuses exclusively on vendor onboarding and maintenance. The training model is based on transforming vendor teams from processors of requests into protectors of organizational payments and data through consistent authentication, validation, documentation, and internal controls.

This background is particularly relevant to BEC because payment fraud often begins where cybersecurity controls end and vendor-administration decisions begin.


What Participants Will Learn on September 4, 2026

The Business Email Compromise—Accounts Payable event is a two-hour live online program providing two NASBA-approved CPE credits in Auditing. It is designed for participants from basic through advanced levels and has no prerequisite or advance-preparation requirements.


Participants will learn how to:

  • Recognize common BEC and vendor-payment fraud schemes

  • Understand why email is an unreliable authentication method

  • Identify weaknesses in existing confirmation-call procedures

  • Implement up to six steps for vendor remittance changes

  • Authenticate vendor representatives

  • Validate vendor and banking information

  • Strengthen internal controls over vendor-master changes

  • Add an additional control to reduce the risk of significant payment losses

  • Review payments before transmitting the payment file

  • Notify vendors when information changes

  • Document vendor inquiries and confirmation calls

  • Build an auditable vendor-change process

  • Customize fraud-prevention templates for their organizations


The course includes practical resources such as:

  • An authentication reference

  • A vendor banking form

  • A vendor-validation reference list

  • Global vendor registration resources

  • A confirmation-call script

  • A confirmation-call log

  • A vendor change-notification process

  • A payment-file review procedure

  • A desktop procedure for vendor inquiries


Who Should Attend?

The event is relevant for professionals responsible for any part of the vendor-to-payment lifecycle, including:

  • Accounts Payable personnel

  • Vendor master data teams

  • Procurement professionals

  • Treasury personnel

  • Controllers

  • Finance managers

  • Internal auditors

  • External auditors

  • Fraud investigators

  • Compliance officers

  • Risk managers

  • Information-security personnel

  • Government finance employees

  • School-district finance teams

  • Higher-education administrators

  • Nonprofit financial managers


Managers should also consider registering multiple members of the vendor, procurement, and Accounts Payable teams.


A strong procedure can still fail when only one person understands it.


Questions Every CFO, Controller, and Accounts Payable Manager Should Ask

The Surfside Beach incident creates an opportunity for every organization to examine its own controls.


Management should ask:

  1. Can a vendor change banking information through email?

  2. Can the employee receiving the request also update the vendor record?

  3. Is the vendor contacted through an independently sourced telephone number?

  4. Is the person contacted authorized to approve banking changes?

  5. Is the confirmation documented?

  6. Is the new bank account independently validated?

  7. Are look-alike domains identified?

  8. Is the vendor notified after a change?

  9. Is the first payment reviewed separately?

  10. Are high-dollar electronic payments subject to enhanced approval?

  11. Can the organization identify every vendor changed during the last 30 days?

  12. Can management prove that each change was authenticated?

  13. Are duplicate bank accounts periodically analyzed?

  14. Does the organization have a rapid-response plan for payment fraud?

  15. Does the Accounts Payable team receive specialized BEC training?


An inability to answer these questions should be treated as a control warning.


The Most Important Lesson from Surfside Beach

The most important lesson is not that employees should read email addresses more carefully.


Careful review is useful, but it is not a sufficient safeguard against sophisticated impersonation.


The stronger lesson is: No email should have the authority to redirect a substantial vendor payment by itself.


A properly designed process assumes that:

  • An email account may be compromised.

  • A domain may be impersonated.

  • A signature may be copied.

  • A form may be fabricated.

  • A familiar conversation may be hijacked.

  • A telephone number in the request may belong to a criminal.

  • A persuasive message may be generated by AI.


The control environment should still prevent the money from leaving.


Register for Business Email Compromise—Accounts Payable

The Surfside Beach loss demonstrates that BEC is not an abstract cybersecurity scenario.


It is a direct threat to cash.


One fraudulent vendor change can:

  • Consume years of training budgets

  • Disrupt operations

  • Create litigation

  • Produce adverse audit findings

  • Damage public trust

  • Trigger insurance disputes

  • Require forensic investigations

  • Force an organization to pay a legitimate vendor twice


Corporate Compliance Seminars’ Business Email Compromise—Accounts Payable event on Friday, September 4, 2026, provides practical training for preventing these losses.


The program gives participants more than fraud awareness. It provides an implementable process, specialized instruction, and concrete templates that can be used to strengthen vendor-change controls immediately.


When a six-figure payment depends on the validity of one email, the organization does not merely have an email problem.


It has an internal-control problem.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page