S&P 5007,509.20▲0.9% Nasdaq25,837.21▲1.3% Dow52,224.64▲0.7% Russell 2K2,987.40▲1.5% 10-Yr4.63%+3bp VIX17.55+0.50 WTI$87.52▲3.1% Gold$4,117.00▲1.1% EUR/USD1.141▼0.0% BTC$65,038▼1.6% Nikkei66,116▼0.2%
At close · Wed, Jul 22, 2026
Daily Market Updates.

Insurance

HomeInsuranceIndustry & DealsSurfside Beach faces a $545,598.30 cyber scam tied to…

Surfside Beach faces a $545,598.30 cyber scam tied to payment coverage gaps

The town’s insurer initially said the loss was not covered until fault is assigned, after a business email compromise sent a contractor payment to a fraudulent Utah bank account.

Surfside Beach, South Carolina, says it is dealing with a $545,598.30 budget hole after a business email compromise hijacked a contractor payment for an underground utility project. In March, while the town was midway through paying Wildcat Contractors for work on Ocean Boulevard, a scammer inserted themselves into the email thread, asked for a switch from a check to an electronic transfer, and redirected the project’s fourth payment to a fraudulent account in Utah. According to Insurance Business, the town and Wildcat have not been made whole, and months later they are still arguing publicly over whose fault it was. The fraud involved a lookalike email domain that used a capital “I” instead of a lowercase “l,” and it went through the town’s process because the payment form “looked legit” to town finance director Melanie Gruber. The insurer coverage dispute is now becoming the focal point. Insurance Business reports that the town’s insurer initially said it would not cover the loss because the town had not been found liable, and the town’s attorney later clarified that coverage would apply only if Surfside Beach is found at fault, highlighting a mismatch between common assumptions about cyber insurance and how some policies work. Cyber experts cited by Insurance Business described the technique as a pattern they have seen repeatedly in this type of attack, where an adversary tailors the intrusion to the payment conversation and uses rules and diverted replies to keep the scammer’s version of events in view while stopping the real recipient from correcting course. The article also notes that the fraudulent ACH form included a Los Angeles callback number, a Utah bank account, and a signature Wildcat CEO Alyssa Bowker said appeared copied from an unrelated document.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.