Wildcat Contractors unpaid; FBI says funds likely gone
The scam unfolded through what cybersecurity experts describe as a textbook business email compromise: a fraudster set up lookalike domains using “typosquatting” — a domain reading “wiidcatcontractors.com,” where the third character is a capital I visually identical to a lowercase L in some fonts, and “surfsidesbeach.org” — and inserted themselves into email exchanges between the town and Wildcat Contractors, a Gastonia, N.C.-based firm performing underground utility line work on Ocean Boulevard.
According to emails reviewed by The Wall Street Journal, the scammer filled out Surfside Beach’s ACH form on the day of the transfer request. Town Finance Director Melanie Gruber said the form did not raise suspicions — the Utah bank listed was real, the CEO’s signature matched town files, and companies sometimes use different contact names and phone numbers. “It looked legit to us,” Gruber said.
Alyssa Bowker said the form contained multiple red flags: the listed contact name was not her employee, the phone number had a Los Angeles area code, and her own signature appeared blurry and lifted from another document. She also said it was unusual for a project manager to overrule the CEO on payment method.
The town made attempts to verify the transfer. Gruber said an employee called Wildcat’s project manager on Friday, March 13. Kyle Bowker, the company’s president, confirmed the call and said the project manager referred the caller to Alyssa Bowker. Gruber said the town then called Bowker’s mobile phone and left a voicemail about the ACH transfer. Bowker said she does not recall the voicemail but that she may have missed it.
The town also emailed Bowker and the project manager twice that day at what appeared to be correct addresses, Gruber said — but the emails did not go through, according to Bowker.
The following Monday, the town wrote to Bowker again that the transaction had been completed to the account provided — another email Bowker said she never received.
The fraud was not discovered until April 27, when Bowker, after months of inquiries about payment, was told by town officials that they had already paid. When the town shared the ACH form and emails, Bowker spotted the “wiidcat” domain.
Mayor Krouse said the town’s IT department found no evidence that its own email system was breached. Wildcat’s IT consultants initially reached the same conclusion about the company’s network, Bowker said. The ACH request, Krouse said, came from a valid Wildcat email address. “We don’t see where the town erred,” Krouse said, adding that he does not see “why we should be paying double.”
The FBI’s Cyber Enabled Fraud and Money Laundering Unit chief, Timothy Lynch, said the bureau has historically clawed back pilfered funds about 75% of the time when scams were reported within 72 hours. Because 45 days elapsed before the Surfside Beach heist was detected, Lynch said recovery is “highly unlikely.”
Residents have voiced anger at Town Council meetings. “It just feels like gross negligence,” said Rachel White, 31, who manages the local farmers market. “Where’s the professionals?” said Cecilia Horne, 67. Judy Henion, 76, called the town’s handling of taxpayer money “loosey goosey” and demanded answers at a council meeting.
“I didn’t get scammed, they got scammed,” Bowker said. “Why should I not be paid?”
Surfside Beach joins a growing list of municipalities hit by business email compromise. Peterborough, N.H., lost $2.3 million in 2021 and recovered just $650,000. Lexington, Ky., was conned out of $3.9 million in 2022 but authorities seized all of it from a private bank account, leading to five federal convictions.
Artificial intelligence is increasingly aiding the schemes, Lynch said. In years past, scammers often overused “kindly” — a word seen in at least one Surfside Beach email — but AI now smooths syntax and diction, making messages from overseas criminals harder to detect.
“The scammer’s trick is so subtle it can pass the human eyeball test,” said Ben Bernstein, a cybersecurity expert at Huntress Labs. The best safeguard, Lynch said, is a simple phone call to a known number to verify any payment request.
Councilor Rick Lawhorn said the priority is recovery, but “the most important thing, other than trying to get as much money back as we possibly can, is to get it right so that we never have this happen again.”