Madison Utilities in Madison, Alabama lost nearly $1 million earlier this year after falling for a phishing email — and in a rare twist, got every dollar back.
How the Madison Utilities Phishing Scam Worked
The utility was paying a contractor working on a capital project when an email arrived that looked like it came from the exact address they'd always sent payments to. There was just one change: the message asked them to change the routing number and bank account for the transfer. They complied — and the money went straight to scammers instead of the contractor.
This is a textbook case of business email compromise (BEC): criminals impersonate a trusted vendor, slip a single fraudulent instruction into a legitimate-looking thread, and redirect a payment.
This is why businesses should always be vigilant when responding to and conducting bank transactions based on emails.
A Rare Happy Ending
CEO Emory DeBord said the utility recovered the full amount after working with investigators, Regions Bank, and a cybersecurity firm. The FBI joined the investigation, and Madison police continue to look into the case.
Cybersecurity expert Shanon Driver of the Covenant Training Center called the recovery remarkable — in most cases like this, the money lands in an offshore account and disappears for good.
It Wasn't the Only One
DeBord compared the incident to what happened in Arab, Alabama earlier that same month, when the city lost over $400,000 in a similar scam.
How to Protect Yourself From Payment-Redirection Scams
- Never change payment details based on an email alone. Verify by phone using a number you already have — not one from the email.
- Look closely at the sender address for subtle spoofing or lookalike domains.
- Treat any "urgent" banking-change request as a red flag and slow down.
- Train everyone who handles payments to recognize business email compromise.

No comments:
Post a Comment