What happened
One Treasure Island, a San Francisco nonprofit serving low-income residents, lost $650,000 after criminals compromised its bookkeeper's email account, inserted themselves into an existing email thread and requested a change to wire instructions for a grant payment. Executive director Sherry Williams pursued the funds herself, contacting the receiving bank in Odessa, Texas and seeking help from senators before the Secret Service opened an inquiry.
How the deception worked
The attackers took over the outsourced bookkeeper's mailbox, which sat at the center of the nonprofit's payment approvals, and then replied inside a live thread about a pending grant disbursement rather than starting fresh correspondence. Because the message carried the real address, the real subject line and the real transaction context, the substituted wiring instructions read as an ordinary administrative update. Staff sent the $650,000 grant payment to the criminals' account at a small out-of-state bank, which was then drained onward. The organization discovered the diversion only when the intended recipient reported non-receipt, and small-nonprofit resourcing left it largely on its own to chase the money.
AI involvement · No AI reported
No AI or synthetic media reported.
The control that would have caught it· our reading, not a claim from the sources
Thread hijacking beats sender-address checks, so any change of wire instructions inside an existing thread must trigger a verbal callback to a previously known number before funds move.
Sources (2)
- Scammed San Francisco Nonprofit Falls Victim to Costliest Type of CybercrimeCBS News Bay Area / Associated Press·cbsnews.comOpen ↗
- A nonprofit that helps the poor lost $650,000 to scammersSan Francisco Chronicle·sfchronicle.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.