Public bodies publish their vendor lists. Attackers read them.
A county finance office runs on two clerks, a fifteen year old ERP, and a procurement code written before email. It also publishes, by law, exactly who it pays, how much, and roughly when. That combination is why local governments keep wiring seven figures to strangers, and why the auditor's recommendation to train staff will not stop the next one.
Picture a county finance director with a staff of two. There is a road resurfacing contract running through the summer, awarded competitively, with progress payments scheduled against completed milestones. The contractor is a regional firm the county has used for years.
In late July a letter arrives on the contractor's letterhead, with the contractor's logo, referencing the correct contract number and the correct award amount. The firm has moved its banking to a new institution following a refinancing, it says, and the remaining progress payments should be directed to the new account. There is a signature from a name that appears on the contract. A phone number is provided for any questions.
The clerk follows the county's procedure. She checks the contract number, which is right. She checks the award amount, which is right. She checks the payment schedule, which matches. She calls the number and speaks to someone who confirms the change and sounds entirely ordinary. She files the letter, updates the vendor master record, and the August payment goes out on schedule.
In October the contractor calls to ask about two missing payments.
Here is the part that matters, and it is the reason this is a different problem from the same fraud at a private company. The attacker did not need to compromise anything to write that letter. The contract number, the award amount, the vendor name, the payment schedule and the name of the signing officer were all published, because the county is legally required to publish them.
Short answer. Cities and counties prevent vendor payment fraud by requiring the enrolled vendor contact to cryptographically sign any change to banking details, and the enrolled finance officer to sign any disbursement above a threshold, with receipts the state auditor can verify offline without contacting anyone. Training and callbacks are diligence, not prevention. The letter and the phone call are the attack, so a control that evaluates them cannot work.
Why are local governments targeted more precisely than private companies?
Because they publish the reconnaissance.
This is the single most useful observation in this article and it is almost never stated plainly. A private company's vendor relationships are commercial information. An attacker targeting a manufacturer has to do work: compromise a mailbox, read a thread, infer relationships, guess at amounts and timing. That work is the expensive part of the attack and it is where most attempts fail.
A public body hands that work over as a matter of law and policy. Consider what is routinely available without any compromise at all:
- Who you pay. Contract awards are published. Bid tabulations name the winning vendor and often the losing ones.
- How much. Award amounts, change orders and contract values appear in council or board agendas and minutes.
- When. Payment schedules, milestone structures and warrant registers are frequently public, and many jurisdictions publish check registers listing every disbursement.
- Who signs. The finance director, the clerk, the purchasing agent and the authorised signatories are named on public documents, with titles and often direct contact details.
- What the paperwork looks like. Agendas and minutes are published as PDFs, complete with letterhead, formatting conventions and the vocabulary the organisation actually uses.
An attacker with an afternoon and a browser can assemble a targeting file that would take weeks of intrusion against a comparable private organisation. They know the vendor, the amount, the schedule, the names, and the house style. That is not a security failure by the county. It is the transparency obligation working exactly as intended, and it is not going to be repealed, nor should it be.
The correct conclusion is not that public bodies should publish less. It is that public bodies cannot rely on obscurity as any part of their control set, and must therefore rely on controls that work when the attacker knows everything. Very few of their current controls meet that standard.
What has this actually cost?
Public reporting documents individual losses well, even though there is no comprehensive national tally.
Laurens County, South Carolina paid more than 1.5 million dollars to criminals impersonating a contractor through fraudulent wire transfer instructions, a case documented in contemporaneous reporting on the incident. The City of Baltimore lost over a million dollars in a vendor impersonation scheme uncovered in spring 2025, also documented in press coverage at the time. Both follow the pattern described above: a plausible instruction, a legitimate looking change, a real contract, and a payment that went where it was told.
These sit inside a much larger category. The FBI's Internet Crime Complaint Center recorded roughly 3.05 billion dollars in reported business email compromise losses across 24,768 complaints in 2025, with the large majority of that money moving by wire or ACH transfer. Public entities are a subset of those complaints and are not broken out separately in the headline figures.
A note on the numbers you will see elsewhere
You will encounter confident totals for public sector cyber losses in vendor marketing. Treat them carefully. There is no authoritative national census of municipal payment fraud, for the straightforward reason that no single body collects it: some losses appear in state auditor findings, some in council minutes, some in IC3 complaints, some in insurance claims, and many in more than one, which makes aggregation across sources unreliable. Anyone presenting a precise figure should be asked how they avoided double counting.
Why is the public sector evidence base better than the private sector's?
This is the counterintuitive part, and it is genuinely useful for anyone trying to reason about this problem.
Private companies do not disclose payment fraud losses unless a securities obligation forces them to, and for most losses none does. A mid sized manufacturer that wires 800,000 dollars to an impostor will tell its insurer, its bank and possibly the FBI, and will tell nobody else. The result is that the private sector loss data is a thin slice of reported complaints sitting on top of an unknown mass of quiet write offs.
Public bodies cannot do that. A county that loses 1.5 million dollars of public money has to account for it in a public budget, discuss it in a public meeting, disclose it to a state auditor, and frequently answer questions from local press. The loss becomes a matter of record whether anyone wants it to or not.
So although the individual amounts are usually smaller than the largest corporate cases, the public sector produces a far more honest evidence base. If you want to understand how these attacks actually succeed, council minutes and auditor findings are a better corpus than any vendor threat report, because they describe what the organisation actually did rather than what a marketing team wants you to conclude.
What does the finance office actually look like?
Any recommendation that ignores the operating reality will be ignored in return, so it is worth describing accurately.
The team is small. A county of eighty thousand people may run accounts payable with two or three staff who also handle payroll, receipting, and whatever the board asked for last week. There is rarely a security function. There is often no dedicated IT staff beyond a contracted provider.
The systems are old and hard to change. Government financial systems from vendors including Tyler Technologies and Oracle are deployed on multi year contracts, customised, and upgraded slowly because an upgrade means a validation cycle nobody has capacity for. The vendor master record is a table in that system, and changing how it behaves is a vendor roadmap question rather than a configuration change.
Procurement rules add friction without adding assurance. This point deserves emphasis because it is frequently misunderstood by people arriving from the private sector. Public procurement codes are strict about competition, documentation and approval thresholds. They are largely silent on authentication. A change of banking details can be entirely compliant with a procurement code that never contemplated the question of whether the letter was genuine. The rules make the process slower and no harder to fool.
And the staff are accountable in a way private employees are not. Public money carries personal exposure, reputational risk in a small community, and the possibility of appearing by name in a newspaper. That produces caution, which is good, and also produces a strong preference for following the documented procedure precisely, which is exactly what the attacker is exploiting. The clerk in the opening scene did not deviate from procedure. She followed it, and the procedure was the vulnerability.
Why does the auditor's finding say train staff?
Because within the current control vocabulary there is not much else to say.
The controls available to a state auditor evaluating this loss are, broadly: was there a documented procedure, was it followed, was there segregation of duties, was there a callback, and was there training. Every one of those is a question about diligence. None of them is a question about whether the instruction was genuine, because no control in the standard set establishes that.
So the finding writes itself. The procedure existed. It was followed. The callback was made. Therefore the recommendation is enhanced training and enhanced verification procedures, which is to say: do the same things, but more carefully. The next entity does the same things more carefully and loses money to the same attack, because carefulness was never the binding constraint.
We wrote the general teardown of callback verification in Call to verify, the number came from the fraud, and the vendor master change problem in its commercial form in Vendor email compromise, the invoice is real and the bank account is not. The public sector version has all of those failure modes plus published reconnaissance.
How does a signed vendor change work?
The control is to make the change itself something only the real vendor can authorise, and to make the ERP enforce it rather than asking a clerk to judge it.
The vendor's authorised finance contact enrols a device once, ideally at contract award when the entity and the vendor are already exchanging formalities. From then on, a change to banking details is not a letter. It is a request that the enrolled contact signs on their own device, and what they sign is the specific change.
vendor_change = {
"entity": "Ridgeway County",
"vendor_id": "V-00418",
"vendor_name": "Halloran Paving Company",
"contract_ref": "RC-2026-ROAD-11",
"old_account_hash":"sha256:9c41...e77a",
"new_routing": "****0114",
"new_account": "****7752",
"effective_date": "2026-08-01",
"requested_by": "[email protected]"
}
digest = SHA-256(canonical_json(vendor_change))
signature = sign_on_enrolled_device(digest)
The reason the old account is included as a hash rather than in the clear is worth a sentence, because it is the kind of detail that separates a design from a slogan. Including it binds the change to a specific starting state, so a signature obtained for one change cannot be replayed against a record that has since moved. Hashing it means the signed object can be handed to an auditor without exposing account details in a document that may itself become a public record.
The enforcement is short and lives in the payment run rather than in the clerk's judgment:
def apply_vendor_change(change, receipt):
if not receipt:
raise Blocked("unsigned change, hold for manual path")
if not verify_ed25519(receipt.signature,
sha256(canonical_json(change)),
published_key):
raise Blocked("signature does not cover these details")
if receipt.signer != vendor.enrolled_contact:
raise Blocked("signer is not the enrolled vendor contact")
if change.old_account_hash != current_account_hash(change.vendor_id):
raise Blocked("stale change, vendor record has moved")
commit(change, evidence=receipt)
Above a threshold, the disbursement release gets the same treatment, signed by the enrolled finance director over the payee, amount and warrant reference. That covers the second attack shape, where the vendor record is untouched but a one off payment is directed elsewhere.
Replaying the opening scene
The attacker still sends the letter. It is still on convincing letterhead, still references the correct contract, still provides a phone number that answers.
The clerk still reads it. She may still make the call. But the vendor master record cannot be updated from a letter, because the ERP requires a signed change from the vendor's enrolled contact, and the attacker cannot produce one. The letter goes into a manual exception path, where it will sit until someone reaches the real contractor through the contract file.
Nobody had to spot the fraud. The fraud simply could not produce the artifact the system required.
Why does the auditor care more here than a private CFO would?
This is the argument that makes the control saleable in the public sector, and it is genuinely stronger here than in a commercial setting.
A public entity is audited annually, by an external auditor, against a standard, with a published result. Internal control over disbursements is squarely within scope, and findings have consequences: they appear in a public document, they attract board attention, and repeated findings attract state level attention.
In that environment, the difference between a control the entity attests to and a control an auditor can independently verify is worth a great deal. Today, an entity demonstrating its payment controls hands the auditor its own records: a procedure document, a sample of files, notes of callbacks written by the person who made them. The auditor is being asked to accept the entity's account of its own diligence.
A signed receipt is a different kind of evidence. The auditor verifies an Ed25519 signature against a published key, offline, without contacting the entity, the vendor, or any vendor of software. Either a signature over these exact payment details exists from the enrolled party, or it does not. There is no sampling, no interviewing, and no reliance on the auditee's narrative.
That property, that the evidence does not depend on trusting the party being audited, is the thing to lead with when explaining this to a finance director. It converts an annual source of discomfort into an annual demonstration of strength.
Where does the public record expose you?
Mapping the payment lifecycle against what is publicly knowable is a useful exercise for any entity, because it shows precisely where obscurity is doing no work.
| Lifecycle stage | What is typically public | How the attacker uses it | Control that survives disclosure |
|---|---|---|---|
| Bid and award | Vendor names, award amount, contract reference | Selects a target and a plausible sum | Enrol vendor contact at award |
| Contract execution | Signatories, titles, contact details | Names the sender and the recipient correctly | None needed, this is fine to disclose |
| Change orders | Revised amounts and dates | Times the approach to a real change | Signed change requests |
| Vendor master update | Not usually public | The target action | Signature from enrolled vendor contact |
| Payment schedule | Milestones, board approved schedules | Times the approach before a real payment | Signed release above threshold |
| Disbursement | Check and warrant registers | Confirms the attack worked, and the next amount | Receipt filed with the warrant |
| Annual audit | Findings and management responses | Learns which entities have weak controls | Auditor verifiable receipts |
The last row is uncomfortable and worth sitting with. Published audit findings tell an attacker which entities in a state have known control weaknesses in disbursements. The transparency that is supposed to drive improvement also distributes a target list. That is not an argument against publishing findings. It is an argument for closing them quickly.
How does a public body actually pay for this?
Procurement reality deserves a straight answer rather than a hand wave, because a control nobody can buy is not a control.
Three routes are realistic. Cyber insurance and public entity risk pools are the most promising, because pools already price social engineering coverage and already impose control requirements on members. A pool that requires signed vendor changes across its membership solves the enrolment problem regionally in one decision, which no individual county could achieve alone.
State level procurement is the second. Where a state negotiates a contract that local entities can order against, the cost and the evaluation burden drop dramatically for a two person finance office.
Federal and state grant programmes for local cybersecurity are the third, and they favour projects that produce auditable improvements, which this does.
What is not realistic is expecting each of several thousand small entities to independently evaluate, procure and integrate a control. Anyone proposing that has not spent time in a county finance office.
Honest limits
Vendor enrolment is the hard part, and it is a network problem. A county cannot compel its vendors to enrol, and a vendor serving one small county will not enrol for that alone. The realistic sequencing is largest vendors by spend first, then regional coverage through a risk pool or state contract. Until coverage is meaningful, most changes still go through the manual path.
One time and emergency vendors are outside this. Disaster response, emergency repairs and sole source purchases involve vendors with no prior relationship and no enrolment. Those need a documented alternative path, and that path is where the next attack will go.
Procurement law may require paper in parallel. Some codes require signed physical documents for certain changes. A cryptographic signature can sit alongside that requirement, and cannot replace it without statutory change.
It does not address the insider. A finance officer with signing authority who directs a payment improperly will produce a valid signature. Segregation of duties, dual authorisation and audit remain the controls for that, and this does not substitute for them.
Manav has no government ERP connectors. The signing and offline verification primitives are shipped, with a working demonstration at the signing lab and integration details in the developer documentation. Native integration with Tyler, Munis or Oracle financial systems does not exist today. Adopting this now means an API integration or a documented step alongside the existing process, and any entity should ask its ERP vendor directly what their roadmap says.
What to do this week
- Search for your own entity the way an attacker would. Spend thirty minutes finding your vendor names, award amounts, payment schedules, check register and the names of your signatories. Print what you find. Take it to your next leadership meeting. It is the most persuasive artifact available and it costs nothing.
- Impose a hold on newly changed vendor accounts. No payment to a changed banking detail for a defined period, no exceptions below the finance director. This is a policy change, it is free, and it defeats the timing most of these attacks rely on.
- Rank your top twenty vendors by annual spend. That list is your enrolment programme, and it is likely to cover the large majority of your disbursement value.
- Ban verification numbers taken from the request. Numbers come from the executed contract or the vendor file, never from the letter, the email or a linked website. Audit five recent vendor changes to see whether this happened.
- Ask your ERP vendor one question in writing. Can a vendor master banking change be blocked unless a cryptographic signature over the new details is present? File their answer. It will be useful at audit either way.
- Talk to your risk pool. Ask what controls would reduce your social engineering premium or raise your sublimit. Pools move faster than procurement.
- Read the last three years of your own audit findings on disbursement controls. If the recommendation was training, ask what has changed since, and whether the answer would prevent the scene at the top of this article.
Frequently asked questions
How can a city or county prevent vendor payment fraud? By requiring enrolled vendor contacts to sign changes to banking details, and enrolled finance officers to sign disbursements above a threshold, with receipts an auditor can verify offline. Because the attacker can obtain the contract details from public records, controls that depend on recognising a suspicious request cannot be relied upon.
Why are local governments targeted by business email compromise? Because transparency obligations publish the targeting information. Vendor names, contract values, payment schedules, signatory names and document formats are all matters of public record, so an attacker can construct a highly specific and plausible request without compromising anything.
Does a callback to the vendor stop this? Not reliably. If the number comes from the fraudulent request it reaches the attacker, caller identification can be spoofed, and voice synthesis has removed voice recognition as a dependable signal. A callback to a number taken from the executed contract is meaningfully better and still not sufficient on its own.
What do state auditors recommend for vendor changes? Typically documented procedures, segregation of duties, verification callbacks and staff training. These are diligence controls that establish whether the entity was careful. They do not establish whether the instruction was genuine, which is why entities that follow them still suffer losses.
Is public sector loss data better or worse than private sector data? Better, though the amounts are usually smaller. Public bodies must account for losses in public budgets, disclose to auditors, and answer to elected boards, so incidents become a matter of record. Private companies write off comparable losses without disclosure unless a securities obligation applies.
Can a small entity with two finance staff realistically adopt this? Only through an aggregator. Individual evaluation and procurement is unrealistic at that scale, which is why risk pools, state contracts and grant programmes are the practical routes, and why a pool level requirement solves vendor enrolment regionally in a way no single entity can.
Does this replace positive pay? No. Positive pay is a bank side control that matches presented items against an issued file and is genuinely useful against altered and counterfeit items. It does not evaluate whether the payee in the issued file was legitimately established, which is the step this control addresses.
Sources
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report, for business email compromise loss totals and complaint counts: ic3.gov annual reports
- FBI Internet Crime Complaint Center public service announcements on business email compromise and payment redirection: ic3.gov public service announcements
- Government Finance Officers Association, best practices on internal controls and payment fraud prevention: gfoa.org best practices
- Uniform Guidance, 2 CFR Part 200, internal control requirements for entities expending federal awards: ecfr.gov 2 CFR 200
- Multi-State Information Sharing and Analysis Center, advisories and resources for state, local, tribal and territorial governments: cisecurity.org MS-ISAC
- Cybersecurity and Infrastructure Security Agency, resources for state and local government cybersecurity: cisa.gov state and local
The county published the vendor, the amount and the date. The attacker did not need to hack anything. They needed a letterhead.