Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Finance Fraud topic

No spam. Unsubscribe anytime.

Pender County outlines response after roughly $581,000 redirected in ACH fraud

Pender County Board of Commissioners · January 6, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

County manager described a mid‑September ACH fraud that redirected roughly $581,000 in payments meant for Lower Cape Fear Water and Sewer Authority; county filed an IC3 complaint, engaged law enforcement and the state auditor, and tightened Munis vendor‑change controls and phishing training.

Pender County officials on Jan. 5 publicly described steps taken after an attempted ACH scam that led to at least one large payment being sent to fraudulent banking information.

County Manager Colby Sawyer said the incident began in mid‑to‑late September when staff received an invoice from the Lower Cape Fear Water and Sewer Authority for about $581,000 that was followed by an apparently legitimate request to change the vendor's banking information. “We made that change on October 1,” Sawyer said in the meeting. Subsequent invoices were paid to the altered account before county staff and the vendor realized something was wrong in December, he said.

Sawyer said finance staff discovered the discrepancy after the vendor contacted the county about unpaid invoices. The county immediately launched an internal inquiry, implemented cybersecurity protocols, pulled logs and preserved eDiscovery, and contacted the sheriff's office, the FBI and the State Bureau of Investigation. By 8:30 p.m. the county had filed an IC3 (Internet Crime Complaint) to notify federal authorities, Sawyer said.

Finance staff (identified in public remarks as “Meg”) described the county’s prior vendor‑change verification process—contacting the county department that had the vendor relationship, checking published phone numbers, and confirming recent invoice numbers—and said county procedures have been strengthened. “We have a form that vendors can fill out that would request this specific change, and we document who we talk to when we talk to them,” Meg said. The county has implemented a multi‑step approval workflow in its Munis system requiring multiple approvals for vendor changes and added enhanced phishing training for staff who handle invoices.

IT Director Marcel Miranda told commissioners the county is on the latest Tyler Enterprise ERP (Munis) build and has implemented additional configured controls so an ACH or vendor change requires three separate approvals. Miranda said additional fields were locked and additional approvals added so field edits generate notifications requiring review.

Sawyer said the county has engaged outside partners, including the vendor’s bank and the county’s insurers, and has invited the state auditor to assist. “They have some powers that allow them to trace funds and recover funds a little more quickly,” Sawyer said, and the county has requested both a forensic cybersecurity review and a financial audit at state expense.

Sawyer emphasized the payments were made from enterprise funds and said staff believe the incident was isolated to the vendor involved. He declined to discuss active investigative details or personnel matters in open session. The county did not provide an immediate public accounting of recovered funds; Sawyer described the dollar figure referenced in the meeting as about $581,000.