Business Email Compromise in Accounts Payable: What the $545,598 Surfside Beach Fraud Teaches Every Organization
- John C. Blackshire, Jr.

- Jul 24
- 12 min read
A single request to change a vendor’s payment method can expose an organization to a six-figure loss.
That is the central lesson from the Business Email Compromise incident that struck the Town of Surfside Beach, South Carolina, in 2026.
The municipality issued a $545,598.30 Automated Clearing House payment intended for Wildcat Contractors. The money was instead redirected to an account controlled by fraudsters. According to the Town, fraudulent communications began on March 9, 2026, and the payment was issued on March 13. The loss was not discovered until the contractor notified the Town on April 28 that it had not received the money.
The incident illustrates a critical weakness in many Accounts Payable departments:
Payment fraud does not necessarily require criminals to defeat the accounting system. They may only need to defeat the vendor-change process.
On Friday, September 4, 2026, Corporate Compliance Seminars will present the live online CPE event Business Email Compromise—Accounts Payable. The two-CPE program is designed to help Accounts Payable, finance, procurement, audit, compliance, and vendor-management professionals strengthen the controls used to authenticate vendors, process bank-account changes, and prevent fraudulent payments.
The course is taught by Debra R. Richardson, MBA, CFE, APM, APPM, CPRS, a recognized specialist in vendor setup, vendor maintenance, payment fraud prevention, and Accounts Payable internal controls.
What Happened at Surfside Beach?
Surfside Beach was making a legitimate payment to a legitimate contractor for legitimate work.
That is precisely what made the fraud so dangerous.
This was not an obviously suspicious invoice from an unknown company. The attackers inserted themselves into an existing commercial relationship and created communications that appeared connected to a real payment.
According to reporting by The Wall Street Journal, someone posing as an employee of Wildcat Contractors requested that the expected payment be changed from a check to an electronic transfer. The Town subsequently sent $545,598.30 to a Utah bank account that did not belong to the contractor.
The Town’s subsequent forensic review reported that:
The payment was issued on March 13, 2026.
Wildcat Contractors notified the Town on April 28 that it had not received the payment.
Fraudulent communications had begun on March 9.
Spoofed and typo-squatted domains were used.
One fraudulent domain added an “s” to the Town’s legitimate domain name.
Communications involving legitimate and fraudulent contractor domains contributed to the deception.
Investigators found no evidence that the Town’s Microsoft 365 accounts had been accessed without authorization.
The distinction is important.
A Business Email Compromise incident does not always require the victim organization’s email account to be hacked. Fraudsters may instead use:
Look-alike domains
Spoofed addresses
Compromised vendor accounts
Conversation hijacking
Social engineering
Fabricated banking forms
Information gathered from prior correspondence
This means that multifactor authentication, spam filters, cybersecurity awareness training, and endpoint security—although essential—are not sufficient by themselves.
The payment process must contain controls that operate outside the email conversation.
The Fraud Used Typosquatting to Defeat Visual Review
Typosquatting occurs when a criminal registers a domain that closely resembles a legitimate domain.
The difference may involve:
One added letter
One deleted letter
Two transposed letters
A capital “I” substituted for a lowercase “l”
A numeral substituted for a letter
A slightly different domain extension
An added hyphen or word
In the Surfside Beach incident, the Town reported that criminals created a domain adding an extra “s” to the legitimate Surfside Beach domain. The forensic findings also identified fraudulent communications involving look-alike Wildcat Contractor domains.
These domains can be extremely difficult to detect when employees:
Read email on mobile devices
Work under deadline pressure
Trust an existing email thread
See a familiar display name
Expect the underlying payment
Assume another employee already performed verification
The fraudulent message does not need to be perfect.
It only needs to appear sufficiently credible for the payment process to continue.
Why the Surfside Beach Incident Was a Business Process Failure—not Merely an Email Problem
Business Email Compromise is often classified as a cybersecurity risk.
That classification is incomplete.
BEC is also an:
Accounts Payable risk
Vendor-management risk
Procurement risk
Treasury risk
Internal-control risk
Fraud risk
Governance risk
Training risk
Cybersecurity personnel may block malicious attachments, identify suspicious logins, or detect compromised accounts. They ordinarily do not decide whether a vendor’s new bank account should be entered into the vendor master file.
That decision belongs to the business process.
The central control question is not simply:
Did the email look genuine?
The better questions are:
Was the change requested through an authorized channel?
Was the requester authenticated?
Was the vendor independently contacted?
Was a known telephone number used?
Was the bank account validated?
Did a second employee approve the change?
Was the vendor notified through a separate communication channel?
Was the first payment to the new account reviewed?
Did the payment file receive a final fraud-focused review?
A payment can be technically authorized within the accounting system while still being fraudulently redirected.
The Confirmation Call Must Be Truly Independent
Many organizations believe they have an effective control because employees make a confirmation call before changing vendor banking information.
The effectiveness of that control depends on how the telephone number is obtained.
An employee should not confirm a bank-account change by calling:
A number in the change-request email
A number on an attached banking form
A number supplied by the person requesting the change
A number found in the signature block of the suspicious message
A number included in a newly submitted vendor form
Those sources may all be controlled by the fraudster.
A more reliable confirmation call uses a telephone number obtained from an independently maintained source, such as:
The existing vendor master record
The original contract
A previously validated onboarding file
An established vendor portal
A known company representative
A reliable external validation source
The employee should also speak with a person authorized to approve payment-instruction changes—not merely whoever answers the telephone.
The CCS course directly addresses both the problem with email and the potential weakness in poorly designed confirmation calls. It provides a confirmation-call script, a call log, authentication references, vendor-validation resources, and desktop procedures for vendor inquiries.
The 45-Day Detection Delay Increased the Loss
The payment was made on March 13. The Town learned on April 28 that the contractor had not received it.
That delay reveals another important control issue.
Many organizations focus on preventing fraudulent payments but devote less attention to detecting them immediately after release.
Detective controls may include:
Vendor notification when banking data changes
Vendor notification when a payment is issued
Review of the first payment sent to a new account
Positive Pay or ACH debit and credit controls
Daily reconciliation of payment exceptions
Independent review of high-value electronic payments
Verification of unusual payment-method changes
Rapid escalation when a vendor reports nonpayment
The longer a fraudulent payment remains undetected, the more time criminals have to move the funds through additional accounts.
The control environment should therefore be designed around three objectives:
Prevent unauthorized vendor changes.
Detect suspicious payments immediately.
Respond rapidly enough to improve the possibility of recovery.
Business Email Compromise Exploits Normal Activity
Many frauds begin with obviously abnormal conduct.
BEC often does not.
The transaction may involve:
A real vendor
A real invoice
A real project
A real payment amount
A real payment deadline
A familiar employee name
A familiar email conversation
Only one element may have changed:
Where the money is sent.
This makes BEC especially dangerous because most traditional Accounts Payable controls are designed to verify that:
Goods or services were received.
The invoice is valid.
The amount is accurate.
The purchase was authorized.
The invoice was approved.
The payment is not a duplicate.
All of those conditions may be satisfied in a payment-redirection fraud.
The invoice is legitimate. The vendor is legitimate. The expense is legitimate. The payment is approved.
The bank account is fraudulent.
The Vendor Master File Is a Financial Control
The vendor master file is sometimes treated as an administrative database.
It should be treated as a high-risk financial asset.
The vendor master file determines:
Who can be paid
Where payments are sent
Which tax classifications apply
Which addresses are used
Which payment methods are authorized
Which banking instructions control disbursement
An unauthorized change to a vendor record can redirect every future payment, not just one transaction.
Effective vendor-master controls may include:
Restricted access
Segregation of duties
Required documentation
Independent vendor authentication
Bank-account validation
Duplicate-vendor testing
Change reports
Supervisory approval
Audit trails
Periodic data cleansing
Inactive-vendor reviews
Post-change notifications
Monitoring of the first payment after a change
The CCS program teaches participants how to implement up to six steps for reducing BEC and other payment fraud risks when remittance information is changed through email, fax, or paper-based requests.
Six Control Steps for Vendor Banking Changes
The appropriate process will depend on the organization’s systems, size, industry, and risk profile. A controlled vendor-bank-change process generally includes the following elements.
1. Separate the request from the approval
The employee receiving the request should not be able to complete the entire change without review.
Segregation may involve:
One employee receiving the request
Another authenticating the vendor
A third approving the master-file change
Treasury or Accounts Payable reviewing the payment
Smaller organizations may use compensating controls when staffing limits prevent complete segregation.
2. Authenticate the requester
Authentication asks: Is this person actually associated with the vendor and authorized to request the change?
Authentication may use:
Previously established contacts
Known telephone numbers
Secure portal credentials
Contract records
Preset passcodes
Challenge questions
Internal vendor ownership records
An email address alone is not sufficient authentication.
3. Validate the new information
Validation asks: Does the submitted information correspond to a real organization, bank, address, registration, or tax record?
Potential validation procedures include:
Confirming legal entity information
Reviewing tax documentation
Checking business registrations
Validating bank-routing information
Comparing country and geographic indicators
Investigating inconsistencies
Screening against internal and external watchlists
Authentication verifies the person. Validation evaluates the data.
Both are necessary.
4. Perform an independent confirmation
The vendor should be contacted using a trusted communication channel that was not supplied in the current change request.
The employee should confirm:
That the vendor requested the change
The effective date
The new payment method
The financial institution
The authorized requester
Any unusual differences in location or account ownership
The confirmation should be documented.
5. Approve and record the change
The approval should identify:
Who requested the change
Who authenticated the vendor
What sources were used
Who approved the change
When the change was entered
What record was changed
What exceptions were identified
How exceptions were resolved
The process should be auditable from beginning to end.
6. Monitor the first payment
A first payment sent to new banking information deserves heightened scrutiny.
The organization may:
Require a second approval
Limit the initial payment amount
Notify the vendor before release
Confirm receipt afterward
Review the payment against the approved change documentation
Hold unusually large changes for additional verification
The CCS course provides templates and resources intended to help participants implement these types of controls, including banking forms, validation references, confirmation-call tools, vendor notifications, payment-file reviews, and desktop procedures.
Why Cybersecurity Awareness Training Is Not Enough
Employees are often told to:
Avoid clicking unfamiliar links
Inspect email addresses
Watch for grammatical errors
Report suspicious attachments
Use strong passwords
Enable multifactor authentication
These practices remain important.
However, the Surfside Beach incident shows why Accounts Payable teams need specialized process training.
A fraudster may:
Avoid sending an attachment
Avoid requesting login credentials
Use polished language
Reference a real invoice
Know the project details
Participate in an existing conversation
Use a domain that appears nearly identical
Submit a realistic banking form
Request an operationally plausible change
The Vendor Process Training Center created by Debra Richardson emphasizes that vendor teams require training that begins where general cybersecurity awareness ends.
Its programs focus on authentication techniques, internal controls, best practices, and vendor validations designed to reduce fraudulent payments, compliance failures, and inaccurate vendor data.
Artificial Intelligence Is Making BEC More Convincing
Older phishing messages were often recognizable because they contained unusual grammar, awkward wording, or inconsistent formatting.
Generative AI can help fraudsters produce:
Professionally written emails
Plausible payment explanations
Industry-specific terminology
Realistic executive messages
Tailored vendor communications
Rapid responses during an active conversation
Messages written in the style of a known employee
AI can also assist criminals with open-source research, translation, impersonation, and social-engineering preparation.
The practical consequence is clear: Organizations cannot rely on spelling errors as a fraud-control system.
The strength of the control must come from the process, not from the employee’s ability to identify imperfect writing.
AI may also support fraud prevention by helping organizations:
Detect look-alike domains
Analyze unusual email patterns
Prioritize suspicious vendor changes
Identify abnormal payment behavior
Review duplicate bank accounts
Flag inconsistent addresses
Generate fraud-risk dashboards
However, technology should supplement—not replace—independent authentication and human review.
Internal Auditors Should Test the Entire Vendor-Change Process
Internal Audit should evaluate more than whether a policy exists.
Testing should determine whether the process works under realistic conditions.
Relevant audit questions include:
Can banking information be changed through ordinary email?
Who has access to modify vendor records?
Is access periodically reviewed?
Are requester identities authenticated?
Are independent telephone numbers required?
Are calls documented?
Can the person making the change also release the payment?
Are all changes reviewed?
Are vendor notifications sent?
Are high-value payments subject to additional controls?
Are the first payments to changed accounts monitored?
Are exception reports produced?
Are dormant vendors reviewed?
Are duplicate bank accounts identified?
Are vendor-change records retained?
Are incidents escalated immediately?
Has the process been tested using a simulated BEC scenario?
An audit that reviews only written procedures may miss the difference between a control that is documented and a control that is actually effective.
The Surfside Beach Case Demonstrates Why Every Organization Is Vulnerable
Municipalities are attractive BEC targets because they may:
Process large public-works payments
Publish contracts and project information
Work with numerous vendors
Operate with limited cybersecurity resources
Use decentralized approval processes
Face staffing constraints
Rely heavily on email
Maintain public employee contact information
The same vulnerabilities exist in:
School districts
Universities
Healthcare systems
Nonprofits
Construction companies
Manufacturers
Banks
Insurance companies
Government agencies
Professional-services firms
Public companies
Privately held businesses
Any organization that pays vendors can become a target.
Learn from Debra R. Richardson’s Accounts Payable and Vendor-Management Experience
The September 4 CPE event is taught by Debra R. Richardson, an Accounts Payable and vendor-process specialist with more than 20 years of experience at Fortune 500 organizations, including Verizon, General Motors, and Aramark. Her experience covers Accounts Payable, Accounts Receivable, general ledger, financial reporting, vendor maintenance, vendor onboarding, and vendor self-registration systems.
Debra’s professional credentials include:
Master of Business Administration
Certified Fraud Examiner
Accredited Payables Manager
Accredited Procure-to-Pay Manager
Certified Payments Risk Specialist
She has experience with widely used enterprise-resource-planning platforms, including SAP, PeopleSoft, NetSuite, Intacct, and Munis. She serves on the Nacha ACH Network Advisory Board, provides vendor-master-file expertise for the Institute of Finance & Management, and has been recognized repeatedly as a leading Accounts Payable influencer.
Her Vendor Process Training Center focuses exclusively on vendor onboarding and maintenance. The training model is based on transforming vendor teams from processors of requests into protectors of organizational payments and data through consistent authentication, validation, documentation, and internal controls.
This background is particularly relevant to BEC because payment fraud often begins where cybersecurity controls end and vendor-administration decisions begin.
What Participants Will Learn on September 4, 2026
The Business Email Compromise—Accounts Payable event is a two-hour live online program providing two NASBA-approved CPE credits in Auditing. It is designed for participants from basic through advanced levels and has no prerequisite or advance-preparation requirements.
Participants will learn how to:
Recognize common BEC and vendor-payment fraud schemes
Understand why email is an unreliable authentication method
Identify weaknesses in existing confirmation-call procedures
Implement up to six steps for vendor remittance changes
Authenticate vendor representatives
Validate vendor and banking information
Strengthen internal controls over vendor-master changes
Add an additional control to reduce the risk of significant payment losses
Review payments before transmitting the payment file
Notify vendors when information changes
Document vendor inquiries and confirmation calls
Build an auditable vendor-change process
Customize fraud-prevention templates for their organizations
The course includes practical resources such as:
An authentication reference
A vendor banking form
A vendor-validation reference list
Global vendor registration resources
A confirmation-call script
A confirmation-call log
A vendor change-notification process
A payment-file review procedure
A desktop procedure for vendor inquiries
Who Should Attend?
The event is relevant for professionals responsible for any part of the vendor-to-payment lifecycle, including:
Accounts Payable personnel
Vendor master data teams
Procurement professionals
Treasury personnel
Controllers
Finance managers
Internal auditors
External auditors
Fraud investigators
Compliance officers
Risk managers
Information-security personnel
Government finance employees
School-district finance teams
Higher-education administrators
Nonprofit financial managers
Managers should also consider registering multiple members of the vendor, procurement, and Accounts Payable teams.
A strong procedure can still fail when only one person understands it.
Questions Every CFO, Controller, and Accounts Payable Manager Should Ask
The Surfside Beach incident creates an opportunity for every organization to examine its own controls.
Management should ask:
Can a vendor change banking information through email?
Can the employee receiving the request also update the vendor record?
Is the vendor contacted through an independently sourced telephone number?
Is the person contacted authorized to approve banking changes?
Is the confirmation documented?
Is the new bank account independently validated?
Are look-alike domains identified?
Is the vendor notified after a change?
Is the first payment reviewed separately?
Are high-dollar electronic payments subject to enhanced approval?
Can the organization identify every vendor changed during the last 30 days?
Can management prove that each change was authenticated?
Are duplicate bank accounts periodically analyzed?
Does the organization have a rapid-response plan for payment fraud?
Does the Accounts Payable team receive specialized BEC training?
An inability to answer these questions should be treated as a control warning.
The Most Important Lesson from Surfside Beach
The most important lesson is not that employees should read email addresses more carefully.
Careful review is useful, but it is not a sufficient safeguard against sophisticated impersonation.
The stronger lesson is: No email should have the authority to redirect a substantial vendor payment by itself.
A properly designed process assumes that:
An email account may be compromised.
A domain may be impersonated.
A signature may be copied.
A form may be fabricated.
A familiar conversation may be hijacked.
A telephone number in the request may belong to a criminal.
A persuasive message may be generated by AI.
The control environment should still prevent the money from leaving.
Register for Business Email Compromise—Accounts Payable
The Surfside Beach loss demonstrates that BEC is not an abstract cybersecurity scenario.
It is a direct threat to cash.
One fraudulent vendor change can:
Consume years of training budgets
Disrupt operations
Create litigation
Produce adverse audit findings
Damage public trust
Trigger insurance disputes
Require forensic investigations
Force an organization to pay a legitimate vendor twice
Corporate Compliance Seminars’ Business Email Compromise—Accounts Payable event on Friday, September 4, 2026, provides practical training for preventing these losses.
The program gives participants more than fraud awareness. It provides an implementable process, specialized instruction, and concrete templates that can be used to strengthen vendor-change controls immediately.
When a six-figure payment depends on the validity of one email, the organization does not merely have an email problem.
It has an internal-control problem.
Comments