Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Accounts Payable topic

No spam. Unsubscribe anytime.

Walworth County finance staff report attempted accounts-payable fraud; controls tightened

2390554 · January 23, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Finance staff told the Walworth County Finance Committee an August attempt to reroute vendor payments was stopped before funds were lost; the county has added verification steps after an internal review and a sheriff's investigation traced the scheme to out-of-country actors.

Walworth County finance staff reported to the Finance Committee on Jan. 23 that an attempted accounts‑payable fraud from August 2024 was identified and stopped before funds were permanently lost.

Finance staff said the incident began with an email on Aug. 15 requesting a change to a vendor's bank account. The county received a voided check and a completed form; staff later discovered the form marked the request as a new electronic funds transfer when the vendor already had EFT information on file. On Aug. 22 the county issued a paper check for $289.69 as part of its verification steps. On Sept. 5 the county initiated a small EFT to the new account for $182.00. On Sept. 12 the county initiated an EFT for $789,074.14 with a planned settlement date of Sept. 17; that transaction was stopped after the county's bank fraud unit contacted staff and flagged the payment.

The presenting finance staff member said the county's procedures required verification of all EFT changes by a second communication method and that step had not been followed in this case. ‘‘We need to be rejecting the information. It can't just be, 'they filled it out to the best of their ability,' ’’ the presenter said, summarizing a key lesson learned.

The county audited six months of vendor‑change activity, opened a case with the Walworth County Sheriff's Office and said the sheriff's investigation traced the scheme to fake companies, addresses and phone numbers outside the country. The presenter said no county funds were ultimately lost.

As a result, the county described three layered changes to its workflow: (1) a named recipient reviews incoming change requests for red flags, (2) a data‑entry reviewer verifies and flags suspicious items, and (3) an electronic approval step requires a separate outreach to the vendor using contact information already on file. The county also described a new written red‑flag checklist and more staff training, and said it now requires monthly billing for court‑appointed attorney contracts to improve budgeting and detect anomalies earlier.

Committee members asked whether large payments receive extra review; the presenter said all outgoing batches are reviewed but emphasized the need to match vendor contact methods to the stored vendor records before changing EFT instructions.

The committee received the presentation; no committee vote was required. The presenter asked department heads to share the lessons with their staffs and said the finance office will continue to refine procedures.

The county named the vendor involved in the attempted change as Payne & Dolan (a construction contractor) and said staff encouraged the sheriff's office to contact that vendor, but county staff did not report whether Payne & Dolan experienced related fraud attempts elsewhere.

The county recorded the incident in the committee packet as “presentation of 2024 Walworth County accounts payable attempted cybersecurity fraud incident.”