{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec"},"incident":{"slug":"2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec","title":"Dickinson Public Schools loses $4.92M to vendor-impersonation BEC","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Dickinson Public Schools","sector":"Education","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss"],"loss_usd":4920000,"loss_kind":"direct_loss","loss_note":"USD; two payments diverted from the district's restricted building fund. No recovery reported at time of disclosure.","records_affected":null,"threat_actor":null,"summary":"Dickinson Public Schools in North Dakota lost $4.92 million from its restricted building fund after criminals impersonating a trusted vendor redirected two payments to a fraudulent account. The case was reported publicly on 13 February 2026. Dickinson police brought in the FBI and the Department of Justice because the scope exceeded local capacity. The district said no student or staff personal data was compromised and that classroom operations were unaffected.","how_it_worked":"The fraud followed the standard business email compromise pattern for construction-heavy public bodies: the attacker adopted the identity of a vendor the district was already paying on a large capital project and submitted new banking instructions for an upcoming payment. Because the request arrived in the context of an expected, legitimate invoice for a project the finance team knew about, the change of account looked routine. Two payments were released before the substitution was discovered. The district has since added enhanced vendor verification, stronger email controls and staff cybersecurity training.","lessons":"Any change to vendor banking details should trigger an out-of-band callback to a phone number already on file, never one supplied in the request, plus dual authorisation on payments above a threshold.","confidence":"Confirmed","sources":[{"title":"North Dakota School District Loses $4.9M to Email Scam","url":"https://www.govtech.com/education/k-12/north-dakota-school-district-loses-4-9m-to-email-scam","publisher":"Government Technology"},{"title":"North Dakota school district loses nearly $5 million in sophisticated email scam","url":"https://www.valleynewslive.com/2026/02/11/north-dakota-school-district-loses-nearly-5-million-sophisticated-email-scam/","publisher":"Valley News Live"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-dickinson-public-schools-loses-4-92m-to-vendor-impersonation-bec"}}