Coastal SC town reckons with fallout of $500K+ cyberscam | #cybercrime | #infosec


SURFSIDE BEACH — Surfside Beach is a golf cart kind of town: Small enough that folks navigate them to the local Piggly Wiggly or Neal and Pam’s Bar and Grill.

But for the past month — and stung by the loss of more than a half million dollars at the hands of cyber thieves — leaders in the quaint coastal getaway are reckoning with a new digital ecosystem and old-fashioned fears.

“I can tell you, I get stopped on the street every single day and I’m asked, ‘How did we hit the button to send the money without talking to a human being?'” councilman Rick Lawhorn said.







Surfside Beach Town Councilman Rick Lawhorn, left, and Mayor Robert Krouse discuss a cybercrime investigation on July 28, 2026. 



A detailed forensic report made it clear how cyber scammers recently were able to intercept $549,000 meant for utility work and instead park it at a Utah bank — that’s about 2.5 percent of the town’s $20.7 million 2026-27 budget. 

As for the why? That’s what a newly formed tribunal is planning to find out. Town leaders voted 5-2 on July 28 to form an investigative body, with plans to speak with experts in accounting, cybercrime and other areas in public forums. 

“I’m not interested in retracing law enforcement’s steps,” councilman John Hiatt said. “There’s $545,000 of the public’s money that’s unaccounted for, and I think we need to be a bit of a bulldog in getting to the bottom of everything that’s impacted this loss.”

Policies not followed

Residents agree.

“I don’t think most doubt there was a scam, the problem is twofold. First, it could have been easily prevented if the proper full verification was completed,” Colette Huttenlocher-Phillips said in a Facebook comment. “Attempting to do a verification process is not the same as completing that process. An unanswered phone call just doesn’t cut it. There’s no acceptable excuse here for why simple measures were bypassed.”

Surfside Beach officials sent a $549,000 payment in mid-March to Gastonia, N.C.-based Wildcat Contractors for underground utility work it had completed. 

Only the money never hit Wildcat’s account. Instead, a simple but devastatingly effective cyberattack weaved its way between the transaction. The FBI calls it “business email compromise.”

To date, the family-owned business still hasn’t been compensated.

“I have read what Surfside has chosen to publish and see they have selected to disclose only certain emails that support their narrative, which have not been validated as authentic and/or from Wildcat servers,” CEO Alyssa Bowker told The Post and Courier. “Surfside never verbally confirmed with me or anyone at Wildcat that the ACH change was legitimate.”

More commonly known as “URL hijacking,” Microsoft says typosquatting involves intentionally misspelling another organization’s domain in a subtle way. A scammer might substitute a zero for the letter “o” or add letters to the middle or end of a name, for instance. Thieves also requested that the town move away from sending an electronic check and use an ACH payment instead.

Also known as an “automated clearing house,” ACH transactions allow funds to move from one account to another — payroll departments and mortgage companies rely on them. 

Internal documents show that Surfside Beach violated its own cash handling policy, which limit ACH payments to $200,000.

“Anything over that must be in the form of a check unless written approval from town administrator and finance director is received and extensive verification is done before processing,” the town’s policy says.

Bowker said those basic failsafes were missed.

“Confirming modifications to payment instructions over the phone is a standard and widely accepted business practice that Surfside failed to follow,” she said.

Councilman Skip Wells said his bank will run a test ACH payment of a $1 even before transferring funds for a modest cable bill.

“I don’t understand how that didn’t happen, especially with this much money,” he said.

An invisible enemy

A May report by nonprofit think tank Information Technology and Innovation Foundation said state and local governments are particularly vulnerable to phishing attacks because of aging IT systems, inadequate training and understaffing. 

“State and local governments consistently face significant resource and capacity constraints that impede the implementation and maintenance of effective cybersecurity programs. Many agencies operate with understaffed teams, aging infrastructure, and weak or reactive incident response systems. These limitations leave governments dangerously exposed to cyber adversaries capable of crippling essential services, stealing sensitive data, and eroding public trust,” the report said.

Through its Municipal Association of South Carolina membership, Surfside Beach is eligible for a limited amount of cybersecurity coverage through the state Municipal Insurance and Risk Financing Fund — but only for about $100,000.

 At a minimum, cyber carriers expect cities to take these steps:

  • Have multifactor authentication in place.

  • Use Microsoft Office 365 as well as Office 365 Advanced Threat Protection.

  • Pre-screen emails for malicious attachments and links.

  • Back up key servers and data at least monthly.

  • Use isolated backups that aren’t connected to the city’s network.

  • Regularly test restoring data and information backups.

  • Conduct regular phishing training.

“If a municipality doesn’t have those controls in place, they may be ineligible for coverage or they may face higher premiums and deductibles,” the association says.

Lawhorn and other town leaders said it was critical their work be held in public.

“We owe the citizens that much,” he said. “We have an oversight responsibility and frankly up to this point, I think we’ve taken too long to do that. I’m after what happened, and how we ensure it doesn’t happen again.”





Click Here For The Original Source.

——————————————————–

..........

.

.