Sumner County recovers funds after vendor-payment phishing attempt; staff to tighten vendor-ACH checks

Sumner County Financial Management Committee · January 8, 2026

Get AI-powered insights, summaries, and transcripts

Subscribe
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Finance staff reported an attempted phishing scam that tricked an AP clerk into initiating a small ACH payment to a fraudulent account, but the bank recovered the funds; the county will add department confirmation before changing vendor payment methods.

Sumner County finance staff told the Jan. 7 financial management committee that a vendor‑payment phishing scheme briefly succeeded in authorizing a small ACH payout but that the county secured a full recovery.

An accounts‑payable coordinator received a series of emails impersonating a highway vendor (Rogers Group) and approved a $348.60 ACH payment after what staff described as an apparently legitimate email and logo with a slightly different domain (".us" instead of ".com"). The payment posted but staff immediately flagged the transaction as suspicious; the county contacted the bank and the funds were returned.

Finance staff described that multiple invoices in the email thread would have amounted to significantly larger payments, and they commended the AP coordinator for processing only the smallest item before the scam was detected. "We got the money back," staff said.

As a control improvement, the county will block suspicious email addresses in its systems and institute a step to contact the originating department before changing a vendor’s payment method to ACH.

What’s next: staff will work with IT to block the perpetrator’s email addresses and present revised procedures for vendor‑payment changes to reduce the risk of future fraudulent requests.