Rss.Slashdot Email Scam Costs South Carolina Town $545K via Typo-Squatting
Article Content
- •Surfside Beach lost over $545K due to a business email compromise scam.
- •Fraudsters used a lookalike domain to impersonate the contractor's email.
- •The town's insurer initially denied coverage, complicating recovery efforts.
Surfside Beach, South Carolina, lost $545,598.30 due to a business email compromise scam. A fraudster impersonated the contractor Wildcat Contractors by using a lookalike email domain, tricking the town into changing a payment method to an electronic transfer. The scammer's domain included a capital 'I' instead of a lowercase 'l', making it difficult to detect. The town's finance director confirmed that a payment was made to a fraudulent account in Utah instead of to Wildcat. Both the town and the contractor are now disputing liability, with the town's insurer initially refusing to cover the loss. Investigations revealed that the scammers used spoofed email domains and forged documents to facilitate the fraud. The town is working with law enforcement and has implemented new security measures to prevent future incidents.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Surfside Beach in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…