The Town of Enfield, New Hampshire, fell victim to a $742,000 wire fraud scheme.
An employee was tricked into changing a bank account number for a vendor, resulting in the payment being directed to a fraudulent account.
The scheme involved a man-in-the-middle attack, where the threat actor impersonated the vendor and provided false banking instructions.
The town notified the bank and some of the funds may be recoverable, but the incident highlights the need to verify payment instructions through alternate means.