top of page

How a Typo-Squatted Domain Cost $540,000! (And Why SMBs Are Next)

  • kkelch3
  • 2 days ago
  • 3 min read

 

A deliberate typo overlooked


It only took one extra letter… A single character buried inside an email address; to redirect a town’s payment and drain $545,000 into a fraudster’s account. No breach, no ransomware, no compromised server. Just a believable email and a routine vendor update.


Most SMBs don’t realize they’re just as vulnerable.

 

Where Routine Becomes Risk

Every business, from construction firms to local service providers, relies on email to communicate with clients, vendors, and subcontractors. It feels harmless.


A vendor emails new banking details, an accountant updates the ACH information, and the payment goes out.


It’s fast, convenient, and part of everyday operations.


But this workflow hides a dangerous assumption:

that the person emailing you is actually who they claim to be.


Surfside Beach made that assumption. So do thousands of SMBs every day.


The Attack That Didn’t Need a Hack

Exploitation of Vendor Trust within the financial workflow


In March 2026, Surfside Beach, South Carolina attempted to pay Wildcat Construction for completed work. Attackers had quietly inserted themselves into the email thread using typo‑squatted domains including “surfsidesbeach.org” and fraudulent Wildcat lookalike domains.


According to the independent forensic report, “DFIR found no evidence of unauthorized access to any Surfside Beach Microsoft 365 accounts” (WBTW, 2026). The town wasn’t hacked; it was impersonated.


The attackers sent a forged ACH form, a fake callback number, and a Utah bank account. Believing the instructions were legitimate, the town sent $545,598.30 straight to the fraudsters.


Wildcat never received payment. Surfside Beach lost the money. And the insurer declined coverage.


Great American Insurance Group stated it “respectfully declines coverage” for legal fees and any third‑party claim alleging money owed — because the town’s cyber policy only activates if Surfside Beach is found legally liable (Insurance Business Magazine, 2026).


This is where the true story becomes a warning.


The Part of Cybercrime SMBs Never See Coming

The Surfside Beach case exposes a truth most SMBs haven’t been taught: Cybercrime doesn’t need to hack your systems: it only needs to hack your trust.

Typo‑squatted domains, spoofed email threads, and fraudulent ACH instructions bypass technical defenses entirely.


They exploit human workflows, especially in finance departments where vendor updates are routine and verification steps are often skipped.

And here’s the part SMBs rarely hear: ACH fraud is not an IT failure. It’s a finance‑workflow failure.


Funds intended for services were redirected unintentionally


The attackers didn’t breach Microsoft 365. They didn’t bypass MFA. They didn’t compromise endpoints.


They simply convinced someone to change banking details without realizing it.


This is why SMBs are next. Construction firms, HVAC companies, landscaping businesses, local contractors all operate in environments where email is trusted implicitly and ACH changes are handled casually. Wildcat Construction’s own domain was spoofed, and legitimate emails were intermixed with fraudulent ones, creating what investigators called “shared victimhood.”


For SMBs, this means two things:

  1. Your domain identity is part of your security perimeter. If attackers can impersonate you, they can steal from your clients.


  2. Your ACH workflow is part of your cybersecurity posture. If your finance team accepts banking changes via email, you’re exposed.


The Lesson Behind That $545,000 Loss

The Surfside Beach fraud didn’t happen because someone clicked the wrong link or ignored an alert. It happened because a routine business process was built on trust instead of verification. That’s the real danger for SMBs: the attacks that feel like normal work.


If a single typo‑squatted domain can steal $545,000 from a town, imagine what it could do to a business without dedicated security guidance. Cybercriminals aren’t breaking in — they’re blending in. And the only way to stop them is to question the emails that look the most ordinary.



As a Managed Service Provider (MSP), we at Runtime Cyber Defense (RCD) step in — not to run your accounting department, but to protect the identity layer around it. Domain monitoring, DMARC enforcement, secure vendor communication channels, and BEC‑focused security awareness training are now essential tools for preventing fraud that never touches your network.


Follow our link to the RCD main webpage here to explore or request a free assessment any time!


By Kenny Kelch Cybersecurity Analyst & Problem Solver, Runtime Cyber Defense (RCD)


References:

Insurance Business Magazine. (2026). What a $545,000 email scam in a South Carolina beach town reveals about municipal coverage gaps. https://www.insurancebusinessmag.com/us/news/cyber/what-a-545000-email-scam-in-a-south-carolina-beach-town-reveals-about-municipal-coverage-gaps-583466.aspx


WBTW News13. (2026). Surfside Beach releases findings from independent review of missing $545,000 payment to North Carolina contractor. https://www.wbtw.com/news/grand-strand/surfside-beach/surfside-beach-releases-findings-from-independent-review-of-missing-545000-payment-to-north-carolina-contractor/

 

 
 
 
runtime cyber defense logo
IF YOU CONNECT IT, WE PROTECT IT
Connect With Us

2 Corpus Christi Place, Suite 200

Hilton Head Island, SC 29928

Phone: 623-777-9242

Email: info@runtimecyber.com

  • LinkedIn
  • Facebook
  • Twitter

Veteran Owned Small Business

shutterstock_2036832791.jpg
Schedule Your
FREE Consultation 
bottom of page