top of page
Search

The Surfside Beach $545,598 BEC Loss: How John Blackshire’s Eleven Secret Sauces Could Have Stopped the Payment

A fraudulent payment does not always begin with a fake invoice.


Sometimes the invoice is legitimate. The contractor is legitimate. The project is legitimate. The payment amount is correct.


Only the destination of the money is fraudulent.


That appears to be what happened when the Town of Surfside Beach, South Carolina, issued a $545,598.30 Automated Clearing House payment intended for Wildcat Contractors. The payment was redirected to an account controlled by criminals after deceptive emails were inserted into communications surrounding the contractor’s payment.


The incident provides a valuable case study for municipal governments, school districts, corporations, nonprofit organizations, universities, healthcare systems, and every other organization that pays vendors.


It also demonstrates why preventing Business Email Compromise, or BEC, requires more than cybersecurity software and annual phishing awareness training.


BEC prevention requires a mature business process.


John Blackshire’s Eleven Secret Sauces for Business Process Maturity provide a practical framework for evaluating whether an Accounts Payable process is sufficiently disciplined, monitored, tested, and owned to prevent a fraudulent vendor bank-account change.


Had these eleven attributes been fully embedded in the Surfside Beach vendor-payment process, the fraudulent request would have encountered multiple opportunities for detection before the money left the Town’s bank account.


Corporate Compliance Seminars will examine these risks during the live online CPE program Business Email Compromise—Accounts Payable on September 4, 2026. The course is taught by Accounts Payable and vendor-process expert Debra R. Richardson, MBA, CFE, APM, APPM, CPRS.


What Happened at Surfside Beach?

The Town of Surfside Beach reported that it issued a $545,598.30 ACH payment on March 13, 2026, that was intended for Wildcat Contractors. The contractor notified the Town on April 28 that the payment had not been received. The Town’s review identified fraudulent communications beginning on March 9.


Reporting on the incident described a criminal impersonating a representative of Wildcat Contractors and requesting that the expected payment be changed from a check to an electronic transfer. The payment was then sent to a Utah bank account that did not belong to the contractor.


The scheme reportedly used typosquatting, in which criminals create internet domains that closely resemble legitimate domains.


Examples connected with the incident included:

  • A domain that visually resembled the contractor’s name by substituting a capital “I” for a lowercase “l.”

  • A fraudulent domain that added an “s” to the Town’s legitimate domain.

  • Communications that appeared to continue an existing and legitimate business conversation.


The fraudulent ACH documentation reportedly contained several indicators that deserved additional investigation, including an unfamiliar contact, a Los Angeles telephone number, a Utah financial institution, and a change in payment method from check to electronic transfer.


The Town’s forensic review found no evidence that its Microsoft 365 accounts had been accessed without authorization. That finding illustrates an important BEC principle: fraudsters do not always need to compromise the victim’s internal email system. They may use look-alike domains, impersonated identities, compromised third-party accounts, or manipulated communication threads.


BEC Is a Business-Process Risk

Business Email Compromise is commonly described as a cybersecurity threat.


That description is correct, but incomplete.


BEC is simultaneously an:

  • Accounts Payable risk

  • Vendor-management risk

  • Procurement risk

  • Treasury risk

  • Internal-control risk

  • Fraud risk

  • Governance risk

  • Training risk


Cybersecurity controls may help identify malicious links, suspicious logins, malware, or known fraudulent domains.


They do not necessarily determine whether a new bank account should be entered into the vendor master file.


That decision is made within a business process.


A mature business process should assume that an email could be fraudulent—even when the message:

  • Uses a familiar name.

  • Discusses a legitimate project.

  • References a valid invoice.

  • Appears within an existing email thread.

  • Contains a realistic signature.

  • Includes a completed banking form.

  • Uses professional and grammatically correct language.


The control should not depend on whether one employee notices one altered character in an email address.


The process should prevent the payment even when the email appears convincing.


John Blackshire’s Eleven Secret Sauces for Business Process Maturity

John Blackshire’s model identifies eleven attributes that help key controls operate at a mature level:

  1. Discipline

  2. Understanding the Risks

  3. Standards

  4. Formal Training

  5. Why?

  6. Metrics

  7. Exception Handling

  8. Mentors

  9. Monitoring through Management by Walking Around

  10. Layers of Testing

  11. Ownership and Certification


The framework distinguishes foundational attributes—such as discipline, risk understanding, standards, and training—from advanced attributes involving metrics, exception handling, mentoring, active monitoring, testing, and process ownership.


Applying each Secret Sauce to the Surfside Beach incident shows how a mature Accounts Payable process could have created multiple barriers against the fraudulent payment.


Secret Sauce 1: Discipline

Discipline means that employees follow the required process consistently, even when:

  • The payment is urgent.

  • The vendor is familiar.

  • The request appears legitimate.

  • Management wants the payment released.

  • A callback is not immediately returned.

  • The change seems administratively routine.


John Blackshire’s framework describes discipline through consistency and accountability: processes should be followed consistently, and roles and responsibilities should be clear.


A disciplined vendor-change procedure might state:

No vendor banking information may be changed until an authorized vendor representative has been reached through independently maintained contact information and has verbally confirmed the request.

The important word is no.

Not “unless the email looks legitimate.”

Not “unless the payment is already due.”

Not “unless an employee leaves a voicemail.”

Not “unless the bank is a real bank.”


A control that employees can bypass when circumstances are inconvenient is not a mature control.


In the Surfside Beach case, the Town reportedly attempted to contact the contractor before releasing the payment but did not receive direct confirmation from the contractor’s chief executive before the transfer was completed.


A disciplined process would have stopped there.


No successful independent verification should mean no change and no electronic payment.


Secret Sauce 2: Understanding the Risks

Employees must understand the specific risk the control is designed to address.


The risk was not simply that the submitted ACH form might contain an error.


The risk was that a criminal could impersonate a legitimate contractor and redirect a valid payment.


Blackshire’s framework calls for both identifying potential risks and assessing their likelihood and impact.


For a $545,598 payment, the potential impact was obviously significant.


A risk-aware employee should have recognized the combination of circumstances as elevated risk:

  • A change from check to ACH.

  • A high-dollar payment.

  • A newly submitted bank account.

  • An out-of-state bank.

  • An unfamiliar contact.

  • A telephone number inconsistent with known vendor information.

  • A request made shortly before payment.

  • Email communication that was not independently authenticated.


Each item might have a plausible explanation.


Together, they should have triggered enhanced verification.


Risk understanding changes the employee’s mindset from:

“Does this form look complete?”

to:

“How could a criminal use this request to redirect the payment?”

That second question is the foundation of fraud-resistant processing.


Secret Sauce 3: Standards

Mature processes are governed by documented standards.


Blackshire’s model associates standards with comprehensive documentation and compliance with applicable requirements.


An effective vendor bank-change standard should specify:

  • Permitted methods for submitting changes.

  • Prohibited use of ordinary email for sensitive data.

  • Required authentication procedures.

  • Approved sources for vendor contact information.

  • Required supporting documentation.

  • Bank-account validation procedures.

  • Segregation-of-duties requirements.

  • Approval thresholds.

  • Special procedures for high-dollar changes.

  • Vendor notification requirements.

  • Documentation-retention requirements.

  • First-payment monitoring.

  • Escalation procedures.


The standard should also address a common weakness in confirmation calls.


Employees should not call the telephone number appearing in:

  • The change-request email.

  • The new banking form.

  • The email signature.

  • A document supplied by the requester.

  • A link included in the email.


A fraudster can control every one of those sources.


The callback should use a number obtained from a previously validated source, such as the original contract, established vendor master record, secure vendor portal, or known vendor representative.


Secret Sauce 4: Formal Training

A written policy does not ensure that employees understand how to apply it.


Formal training should teach employees:

  • How BEC schemes operate.

  • How typosquatting works.

  • How communication threads are manipulated.

  • Why display names cannot be trusted.

  • Why completed banking forms can be fraudulent.

  • Why a real routing number does not establish account ownership.

  • How to conduct a proper confirmation call.

  • How to authenticate the person requesting the change.

  • How to document the verification.

  • When to stop and escalate the request.


Blackshire’s framework emphasizes both skill development and continuous learning as risks and industry practices evolve.


This distinction matters because general cybersecurity training is not enough for employees who manage vendor data.


Debra Richardson’s Vendor Process Training Center explicitly states that vendor teams need training that begins where general cybersecurity awareness ends. Its model adds authentication techniques, internal controls, vendor validations, documentation, and process-specific best practices to reduce fraudulent payments and inaccurate vendor data.


The Town’s experience demonstrates why an employee needs more than the instruction to “look for suspicious emails.”


The employee needs a repeatable procedure that makes the authenticity of the email less important.


Secret Sauce 5: Ask “Why?”

Every control should have a clearly understood purpose.


Blackshire’s framework asks whether a control aligns with organizational objectives and whether it actually reduces the identified risk to an acceptable level.


Consider a requirement to make a vendor confirmation call.


Why does the organization require it?


The purpose is not merely to document that someone placed a call.


The purpose is to establish that:

  1. The organization contacted the real vendor.

  2. The person contacted had authority.

  3. The vendor actually requested the change.

  4. The payment instructions are legitimate.


A call that results only in an unanswered voicemail does not achieve that purpose.


An email sent to an address within the same compromised or spoofed conversation does not achieve that purpose.


A call to a telephone number supplied in the suspicious request does not achieve that purpose.


When employees understand the why, they are less likely to perform the control as a mechanical checklist step.


They understand that an incomplete verification means the objective has not been achieved.


Secret Sauce 6: Metrics

Organizations often measure how quickly Accounts Payable processes invoices.


They should also measure how safely vendor changes are processed.

Blackshire’s model recommends performance indicators and data-driven decision-making to evaluate process effectiveness.


Useful vendor-change metrics may include:

  • Number of vendor bank changes requested.

  • Number approved.

  • Number rejected or suspended.

  • Percentage independently confirmed.

  • Percentage with complete callback documentation.

  • Number involving high-risk discrepancies.

  • Number processed outside the standard workflow.

  • Number approved without direct vendor contact.

  • Number of first payments reviewed.

  • Number of duplicate bank accounts identified.

  • Time between payment release and vendor confirmation.

  • Percentage of staff completing specialized BEC training.

  • Results of periodic process testing.


Metrics should not reward speed at the expense of control quality.


A team that processes every request within four hours but fails to authenticate vendors is not high-performing.


It is efficiently processing risk.


Secret Sauce 7: Exception Handling

A mature process defines what happens when something does not look right—or when a required verification cannot be completed.


Blackshire’s model calls for documented response plans and root-cause analysis of deviations.


The Surfside Beach request reportedly presented several inconsistencies.


A mature exception-handling procedure would have classified the request as high risk and required additional review because of factors such as:

  • A large payment amount.

  • A payment-method change.

  • New bank information.

  • Geographic inconsistencies.

  • An unfamiliar contact.

  • Incomplete direct confirmation.

  • Potential discrepancies in the banking form.

  • Unsuccessful email communications.


The response should not be improvisation.


The procedure should state:

  • Who must be notified.

  • Who has authority to approve an exception.

  • What additional evidence is required.

  • Whether the payment must be held.

  • Whether procurement or the contract owner must assist.

  • Whether information security should examine the email domain.

  • Whether the vendor’s executive management must confirm the change.

  • How the exception must be documented.


A high-risk exception should not become routine merely because the payment deadline is approaching.


Secret Sauce 8: Mentors

Fraud prevention cannot depend entirely on the judgment of an employee confronting an unfamiliar request alone.


Mentors provide guidance, reinforce process adherence, and transfer experience to less-experienced personnel.


A mentoring structure could require employees to involve an experienced reviewer whenever a request includes:

  • More than one inconsistency.

  • A high-dollar bank change.

  • An international element.

  • A sudden payment-method change.

  • An urgent request.

  • Failed independent verification.

  • A mismatch between the requester and the contract contact.

  • Concerns about the authenticity of supporting documentation.


Experienced Accounts Payable and procurement professionals often recognize patterns that newer staff may not.


They may ask:

  • Why is the project manager changing instructions previously established by the company’s chief executive?

  • Why is the telephone number from a different state?

  • Why is the new bank in another state?

  • Why did the payment method change immediately before disbursement?

  • Why has no authorized executive confirmed the request?


Mentoring converts individual experience into organizational capability.


Secret Sauce 9: Monitoring Through Management by Walking Around

Management by Walking Around, or MBWA, refers to active engagement by managers with employees and processes.


Blackshire’s model emphasizes direct observation and real-time feedback rather than management relying exclusively on reports.


In an Accounts Payable environment, MBWA does not require literally walking through an office.


It means managers actively observe how employees:

  • Receive change requests.

  • Authenticate vendor representatives.

  • Obtain callback numbers.

  • Document calls.

  • Resolve discrepancies.

  • Approve master-file changes.

  • Review high-value payments.

  • Escalate suspicious activity.


A procedure may look effective on paper while operating very differently in practice.


Management may discover that employees:

  • Use telephone numbers from incoming emails instead of the established telephone number.

  • Treat voicemail as verification.

  • Approve changes when callbacks are not returned.

  • Allow one person to receive, verify, enter, and approve a change.

  • Skip steps to meet payment deadlines.

  • Retain incomplete supporting documentation.

  • Assume another department performed the verification.


Active monitoring identifies these workarounds before they contribute to a loss.


Secret Sauce 10: Layers of Testing

No single control should be expected to prevent every sophisticated payment fraud.

Blackshire’s framework calls for multiple levels of validation and using test results to improve the process continuously.


A layered vendor-change control structure might include:


First layer: Employee review

The processor examines the request for completeness, inconsistencies, domain anomalies, and unusual circumstances.


Second layer: Independent vendor authentication

Another employee contacts the vendor using previously verified information.


Third layer: Bank-data validation

The routing number, institution, account ownership indicators, and geographic information are evaluated. Why would a local business have a bank account in Utah?


Fourth layer: Supervisory approval

A manager reviews the documentation and confirms that required procedures were completed.


Fifth layer: Payment-level review

A separate employee compares the payment file with recently changed vendor records.


Sixth layer: Vendor notification

The vendor receives an independent notification that its banking information was changed.


Seventh layer: First-payment verification

The organization confirms that the vendor received the first payment sent to the new account.


Eighth layer: Internal Audit testing

Internal Audit periodically selects vendor additions and changes and determines whether employees complied with every required control.


The Business Email Compromise—Accounts Payable CPE event includes practical tools supporting these layers, including an authentication reference, vendor banking form, vendor-validation resources, confirmation-call script, call log, vendor change notification, payment-file review, and an auditable desktop procedure.


If one layer fails the employee calls their mentor.


Secret Sauce 11: Ownership and Certification

Every critical process needs a clearly identified owner.


Blackshire’s framework describes ownership as assigning responsibility and empowering the process owner to make decisions and drive improvements. It also describes certification as formal validation of process maturity and compliance.


The vendor-change process owner should be accountable for:

  • Maintaining the procedure.

  • Identifying evolving fraud risks.

  • Approving control changes.

  • Ensuring employee training.

  • Monitoring performance indicators.

  • Reviewing exceptions.

  • Coordinating with cybersecurity and procurement.

  • Responding to audit findings.

  • Certifying that the process is operating as designed.


Ownership prevents the common problem in which everyone participates in a process but no one is responsible for the process as a whole.


The process owner should periodically certify that:

  • Every vendor change is traceable.

  • Required verification was completed.

  • No employee can control the transaction from request through payment.

  • Exceptions were approved appropriately.

  • High-risk changes received enhanced scrutiny.

  • Identified weaknesses were remediated.


How the Eleven Secret Sauces Could Have Interrupted the Surfside Beach Fraud

It would be too absolute to claim that any framework guarantees prevention of every sophisticated fraud.


However, full implementation of the Eleven Secret Sauces would have created numerous control points capable of interrupting the Surfside Beach payment.


The transaction could have been stopped when:

  • The requested payment method changed.

  • The vendor’s new banking information was received by email.

  • The requester’s identity could not be independently authenticated.

  • The contact information differed from established vendor records.

  • Direct verbal confirmation was not obtained.

  • The request contained geographic inconsistencies.

  • The high-dollar payment triggered enhanced review.

  • A supervisor evaluated the combined red flags.

  • A second employee reviewed recently changed vendors before releasing the payment file.

  • The vendor received an immediate change notification.

  • The first payment to the new account was confirmed independently.


The critical lesson is not that one employee should have noticed one suspicious item.


The lesson is that a mature process should not require one person to detect everything.


Detection Speed Is Also Part of Process Maturity

The fraudulent payment was issued on March 13, and the contractor’s nonreceipt was reported on April 28—approximately 45 days later.


The delay materially reduced the possibility of recovering the funds. Reporting on the incident noted that rapid reporting is important because recovery becomes substantially more difficult after criminals move money through additional accounts.


A mature process therefore needs post-payment detective controls, including:

  • Immediate vendor payment notifications.

  • Confirmation of the first payment to a changed account.

  • Daily review of high-dollar ACH activity.

  • Rapid reconciliation of vendor nonpayment complaints.

  • Defined incident-escalation procedures.

  • Immediate contact with the financial institution.

  • Prompt reporting to law enforcement and cybercrime authorities.

  • Preservation of relevant emails, logs, and payment records.


Preventive controls reduce the likelihood of fraud.


Detective controls reduce the duration and potential impact.


Specialized Vendor Training Is Essential

The September 4, 2026, Business Email Compromise—Accounts Payable event is especially relevant because it focuses on the exact point at which many BEC schemes succeed: the vendor setup and maintenance process.


Instructor Debra Richardson brings more than 20 years of experience at Fortune 500 organizations, including Verizon, General Motors, and Aramark. Her background includes Accounts Payable, vendor maintenance, financial reporting, internal controls, fraud prevention, and widely used ERP platforms. She is a Certified Fraud Examiner and serves on the Nacha ACH Network Advisory Board.


Richardson’s Vendor Process Training Center focuses specifically on vendor onboarding and maintenance. Its training is designed to move vendor teams from merely processing requests to protecting organizational payments and data through consistent authentication, validation, documentation, and internal controls.


That approach aligns directly with the Eleven Secret Sauces.


Both models recognize that fraud prevention requires:

  • Clearly defined processes.

  • Employees who understand the risks.

  • Practical training.

  • Consistent execution.

  • Multiple controls.

  • Documented exceptions.

  • Monitoring.

  • Testing.

  • Accountability.


What Accounts Payable Leaders Should Do Now

The Surfside Beach incident should prompt every organization to conduct an immediate review of vendor bank-change controls.


Management should determine:

  1. Can vendors submit bank changes through ordinary email?

  2. Must employees use independently maintained contact information?

  3. Is direct verbal confirmation mandatory?

  4. Does an unanswered voicemail satisfy the procedure?

  5. Can one employee receive, validate, enter, and approve a change?

  6. Are high-dollar changes subject to enhanced review?

  7. Are recently changed vendors identified before payment files are released?

  8. Does the vendor receive an independent notification?

  9. Is the first payment confirmed?

  10. Are exceptions documented and approved?

  11. Are employees formally trained on BEC and vendor impersonation?

  12. Does Internal Audit test actual compliance with the procedure?

  13. Is one person clearly accountable for the entire vendor-maintenance process?


A “no” or “not consistently” response should be treated as a warning.


The Central Lesson

The Surfside Beach incident was not simply an email failure.


It was a test of business-process maturity.


Fraudsters created convincing communications, exploited normal payment activity, and redirected a legitimate obligation. The strongest defense was not perfect eyesight, a better spam filter, or the hope that someone would notice an extra letter.


The strongest defense was a process that required independent authentication before changing where the money would be sent.


John Blackshire’s Eleven Secret Sauces provide a useful framework for building that process.

  • Discipline ensures required procedures are followed.

  • Risk understanding helps employees recognize the threat.

  • Standards define the required controls.

  • Formal training builds practical capability.

  • Why prevents mechanical compliance.

  • Metrics reveal whether the process is working.

  • Exception handling addresses anomalies.

  • Mentors transfer judgment and experience.

  • Management monitoring identifies actual operating practices.

  • Layers of testing prevent reliance on one control.

  • Ownership and certification establish accountability.


Together, these attributes transform Accounts Payable from a payment-processing function into a financial-control function.


Attend the September 4, 2026, BEC CPE Event


The program will help Accounts Payable, procurement, finance, treasury, vendor-management, internal audit, compliance, and fraud professionals strengthen controls over vendor additions and changes.


Participants will receive practical guidance and tools for:

  • Vendor authentication.

  • Banking-information validation.

  • Confirmation calls.

  • Vendor notifications.

  • Payment-file review.

  • Documentation.

  • Fraud-risk reduction.

  • Auditable vendor-maintenance procedures.


The loss at Surfside Beach shows what can happen when one fraudulent communication acquires the power to redirect more than half a million dollars.


The Eleven Secret Sauces show how a mature process can take that power away.

 
 
 

Recent Posts

See All
TUSD Audit Committee Charter Review

Issues with the Governance of the TUSD - July 14, 2026 by John C. Blackshire, Jr. I submited an Independent Review of the Tucson Unified School District Audit Committee Charter for the Governing Board

 
 
 

Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page