Pittsburg, California accidentally sent an unauthorized ACH payment of $913,839.81 to a fraudulent account on February 12. The transfer was identified as a scam on February 17, and swift action to freeze the receiving account allowed recovery of $696,241, leaving about $217,598 unrecovered. Investigators have obtained 18 search warrants tied to 116 accounts and say the primary suspect is believed to be in Nigeria with suspected U.S.-based associates; the FBI and U.S. Attorney’s Office are handling the active investigation.
Pittsburg Sent $913,839.81 to Fake Vendor Account in Business Email Compromise — $696K Recovered

The City of Pittsburg, California, inadvertently transferred $913,839.81 to a fraudulent bank account after scammers impersonated one of the city's known vendors. What began as a routine ACH payment on February 12 turned into an international investigation after staff recognized the transfer as suspicious five days later.
How the Scam Worked
Officials say the attackers used a business email compromise (BEC) tactic: they altered payment instructions so the receiving account appeared to belong to an existing municipal vendor. The payment left city control on February 12, and staff flagged the transaction as fraudulent on February 17.
Investigation and Recovery
Pittsburg police immediately notified Contra Costa County authorities and the FBI. The receiving account was frozen quickly, allowing investigators to recover $696,241 before additional funds were moved beyond reach. Approximately $217,598 remains unrecovered; the city has filed an insurance claim and the final financial outcome will depend in part on the resolution of that claim.
Investigators obtained 18 search warrants tied to 116 accounts across technology firms, financial institutions and telecom providers while tracing the people and infrastructure behind the operation. Evidence reportedly points to a primary suspect believed to be based in Nigeria, with at least two suspected associates identified in the United States. The FBI and the U.S. Attorney’s Office have accepted the case and the investigation remains active.
City Response and Controls
The city publicly disclosed the incident on August 5, after investigators determined release of details would no longer jeopardize the probe. In response to the breach, Pittsburg updated internal financial controls, including stronger ACH verification, revised payment workflows and adjustments to IT staffing.
Prevention and Best Practices
Security guidance from the FBI’s Internet Crime Complaint Center (IC3) and industry experts emphasizes several protections that could prevent similar losses:
- Verify any change to vendor banking details through a secondary channel (use the phone number already on file, not the one supplied in an email).
- Require dual approvals for large or unusual payments and for changes to vendor account information.
- Protect finance email accounts with multi-factor authentication (MFA) and monitor for unusual logins or mailbox rule changes.
- If a fraudulent ACH or wire has been sent, act immediately: contact the sending bank to request a recall or freeze, report the incident to law enforcement and IC3.gov, and preserve all related emails and transaction records for investigators.
Mayor Dionne Adams called the incident an upsetting lesson and said city officials are continuing to work with investigators to identify everyone involved and to attempt recovery of the remaining funds.
Help us improve.




























