A spoofed email cost Guam's government $1.8 million in five weeks

A spoofed email cost Guam's government $1.8 million in five weeks

It took one spoofed email for a fraudster impersonating a Judiciary of Guam official to redirect $1.8 million meant for the court into an account they controlled, according to court records reported by the Pacific Daily News. The FBI has since seized $1 million of it back, but $800,000 is still missing.

Timeline showing how $1.8 million moved from a spoofed email in January to the FBI seizing $1 million on May 4, highlighting the 3-day gap before the fraud was discovered

How $1.8 million moved in five weeks

In January, an unknown fraudster learned that the Judiciary of Guam was expecting a payment from DOA, court documents state. Posing as a Judiciary official through an email address that mimicked the real one, the fraudster contacted DOA's Accounts Payable section and asked that the Judiciary's pending funds be redirected to a new account at Wells Fargo.

DOA asked for verification. On February 5, the fraudster supplied forged documents. The department updated its banking records on February 6 and wired $1.68 million to the fraudulent account on February 16, followed by roughly $107,000 on February 18.

DOA discovered the account change was fraudulent on February 23 and filed a complaint with the FBI's Internet Crime Complaint Center two days later. By then, the money had already moved again: just over $1 million had been transferred out of the fraudster's Wells Fargo account into two JPMorgan Chase accounts on February 20. The FBI traced and seized those funds on May 4, and the US government has since filed a civil asset forfeiture complaint to formally claim the money on behalf of any rightful claimant. About $800,000 taken in the original scheme remains unaccounted for.

Why it worked

Every step of the fraud relied on email as the sole channel of trust. DOA verified the sender through documents sent by email and accepted a bank detail change initiated by email, and no independent, out-of-band confirmation, such as a phone call to a known contact at the Judiciary, took place before the funds moved.

This is a familiar pattern: a plausible internal request, a legitimate-sounding reason for urgency, and a payee change that arrives through the same channel it needs to be verified against. Once the fraudulent banking details were entered as the source of truth, every subsequent check simply confirmed against a record that was already compromised.

The controls that would have stopped this

Three controls would have interrupted this scheme before the wires went out.

  • Verify bank detail changes out of band. Any request to change payment or receiving account details, however it arrives, needs confirmation through a separate channel using a phone number sourced independently of the request itself, not one supplied in the email.
  • Treat "verification documents" as unverified until confirmed by a second source. A forged document sent to support a fraudulent request will look convincing by design. Documents alone should never be sufficient to authorize a banking change.
  • Separate the request from the approval. The employee who receives a change request should not be the same person who confirms and authorizes it. A second reviewer with a standing verification checklist catches what a single point of contact under time pressure will miss.

None of these require new technology. They require treating every bank detail change as a distinct verification event, independent of how convincing the request looks.

What this means going forward

The three controls above cost nothing to implement and would have stopped this scheme at the first email. Any team handling vendor or interagency payments can put them in place this week, starting with a callback number sourced independently of the request itself, not one supplied by the person asking for the change. See how Eftsure verifies vendor bank details before a payment leaves your business, or book a demo to walk through it with your team.

Author

Catherine Chipeta

Published

19 Aug 2026

Reading Time

4 minutes

security-image

The New Security Standard for Business Payments

security-image
security-image