Back to news
Cybersecurity Alert
July 25, 2026 by EmailMeNow IT Consulting

Surfside Beach Lost $545K to Email Scam — Municipal Coverage Gaps and NRD Defenses

Surfside Beach lost $545,598.30 via ACH on March 13, 2026 after both lookalike domains registered March 9. As of Jul 25, neither the town nor Wildcat has neutralized the squats — both still have live MX. Audits: vendor squat 47%, town squat 43% — none at the 100% ideal.

Source: Insurance Business

NewsBusiness Email CompromiseMunicipalCyber InsuranceNewly Registered DomainsTyposquattingMicrosoft 365Google WorkspaceSouth CarolinaCybersecurity
Municipal finance desk with a suspicious ACH payment email and lookalike domain warning

A $545,598.30 contractor payment from Surfside Beach, South Carolina never reached the builder. Attackers slipped into the email thread using lookalike domains for both sides — the town and its contractor — swapped ACH instructions to a Utah account, and left a small beach town and its insurer arguing over whose fault it was.

Insurance Business (July 23, 2026) framed the case as a textbook business email compromise (BEC) — and a warning that “cyber coverage” often is not social-engineering coverage. Local reporting documents a town typosquat surfsidesbeach.org and a vendor lookalike spelling “Wildcat” with an extra “i” (Post and Courier; WMBF).

Our July 25, 2026 RDAP check shows both squats were registered on March 9, 2026 — the vendor squat wiidcatcontractors.com first (16:57 UTC, Wild West Domains), then the town squat surfsidesbeach.org (~2 hours later, 18:48 UTC, Name.com). The town’s ACH of $545,598.30 went out four days later, on March 13, 2026.

More than four months later, neither the town nor Wildcat appears to have gotten either squat disabled. Both domains are still registered, still publish live MX, and can still send or receive mail that looks like the real parties — so the same payment thread remains exposed, and other vendors or municipalities that deal with either organization are still at risk of a repeat.

This is not a duplicate of our cyber insurance controls or Seventh Circuit BEC denial posts — those cover renewals and case law. This piece is the Surfside Beach municipal loss, how email providers handle Newly Registered Domains (NRDs), and a practical typosquat response playbook (triage → abuse takedown → UDRP/URS → ACPA → brokered buy).

Municipal finance desk with a suspicious ACH payment email and lookalike domain warning

Snapshot

FieldDetail
Victim (payer)Town of Surfside Beach, SC (~4,300 year-round residents)
Intended payeeWildcat Contractors (Gastonia, NC) — Ocean Blvd underground utilities
Amount / ACH date$545,598.30 sent March 13, 2026
Fraud typeBEC / vendor payment diversion
Vendor squat registeredwiidcatcontractors.comMarch 9, 2026 16:57 UTC (Wild West Domains, LLC)
Town squat registeredsurfsidesbeach.orgMarch 9, 2026 18:48 UTC (Name.com, Inc.) — ~2 hours after the vendor squat
Gap to payment4 days (register March 9 → ACH March 13)
Lookalike status (Jul 25, 2026)Both still liveno evidence the town or Wildcat has suspended either squat; no website, but live MX (town → Google, vendor → Microsoft 365)
Exposure if left upAnyone still emailing either party can be pulled into a repeat lookalike thread; mail filters that do not block these domains stay vulnerable
DestinationFraudulent account in Utah; LA callback on forged ACH form
Discovery lag~45 days before the hole was clear (Insurance Business); LE contacted late April
InvestigationsFBI, SLED, town/insurer forensics
Pool cyber base (SC typical)South Carolina Municipal Insurance and Risk Financing Fund — about $100,000 direct cyber, optional commercial layer

How the scam worked

StepWhat happened
1. Live threadTown public works and Wildcat were mid-project on payment #4.
2. InsertScammers joined the conversation using lookalike domains that passed the eyeball test — impersonating the town to the vendor and the vendor to the town.
3. Switch channelAsked to change from check to electronic transfer.
4. Forged ACHForm looked “legit” — Utah bank, LA number, signature reportedly copied from another document.
5. Town paidFinance processed the ACH; money never hit Wildcat.
6. Blame fightMayor: town followed process. Contractor: they got scammed. Coverage may hinge on who was compromised.

Kroll’s Dave Burg described the pattern: attackers watch quietly, set rules on payment keywords, and divert real replies so each side only sees the scammer’s version of the thread. Huntress’s Ben Bernstein called the lookalike domain subtle enough to pass a human glance.

Lookalike email diverting a contractor ACH payment to a fraudulent bank account

Why the insurance response is complicated

BEC sits at the intersection of three different triggers — they are not interchangeable:

Coverage typeTypically responds when…
Social engineering fraud (crime / cyber)An employee is deceived into authorizing a transfer — even with no system breach
Funds transfer fraudUnauthorized transfer, often needing some system compromise element
LiabilityPolicyholder is found legally at fault

Surfside Beach’s carrier narrative, as reported, tracks closer to liability: coverage discussion focuses on whether the town is at fault, not simply that $545K is gone. That is the opposite of what many councils assume when they hear “we have cyber.”

Scale makes it worse for small publics. A $100K pooled cyber base cannot absorb a $545K ACH diversion — even if every layer responds cleanly. Coalition’s 2026 claims data (cited by Insurance Business) put BEC + funds-transfer fraud at 58% of cyber incidents in 2025.

Speed is a recovery control: the FBI has said funds are recovered in roughly 75% of BEC cases reported within 72 hours. Waiting weeks collapses those odds.

Newly Registered Domains — why this case matters

Attackers frequently use Newly Registered Domains (NRDs) for short-lived phishing and payment-fraud campaigns. Here the window was concrete: both lookalikes registered on March 9, and the ACH cleared on March 13 — a four-day NRD window that native “first contact” tips and third-party domain-age banners are built to catch.

Timeline (registration → payment)

When (UTC / local reporting)What happened
March 9, 2026 — 16:57 UTCVendor squat wiidcatcontractors.com registered (Wild West Domains, LLC) — RDAP
March 9, 2026 — 18:48 UTCTown squat surfsidesbeach.org registered (Name.com, Inc.) — RDAP; ~2 hours later
March 9, 2026Fraudulent email activity begins (investigators / local reporting)
March 13, 2026Town sends $545,598.30 ACH intended for Wildcat; funds diverted
~April 27–28, 2026Wildcat reports non-payment; town escalates to LE / insurer
July 25, 2026Both squats still registered with live MX; neither party has publicly neutralized them (~138 days after registration)

Both squats are still live — and neither party has shut them down

Reporting describes lookalikes on both sides of the thread: a town typosquat (extra ssurfsidebeach.orgsurfsidesbeach.org) and a vendor typosquat (“Wildcat” written with an extra / substituted i — live domain wiidcatcontractors.com). RDAP + DNS on July 25, 2026 confirm both are still registered, each with no website but working mail routing.

That is not a closed incident. The town and the contractor do not own these domains — attackers do — but neither organization appears to have completed an effective disablement (registrar abuse suspension, hoster takedown, or UDRP/URS transfer). Until that happens, the infrastructure used to divert $545K can still be reused against:

Who remains exposedWhy
Surfside Beach finance / public worksTown squat can still pose as municipal mail in vendor threads
Wildcat Contractors and its other clientsVendor squat can still pose as Wildcat in ACH / invoice threads
Any municipality or GC paying WildcatSame “extra i” lookalike works on the next project
Mail tenants that never blocked these domainsFirst-contact tips help; an explicit block list is stronger
Impersonated partyReal domainSquat domainRegistered (RDAP)RegistrarWebsiteMXDisabled by victim?
Wildcat Contractorswildcatcontractors.comwiidcatcontractors.com2026-03-09 16:57 UTCWild West Domains, LLCNoneLive → Microsoft 365No — still answering DNS
Town of Surfside Beachsurfsidebeach.orgsurfsidesbeach.org2026-03-09 18:48 UTCName.com, Inc.NoneLive → GoogleNo — still answering DNS

That pattern — no site, live MX, months after a public loss — is why lookalikes stay dangerous long after headlines fade. Both squats can still send and receive mail. Treat an MX-on lookalike as open BEC staging until the registrar suspends it, not as a harmless parked name.

The vendor squat also shows why one-sided defenses fail: hardening only the town domain would not have blocked a fraudulent “Wildcat” sender, and vice versa. Both parties in a payment thread need lookalike monitoring and a takedown path. Leaving either squat up after a $545K diversion keeps the same attack surface available for a second hit.

None of the major consumer or business mail platforms offer a native end-user toggle that says “Warn me if this domain is under 30 days old.” Domain age is either baked into backend reputation or requires admin + third-party tooling for an explicit banner.

Email client showing first-contact and newly registered domain caution banners

How email providers handle NRDs

Platform comparison (quick read)

PlatformNative “under 30 days” toggle?Best native controlExplicit NRD banner
Microsoft 365NoFirst contact safety tip + Defender NRD scoring / quarantineThird-party CESS (Abnormal, Mimecast, Avanan, etc.)
Outlook.com / HotmailNoEOP reputation → Junk / blockUncustomizable safety bars only
Google WorkspaceNoAdvanced phishing & malware protection (spoof / unauth warnings)Third-party CESS (Cyren, Proofpoint, Avanan, etc.)
Personal GmailNoSafe Browsing / reputation → Spam or danger bannerNone you can customize
Proton MailNoPhishGuard (auth fail / suspicious source banners)No third-party inbox API scanners; Sieve cannot WHOIS

Microsoft 365 / Office 365 (business)

ControlWhat to do
First contact safety tipDefender → Email & collaboration → Policies & rules → Threat policies → Anti-phishing → enable tip. Shows: “You don’t often get email from [sender]. Learn why this is important.” Covers first-seen senders — including most NRDs.
Backend NRD tagDefender ML heavily penalizes brand-new domains (often quarantine). Admins see “Newly registered domain” in investigations — but cannot build Exchange mail-flow rules solely on that tag today.
Explicit NRD bannerConnect a Cloud Email Security Supplement (Abnormal Security, Mimecast, Avanan, etc.) via Graph / API to inject “CAUTION: Newly registered domain” HTML before delivery.

Personal Outlook.com / Hotmail

You do not get Defender admin or custom mail-flow rules. Rely on Exchange Online Protection: zero-reputation NRDs usually land in Junk or are blocked. If mail reaches the inbox, Outlook may show red/yellow bars for failed SPF/DKIM or poor reputation — you cannot customize those.

Google Workspace

ControlWhat to do
Advanced phishing protectionAdmin console → Apps → Google Workspace → Gmail → Safety → Advanced phishing and malware protection. Under spoofing/authentication, set action to Keep email in inbox and show warning for weak/unauthenticated senders.
Explicit NRD bannerCESS tools (Cyren, Proofpoint, Avanan, etc.) check WHOIS age and inject a custom caution banner when registration is under ~30 days.

Personal Gmail

No Admin console and no third-party API scanning of your inbox. Google’s reputation stack usually Spam-folders or danger-banners brand-new domains with links/attachments. You cannot build a domain-age filter — do not whitelist unknown payees.

Proton Mail

Privacy-first: third parties cannot scan your inbox via API. PhishGuard shows a bright red banner when authentication fails or the source looks suspicious (including many no-reputation domains): “This email has failed its domain’s authentication requirements…” Custom Sieve filters can read headers/body but cannot call WHOIS, so you cannot hand-build an NRD rule.

Recommendation (all providers)

Who you arePractical move
M365 or Google Workspace adminTurn on First contact / Advanced phishing warnings now; add a CESS if you need an explicit “under 30 days” banner on vendor ACH threads.
Outlook.com / Gmail / Proton personalRely on native reputation + PhishGuard; treat any payment-change email as hostile until verified out-of-band.

What to do when you find a typosquat of your domain

Finding a typosquatted version of your domain — like surfsidesbeach.org next to surfsidebeach.org, or wiidcatcontractors.com next to wildcatcontractors.com — can be alarming, but you have several paths to neutralize the threat. The best approach depends on whether the domain is actively used for phishing / BEC, simply parked, or being held for ransom.

Do not tip off the squatter too early. Reaching out before you lock down evidence can raise their asking price or make them hide tracks (privacy WHOIS, move hosting, drop MX).

1. Immediate triage (before outreach)

StepWhy it matters
Screenshot any live site, login page, or mail-related contentPreserves evidence before the page disappears
WHOIS capture (registrar, registrant, dates, name servers)Document details before privacy locks or ownership flips
Check MX / SPF / DKIMActive MX often means the domain is staged for phishing or BEC — treat as incident, not a parked nuisance
Note hosting / CDN IPsNeeded for hoster abuse reports
Alert finance / mail adminsBlock the lookalike in Defender / Workspace; warn staff not to reply to that domain

If the domain hosts malware, a fake login, or your logos / copyrighted materials, you often do not need a lawsuit first:

ChannelAction
Registrar abuseFrom WHOIS, open the registrar’s abuse form (GoDaddy, Namecheap, etc.) and cite phishing / ToS violations
Hosting / CDN abuseSend a takedown or DMCA notice for infringing brand assets on the live site
Mailbox providersReport phishing URLs to Microsoft, Google, and your CESS vendor so messages from that domain are blocked

3. Administrative actions (ICANN policies)

If the domain is parked or only shows generic ads — not yet overtly illegal — use ICANN dispute processes:

PathBest forYou must show (summary)Typical result
UDRP (often via WIPO)Most brand lookalikes(1) Identical / confusingly similar to a mark you own; (2) registrant has no rights / legitimate interest; (3) registered and used in bad faithDomain transferred to you or cancelled
URSClear-cut, urgent abuseHigher burden — indisputable cybersquattingDomain temporarily suspended (not transferred)

UDRP is the common municipal / SMB route when you hold a protectable mark and the lookalike was clearly registered to confuse. URS is faster and cheaper but does not hand you ownership.

4. Civil litigation (U.S. — the heavy hammer)

ToolNotes
ACPA (Anti-Cybersquatting Consumer Protection Act)Civil suit when registration shows bad-faith intent to profit from your mark
ProsCourt can order transfer / cancellation; possible statutory damages
ConsCostly and slow vs UDRP — reserve for high-value brands or stubborn squatters

Municipalities and small contractors should get trademark / IP counsel before filing; many Surfside-style lookalikes are better handled first via abuse reports + UDRP, while payment callbacks stop the ACH bleed.

5. Negotiation and acquisition

Sometimes buying the domain is cheapest — with caveats:

DoDon’t
Use a third-party domain broker so the seller does not know a brand / city is the buyerContact the squatter directly as “Town of …” or “Acme Corp legal”
Cap what you will pay; treat it as risk spend vs a $545K ACH lossAssume payment ends future squatting — paying can mark you as a willing buyer

Choose a path by domain state

Domain statePrefer
Active phishing / BEC MXImmediate triage → registrar/host abuse → mail blocks → law enforcement if funds moved
Parked / ads onlyEvidence pack → UDRP (or URS if slam-dunk)
Ransom / “buy it or else”Brokered negotiation or UDRP/ACPA — do not escalate price with emotional outreach
Your own defensive registrationsRegister common typos (extra letters, I/l, rn/m) before attackers do

Expanded remediation list (municipal + email providers)

Payment & process (coverage-preserving)

  1. Call a known number before any ACH / wire / account-change — never the number in the email (FBI guidance echoed after this incident).
  2. Dual control on vendor banking changes (finance + public works / manager).
  3. Password-protect large contract PDFs and ACH forms; treat “urgent switch to ACH” as a fraud signal.
  4. 72-hour clock — escalate to bank recall + FBI IC3 the same day a diversion is suspected.
  5. Read the policy — confirm whether you have social engineering, funds transfer, or only liability triggers; note $100K pool sublimits vs real ACH sizes.
  6. Tabletop the Surfside scenario with council and the risk pool broker before renewal.

Microsoft 365 / Defender

  1. Enable First contact safety tip on anti-phishing policies.
  2. Review Defender threat explorer for Newly registered domain tags on vendor mail.
  3. Enforce DMARC reject + MTA-STS on the municipal domain; monitor for lookalike registrations.
  4. If explicit NRD banners are required, deploy Abnormal / Mimecast / Avanan (or equivalent) and test on a payment-change mailbox.

Google Workspace

  1. Harden Advanced phishing and malware protection; show warnings for unauthenticated / similar-domain mail.
  2. Add Proofpoint / Cyren / Avanan (or equivalent) for WHOIS-age banners on finance shared inboxes.

Personal Gmail / Outlook.com / Proton

  1. Never whitelist contractor domains from a single thread.
  2. Use Proton PhishGuard banners and Gmail/Outlook danger bars as stop signs — then verify by phone.
  3. Prefer a managed Workspace / M365 tenant for any public entity or firm that moves six-figure ACH.

Identity & domain hygiene (Texas & SC publics alike)

  1. Monitor for typosquats of your .org / .gov / .com (extra letters, I/l, rn/m).
  2. On discovery: screenshot, WHOIS, and MX check before any contact with the registrant.
  3. If MX is live or phishing is up: file registrar + hoster abuse the same day; block the domain in mail filters.
  4. For parked brand lookalikes: prepare a UDRP (or URS) package; reserve ACPA for stubborn / high-value cases.
  5. Prefer a domain broker if you must buy — never negotiate as the obvious brand owner.
  6. Publish clear payment-change procedures on the website so staff have a known process to cite.
  7. Train that lookalike + urgency + ACH change is BEC until a callback proves otherwise.

Why Texas cities and special districts should care

Texas municipalities, ISDs, MUDs, and hospital districts face the same pattern: modest pooled or layered cyber limits, vendor ACH during construction season, and insurers that ask who was compromised before paying. A Surfside-style loss can exceed the cyber sublimit in a single transfer — and a 45-day discovery window wrecks FBI recovery odds. Leaving the lookalike domains up for months afterward, as both Surfside Beach and Wildcat still have, means the next ACH season starts with the same weapon still loaded.

Pair payment callbacks with NRD-aware mail controls on Microsoft 365 or Google Workspace, and finish the job: block + suspend known squats until MX disappears. Personal Gmail/Outlook/Proton are fine for individuals — not for six-figure public payments.

Independent cybersecurity audits

We audited domains tied to this story and the email-provider remediation stack on July 25, 2026, including fresh checks of both reported typosquats (town and vendor — both still registered). 100% is the ideal overall score — none reach it. Scores reflect public email / transport / website posture, not whether a specific ACH was diverted.

The four domains at the center of the thread

RoleDomainOverallIdentityTransportWebsitevs 100% ideal
Vendor (real)wildcatcontractors.com71%95%15%40%−29
Town (real)surfsidebeach.org60%50%15%65%−40
Vendor squatwiidcatcontractors.com47%35%15%40%−53
Town squatsurfsidesbeach.org43%25%15%40%−57

Every one of the four sits at transport 15% — no enforced MTA-STS / TLS-RPT on the public mail path. The real domains score higher on identity (Wildcat 95%, town 50%) than their squats (35% / 25%), but identity strength on your own domain does not stop a different domain from sending convincing mail.

Full audited set

OrganizationDomainOverallIdentityTransportWebsitevs 100% ideal
Proofpointproofpoint.com79%70%40%97%−21
Huntresshuntress.com78%65%40%100%−22
Protonproton.me74%50%100%98%−26
Wildcat Contractors (real)wildcatcontractors.com71%95%15%40%−29
Insurance Businessinsurancebusinessmag.com69%90%15%40%−31
Microsoftmicrosoft.com68%90%70%45%−32
FBIfbi.gov66%75%45%45%−34
Krollkroll.com62%75%15%37%−38
Abnormal Securityabnormalsecurity.com60%65%50%37%−40
Town of Surfside Beach (real)surfsidebeach.org60%50%15%65%−40
Outlook.comoutlook.com53%50%100%37%−47
Googlegoogle.com52%50%70%45%−48
Vendor squat (live)wiidcatcontractors.com47%35%15%40%−53
Mimecastmimecast.com46%25%50%45%−54
Town squat (live)surfsidesbeach.org43%25%15%40%−57
Office.comoffice.com38%25%55%45%−62

How to read this table

  • Both squats are still live — and neither victim has shut them down. wiidcatcontractors.com (47%) was registered March 9, 16:57 UTC and still routes mail via Microsoft 365; surfsidesbeach.org (43%) was registered March 9, 18:48 UTC and still routes via Google. Neither serves a website. More than four months after the March 13 ACH, public DNS shows no suspension — so the town, the contractor, and anyone emailing either party remain likely still vulnerable to the same lookalike play.
  • wildcatcontractors.com posts the strongest identity in this set (95%) yet still lands at 71% because transport is 15% — strong SPF/DKIM/DMARC does not fix an unencrypted-by-default mail path or block a lookalike sender.
  • surfsidebeach.org at 60% (−40 from ideal) with transport 15% is relevant for spoofed “town finance” follow-ups, separate from who bears the ACH loss.
  • proton.me leads consumer privacy mail here at 74% with transport 100%; it still has no custom NRD WHOIS filter.
  • microsoft.com / google.com corporate scores are not your tenant’s Defender/Workspace posture — turn on the admin controls above.
  • Security vendors (Proofpoint, Huntress, Abnormal, Mimecast) are included because they are the practical path to explicit NRD banners.

Audit links

Website stack note

Passive website-tech probes on July 25, 2026 completed for story domains (0 notable among reachable hosts):

DomainStack signal
wildcatcontractors.comSquarespace — vendor-managed core; still review apps and admin MFA
abnormalsecurity.comNext.js (version not exposed)
kroll.comNext.js (version not exposed)
proofpoint.comDrupal (version hidden)
surfsidesbeach.org (town squat)No HTTP(S) A record — site unreachable; MX live (Google); not disabled as of Jul 25
wiidcatcontractors.com (vendor squat)No HTTP(S) A record — site unreachable; MX live (Microsoft 365); not disabled as of Jul 25
All others in this setNo notable public CMS / PHP / short-horizon TLS flags

Hidden CMS versions are common on marketing sites. They do not explain the Surfside Beach ACH diversion — that attack abused lookalike / newly registered domains and payment-process trust, not a public CMS fingerprint. The real signal here is that both squats have no website but working mail — the artifact defenders should act on (block the domains in mail filters, file registrar abuse).

These passive observations are point-in-time public signals. They do not prove exploitability or identify a breach path.

Priority actions for IT and finance teams

  1. Callback every payment-change email on a number from the vendor master file — not the message.
  2. Enable First contact / Advanced phishing warnings on M365 or Workspace this week.
  3. Budget a CESS if council needs explicit Newly registered domain banners on finance mailboxes.
  4. Map insurance triggers (social engineering vs liability) and sublimits before the next ACH season.
  5. Hunt lookalikes of your domain; on find, triage (WHOIS/MX) → abuse takedown or UDRP — do not tip the squatter first.
  6. Do not leave known BEC squats live — after an incident, treat open MX on lookalikes as unfinished IR; block them in mail and push registrar suspension until DNS dies.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for municipal BEC hardening, Defender / Workspace NRD controls, DMARC / MTA-STS, and policy-readiness work aimed at the 100% ideal.


Sources: Insurance Business — What a $545,000 email scam in a South Carolina beach town reveals about municipal coverage gaps · Post and Courier — $545K cyberscam hit SC beach town · WBTW — Insurance investigators on contractor-side breach claim · WMBF — Surfside Beach out nearly $545K