What happened
Dickinson Public Schools in North Dakota lost $4.92 million from its restricted building fund after criminals impersonating a trusted vendor redirected two payments to a fraudulent account. The case was reported publicly on 13 February 2026. Dickinson police brought in the FBI and the Department of Justice because the scope exceeded local capacity. The district said no student or staff personal data was compromised and that classroom operations were unaffected.
How the deception worked
The fraud followed the standard business email compromise pattern for construction-heavy public bodies: the attacker adopted the identity of a vendor the district was already paying on a large capital project and submitted new banking instructions for an upcoming payment. Because the request arrived in the context of an expected, legitimate invoice for a project the finance team knew about, the change of account looked routine. Two payments were released before the substitution was discovered. The district has since added enhanced vendor verification, stronger email controls and staff cybersecurity training.
The control that would have caught it· our reading, not a claim from the sources
Any change to vendor banking details should trigger an out-of-band callback to a phone number already on file, never one supplied in the request, plus dual authorisation on payments above a threshold.
Sources (2)
- North Dakota School District Loses $4.9M to Email ScamGovernment Technology·govtech.comOpen ↗
- North Dakota school district loses nearly $5 million in sophisticated email scamValley News Live·valleynewslive.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.