Earlier this year, the City of Ocala sent $492,000 to what looked like a routine vendor payment. It wasn't. A scammer had taken over or spoofed a vendor's email and sent updated banking details, and the city's own accounts-payable process did the rest. Nobody hacked the city's network. Nobody had to. The city caught the fraud, worked with investigators and its insurer, and clawed back all but $27,000 of it. Two employees involved in processing the payment no longer work for the city.
The Ocala Metro Chamber and Economic Partnership, the area's own chamber-of-commerce-style economic development nonprofit, was not so lucky. In October 2024, a fake email impersonating a real vendor reached the CEP's CFO and board treasurer directly, not a junior clerk, and they wired $142,500 to the scammer's account. The money moved out through checks and ATM withdrawals within days. The man convicted for it was ordered to pay restitution of at least $100 a month on a $142,500 debt, which is a write-off in every way that matters.
Same scam. Same county. Two very different outcomes, and the only real difference between them was how fast each organization caught it.
What Actually Happened, in Both Cases
Someone sent a completely normal-looking email saying a vendor's bank account had changed, and a routine payment went to the new "vendor" instead. No malware, no break-in, nothing for antivirus or a firewall to catch, because the weak point was a person approving a payment they had every reason to trust. This is called Business Email Compromise, or BEC, and it doesn't need to break into anything. It just needs one convincing email and one routine approval.
What To Do About It
- Treat any "updated bank details" notice from a vendor as the one thing worth verifying by phone, on a number you already have on file, never one from the email itself.
- Speed is the whole story here. The organization that caught it fast got almost all of its money back. The one that didn't lost it for good.
- This is not a government-only risk or a large-organization problem. It reached a city accounting process and a nonprofit's CFO and board treasurer just as easily. A small business with the same routine vendor-payment process carries the same exposure.
One of the ways this fraud reaches a business is by spoofing your own domain or a vendor's, sending a lookalike email that appears to come from a real address. Whether your email is set up so an attacker can send fraud in your company's name is something you can check right now, for free.
Can someone send email pretending to be you? Run the free Email Security Check → For ongoing protection against vendor-fraud and phishing attempts aimed at your business, book a free 15-minute call. We serve small businesses throughout Marion County, FL and the surrounding area.