Skip to main content

August 11, 2026

The $545,000 Email Scam Every Florida Contractor Should See

A typosquatted email diverted a $545,000 contractor payment. What Central Florida construction companies should change about payment verification.

The anatomy of a $545,000 email

In March, the town of Surfside Beach, South Carolina owed its contractor a progress payment for burying power and fiber lines along Ocean Boulevard. Someone else collected it. The scammers had registered two lookalike domains: one imitating the contractor, Wildcat Contractors, with a capital I standing in for the lowercase l, and one imitating the town itself. Ninety minutes after a real conversation about payment timing, the fake project manager slid into the email thread and asked to switch from a check to an electronic transfer.

On March 13 the town wired $545,598.30 to a bank account in Utah. Nobody noticed for 45 days. By then, an FBI supervisory agent told reporters, recovery was highly unlikely; the bureau’s good outcomes happen when fraud gets reported within about 72 hours.

The detail worth reading twice: forensics found no compromise at all. Nobody’s mailbox was hacked, no malware, no breached server. A criminal spent a few dollars on two domains, watched a public bid award, and typed convincingly.

The contractor did the work and still isn’t paid

Wildcat finished the job. The town says it doesn’t see where it erred. Lawyers are now sorting out who eats the loss, and until they do, a contractor is out half a million dollars for work already in the ground.

This was not a one-off. Three weeks earlier, Pine County, Minnesota disclosed that a $400,143 payment owed to Redstone Construction was diverted by fraudulent payment instructions that arrived, again, by email. Reported by the local county paper, same shape, same outcome: investigation open, contractor unpaid.

Progress payments are the perfect target. They are large, scheduled, expected, and negotiated across months-long email threads involving owners, general contractors, and subs who have often never met in person.

Stuck on something like this right now?

Talk it through with a real US-based engineer, 24/7, no phone trees: (407) 587-0089.

Book a Free Strategy Session

Construction is now a top-tier target, and not just for fraud

The wire fraud wave sits inside a bigger trend. Dragos published its Q2 2026 industrial ransomware analysis this week: 1,140 ransomware incidents against industrial organizations in one quarter, up 12% from Q1, with construction the second-hardest-hit sector at 176 incidents. US companies absorbed 38% of the global total. The most common ways in were not exotic: phone-based social engineering, attackers posing as IT support in Microsoft Teams, and unpatched internet-facing gear like VPN appliances.

The same report notes a shift toward stealing data without encrypting anything, which means the old comfort of “we’d notice ransomware” no longer holds. In July, the Akira crew claimed a mid-sized Michigan contractor, alleging 168GB taken including scanned employee passports and client contracts; class-action attorneys began soliciting within a week. The company hasn’t confirmed the claims, and it doesn’t have to for the legal exposure to start.

Why this lands on Central Florida desks

Look at the payment flows around here. Orlando’s council has approved a $2.62 billion capital improvements fund, including early money toward a proposed rail link between the airport, the Convention Center, and International Drive. Add the private pipeline of hotels, distribution centers, and multifamily projects, and Central Florida runs some of the busiest owner-to-GC-to-sub payment chains in the country.

To be plain: none of the incidents above happened here, and we are not aware of a Central Florida case in this news cycle. That is the point of writing this now rather than after one. Every mechanism in the Surfside story exists in every draw cycle running through Orlando this month.

The habit that beats the scam

The defense that works is boring and costs almost nothing: any change to payment instructions, any change at all, gets verified by a phone call to a number you already had on file before the request arrived. Not the number in the email signature. The one from the contract.

Around that habit, the technical layer earns its keep. Flag external senders and newly registered domains in Microsoft 365 so a three-day-old lookalike domain announces itself. Publish and enforce email authentication so your own name is harder to spoof at the subs and owners you work with. Register the obvious misspellings of your company domain before someone in Utah does. Treat any payment-change email as a security event, and if money moves wrong, report it to the FBI’s IC3 the same day, because the 72-hour window is real.

One more step worth stealing from the lawyers: put the verification procedure in the contract. The Surfside dispute is dragging on precisely because nobody agreed in advance on how payment instructions could change or who bears the loss when a fraudster intervenes. A paragraph in your owner and subcontractor agreements naming the verification method, the authorized contacts, and the loss allocation turns a future argument into a checklist. And train the specific person who processes draws, not the whole company generically; the scam is aimed at one desk.

What we do for contractors

Cyber Command provides IT support for construction companies across Central Florida: the email hardening and lookalike-domain monitoring described above, human-run security monitoring that watches for the account takeovers and impersonation attempts this industry attracts, and the day-to-day helpdesk that keeps estimating software, field tablets, and the job-site trailer connected. It is designed to reduce the odds that your firm is the one in the next story, and to make sure a bad email gets caught in hours, not 45 days.

We are headquartered in Winter Springs and work with industrial and field-service businesses across Orlando, Tampa Bay, and Jacksonville. If your draw schedule runs through email threads, talk to a real person about what your payment chain looks like to an outsider. The first conversation costs nothing.

This article is for general informational purposes only and is not legal, compliance, insurance, or other professional advice. Threats, technologies, and regulations change quickly; confirm current requirements with your own advisors before acting. See our full disclaimer.