Surfside Beach, South Carolina, has about 4,300 year-round residents, a beloved pier, and now a $545,598.30 hole in its budget that nobody has agreed to fill.
In March, the town was midway through paying a contractor, Wildcat Contractors, for an underground utility project on Ocean Boulevard. A scammer inserted themselves into the email thread between the town's public works director and the contractor, using a lookalike domain with a capital "I" standing in for a lowercase "l," and asked the town to switch that payment, the project's fourth, from a check to an electronic transfer. The town obliged. The money went to a fraudulent account in Utah instead of to Wildcat. Neither side has been made whole, and months later, the two sides are still arguing in public about whose fault it was.
It's a clean, almost textbook case of business email compromise. Nationally, the FBI attributes roughly $3 billion in losses to this exact fraud category over the past year. But the more interesting part, for anyone in this industry, is what's happened since the money disappeared: the town's insurer initially said it wouldn't cover the loss because the town hadn't been found liable, and the town's own attorney has since clarified that coverage would only apply if Surfside Beach is found at fault. That's not how most people assume cyber fraud coverage works, and the gap between assumption and actual policy mechanics is the real story here.
Dave Burg, global head of cyber and data resilience at Kroll, said the scam matched a pattern he's seen repeatedly: "You're in the middle of this conversation, you make your attack perfectly tailored." Attackers who gain access to an email account this way tend to work quietly in the background, watching for the right moment. They set rules so they're alerted the instant a payment-related message arrives, and they divert the real recipient's replies out of sight, so the only version of the conversation anyone actually sees is the one the scammer is writing. Ben Bernstein of Huntress Labs called the lookalike-domain trick subtle enough to "pass the human eyeball test," and in this case it worked: the fraudulent ACH form had a Los Angeles callback number, a Utah bank account, and a signature that Wildcat's CEO Alyssa Bowker said appeared to be copied from an unrelated document. None of it stopped the payment. Town finance director Melanie Gruber said the form simply "looked legit to us."
Mayor Robert Krouse has maintained the town's process was followed correctly: "We don't see where the town erred." Bowker sees it differently. "I didn't get scammed, they got scammed," she said of the town. Both positions can't be right, and which one prevails is now sitting with South Carolina's state law enforcement division and the town's own insurance investigators.
Business email compromise sits at an awkward intersection of three different types of coverage, and which one actually responds depends entirely on how a policy is written and what actually happened technically.
Social engineering fraud coverage, typically found in crime or cyber policies, responds when an employee is deceived into authorizing a transfer, full stop, regardless of whether any system was actually breached. Funds transfer fraud coverage responds to unauthorized transfers, often requiring some element of system compromise. Liability coverage is different in kind: it only responds if the policyholder is found legally at fault for a loss, which is the trigger Surfside Beach's carrier appears to be applying. None of these are interchangeable, and a policyholder who assumes "we have cyber insurance, we're covered" can be in for an unpleasant surprise if the policy in question is really a liability program with a thin cyber add-on rather than a dedicated crime or social engineering policy.
This isn't a new problem. Insurers have a long history of denying social engineering claims under standard crime and fidelity policies on the grounds that no "direct" fraud occurred, since no hacker actually broke into a system and moved the money themselves, a coverage fight that pushed many insurers to start selling explicit social engineering endorsements in the first place. Surfside Beach's dispute over whether the breach originated on the town's side or the contractor's side is, functionally, a modern version of that same argument: coverage is turning on exactly where the technical fault line sits, not simply on the fact that $545,598.30 is gone.
BEC and funds transfer fraud together made up 58% of all cyber incidents in 2025, with 52% of funds transfer fraud claims originating from a BEC lure, according to Coalition's 2026 Cyber Claims Report. Separate data from Resilience, cited in Insurance Business's coverage of a recent MGA breach, found social engineering drove 57% of incurred cyber claims and 60% of losses in the first half of 2025. As Coalition's global head of claims, Rob Jones, put it, "old-fashioned email-based crime hasn't gone anywhere," even as ransomware continues to dominate headlines.
For a small municipality, the exposure is structurally worse than it is for a mid-sized private company. South Carolina's municipalities typically get their property, liability and cyber coverage through the South Carolina Municipal Insurance and Risk Financing Fund, a member-funded pool that provides a base layer of just $100,000 in direct cyber coverage, with an optional commercial cyber policy layered on top for members that apply and qualify for it. Even in the best-case scenario where every layer of that structure responds cleanly, $100,000 doesn't come close to covering a $545,598.30 loss. Multiply that gap across the thousands of small municipalities, school districts, and special-purpose entities that rely on similar pooled arrangements nationwide, and the underlying math is the same everywhere: modest pooled cyber limits built for an earlier, smaller threat, now facing losses that have grown considerably.
A few practical takeaways follow directly from how this case has unfolded so far.
Don't assume "cyber coverage" means BEC coverage. The specific insuring agreement matters more than the policy's general label. A public entity should know, before a loss happens, whether its coverage responds to social engineering deception itself, to unauthorized funds transfers specifically, or only to a liability finding, because those are three different triggers with three different burdens of proof.
Verification protocols are now a coverage condition, not just good practice. FBI Cyber Enabled Fraud and Money Laundering Unit chief Timothy Lynch's advice after this incident was blunt: "Call a known number to ensure a request is authentic." That's also, increasingly, language insurers are building directly into policy conditions, meaning a skipped callback isn't just a process failure, it can be the difference between a paid and a denied claim.
Speed matters more than most policyholders realize. The FBI has said that funds are recovered in roughly 75% of BEC cases reported within 72 hours, but recovery becomes highly unlikely after that window closes. Surfside Beach didn't identify the fraud for 45 days. For public entities juggling multiple vendor relationships and payment channels, building a fast internal escalation path for any last-minute change to payment instructions is now as much a coverage-preservation measure as a fraud-prevention one.
Sublimits deserve their own line item in any renewal conversation, particularly for public entities relying on pooled risk programs built around modest base cyber layers. A $100,000 sublimit that looked adequate when it was set may not reflect what a single successful BEC attempt can now cost.
Surfside Beach has since tightened how it handles vendor payments, including new password protections on larger contracts and a more careful review process before any ACH change is approved. Whether that comes with any actual recovery of the $545,598.30 still depends on a liability question nobody outside the investigation has answered yet: whose email got compromised. Until that's resolved, both the town and its contractor are stuck in exactly the coverage gap this piece describes, out real money, with an insurance program that was never quite built to answer the question being asked of it.