The town of Surfside Beach, South Carolina, wired half a million dollars of taxpayer money to a stranger and now insists it did nothing wrong. The mayor cannot see “where the town erred.” The finance director thought the form “looked legit.” The fraud was not caught for forty-five days. And the contractor who actually did the work — the plumbing, the excavation, the underground utility lines on Ocean Boulevard — still has not been paid a cent.

Let us begin with what is verifiable. On March 13, a fraudster using the domain “wiidcatcontractors.com” — a typosquat in which the third character is a capital I doing duty as a lowercase L — filled out the town’s ACH form and asked for $545,598.30. The town sent it to a bank in Utah. No alarm sounded. The public works director received the request and the transfer went through. The finance director processed it. The town made calls — to Wildcat’s project manager, who was reached, and to CEO Alyssa Bowker, which went to voicemail — and sent emails that did not go through. Nobody secured verbal confirmation from the authorized signer before wiring half a million dollars.

Make a phone call. That is not an expensive new protocol. That is not a software upgrade. That is what you do when your grandmother says she is moving money and you ask her to call you first, and she calls you, and you say it is fine, and the money moves. That is the human-eyeball test. The town did not pass the human-eyeball test — not because it could not, but because the form filled out by a stranger had a real Utah bank listed, a signature that matched town files, an address that looked official — it looked legit. The people whose job it is to spend public money more carefully than their own money treated “looks like what we usually see” as the same thing as “verified.”

Now the mayor says the town sees no error and should not have to pay the contractor twice. This is a curious definition of error. The town sent a check to the wrong address. The town would not say “we see no error” if it put a check in an envelope addressed to a man who does not exist and mailed it. The town would say we made a mistake, and the contractor who poured concrete is not the one who caused it. But here the error is digital, so the town calls it an act of God — a bolt from the internet no reasonable person could have foreseen.

The federal government has a phrase for the thing that gets money back from overseas scammers: reporting the crime within seventy-two hours. The FBI’s cyber fraud unit recovers pilfered funds about three-quarters of the time when a victim acts in time. Surfside Beach waited forty-five days. The contractor, Alyssa Bowker, was emailing asking about payment for months. The town told her it had already paid. Nobody on the town side looked at the payment record, saw that the money went to a bank account that was not Wildcat’s, and said hmm.

This is the pattern that keeps repeating: the powerful — and the people with check-signing authority over public money are powerful relative to the people who will lose their shirts if the town cannot make a disbursement — treat their own negligence as a kind of innocence. The mayor does not think he erred. The finance director says the form looked legit. The faith is that if the procedure was followed, the outcome is not the town’s fault. But the procedure did not include verifying the identity of the person on the other end of a wire transfer of half a million dollars. The procedure was trusting a pdf. The procedure was the problem.

Meanwhile Alyssa Bowker’s company, Wildcat Contractors, has not been paid for real work performed — underground utility lines on a real street, built by real workers who used real materials and expect real wages. The town’s position is that Bowker should absorb the loss because it was her signature the fraudster lifted. But the fraudster did not lift Bowker’s signature until the town asked for it; the scheme worked because the town accepted an emailed pdf with a blurry CEO signature and did not call to confirm. Bowker’s employees did not make the mistake. Bowker’s project manager did not send the email. The money was in the town’s care until the town mailed it to a stranger.

The mayor says the town should not pay double. The correct reading is: the town should pay the contractor what it owes and then sue the mayor for a refresher on who is responsible for what leaves the town treasury.

The serial catalogue of municipal business email compromise fills itself: Peterborough, New Hampshire, lost $2.3 million and got back $650,000. Lexington, Kentucky, lost $3.9 million but authorities seized all of it and convicted five people. Congress has spent months urging telecoms to bolster protections against cyberscams, and the scammers meanwhile refine the one tool that makes everything easier: as Google’s recent suit against scammers using its Gemini AI to create phishing websites illustrates, AI that smooths the syntax, swaps the telltale “kindly” for natural diction, produces the email an American finance director would write.

The safeguard has not changed. The safeguard is the telephone call picked up and answered. The town called the project manager, reached him, and did not get the confirmation they needed. They called Bowker and left a voicemail she does not recall. They emailed twice to addresses that bounced. And then they wired half a million dollars anyway. The voicemail is still in the machine; the half million is in a Utah bank or wherever the FBI will not recover it. And the contractor who built the underground utility lines on Ocean Boulevard is still waiting for the check the town sent to the wrong person.