Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Blog post2026-08-17By Securing Your Law Firm

A Town Lost $545,000 Over One Swapped Letter in a Domain Name

A South Carolina town paid $545,598 to a scammer using a typosquatted domain and a hijacked email thread. Here's the exact playbook – and the controls that stop it.

Surfside Beach, South Carolina has about 4,300 year-round residents. In March 2026, the town sent $545,598.30 meant for a contractor's utility project to a bank account in Utah that had nothing to do with the contractor.

According to reporting in the Wall Street Journal, nobody broke into the town's network. Nobody broke into the contractor's network, either. Both sides' IT teams checked. Neither found an intrusion. The money still moved – because a scammer registered a domain one character off from the real contractor's, inserted themselves into a live email thread about an actual invoice, and asked for the payment method to change.

The town's finance director later put it plainly: the paperwork "looked legit."

That's the entire point of a business email compromise attack, and it's the reason this story is worth reading closely even if your firm has never touched a municipal contract.

In this article:

  • What actually happened in Surfside Beach, based on WSJ reporting
  • Why "our network wasn't breached" doesn't mean a firm is safe
  • The specific, checkable controls that would have caught this before the money moved

What Actually Happened

The contractor, a North Carolina-based utility company, had been mid-project with the town for months – the kind of routine, recurring vendor relationship every business runs on. Somewhere in that relationship, a scammer gained enough visibility into the email exchange to time an attack around a real, expected payment.

They registered a domain that substituted a capital "I" for a lowercase "l" in the contractor's name – visually indistinguishable in many fonts – along with a second lookalike domain with an extra letter added to the town's own name. Using one of these, they inserted a message into the payment conversation asking the town to switch from a paper check to an electronic transfer, citing a policy change at the contractor.

The town's finance team followed a process: they checked that the routing information matched what looked like the company's, confirmed a signature against file records, and placed a phone call before authorizing the transfer. The call reached someone connected to the scam rather than the contractor's owner directly, and follow-up voicemails and emails to the real contractor never received a response – because the scammer was also intercepting incoming messages on their end of the fake domain.

By the time the discrepancy surfaced, roughly 45 days had passed. Per the FBI, recovery odds fall sharply once a BEC theft goes unreported for more than 72 hours – and by 45 days, meaningful recovery becomes unlikely. As of this writing, the funds remain missing and the contractor remains unpaid for completed work.

Why "It Looked Legit" Isn't a Defense

This is the detail that should concern every firm handling client funds, not just municipalities: the town did have a verification step. They called a number before wiring money. The process wasn't absent – it just wasn't independent of the compromised channel.

That's the recurring failure point in business email compromise, and it's exactly what the FBI's Cyber Enabled Fraud and Money Laundering Unit points to when it advises calling a number a business already has on file – not one provided in the email requesting the change, and not a number reached through the same thread the fraud arrived in.

A callback is only a real control if the number it dials was known before the suspicious message arrived.

The Same Playbook, Higher Stakes at a Law Firm

Municipalities move six-figure contractor payments. Law firms move six- and seven-figure real estate closings, M&A escrow, and settlement disbursements – on tighter timelines, with more parties in the email chain, and often under exactly the kind of "please expedite" pressure that made Surfside Beach's finance team move quickly rather than push back harder.

The mechanics transfer directly:

  • Lookalike domains work on law firms the same way they worked here – a client, opposing counsel, or title company won't necessarily notice one swapped character in a reply-all thread they've been on for weeks.
  • Thread hijacking doesn't require compromising your firm's systems at all. If a client's inbox, a title company's, or a co-counsel's is compromised anywhere in the transaction chain, an attacker can watch a real closing timeline and strike at the moment money is expected to move – exactly as reported here.
  • A callback that isn't independent is not a control. If the "verification" call is placed to a number that arrived by email, or reaches whoever answers rather than the specific person who's expected, it doesn't do the job it's meant to do.

Three Controls That Would Have Stopped This

None of these required predicting the attack. They required specific, checkable infrastructure:

  • Lookalike domain monitoring. A scan for domains registered to impersonate your firm or a frequent counterparty – the earlier a spoofed domain is found, the smaller the window an attacker has to use it. This is exactly what our Find Impersonating Domains and Clean Up Your Records engagement is built for.
  • Full DMARC enforcement, not just SPF/DKIM configured and forgotten. This is the control that stops an attacker from sending mail that appears to come directly from a domain you actually own – separate from the lookalike-domain problem, and just as commonly left half-configured. Bundled with a mailbox compromise check in Lock Down Your Firm's Email.
  • A documented, independent wire verification process – a known phone number, confirmed before any transaction begins, that never changes based on an email. This is the kind of procedure we build into a firm's Incident Response Plan, so it exists in writing before anyone is under pressure to move money quickly.

What Your Firm Can Check This Week

Surfside Beach had a process. It still lost $545,000. The gap wasn't effort – it was that the process relied on channels the attacker already controlled.

Ask this at your own firm: if a client, a title company, or opposing counsel emailed tomorrow asking to change how a payment moves, does anyone verify that through a channel the attacker couldn't have touched? And would your firm's own domain stop someone from sending that email as you in the first place?

If you're not sure, the free Proprietary Exposure Review shows the public spoofing and lookalike-domain signals attackers can already see – in minutes, with no access to your systems required.

This article is informational and does not constitute legal or compliance advice. Details regarding the Surfside Beach incident are drawn from reporting by the Wall Street Journal; the investigation into the incident remains ongoing.