Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Southern Door board details phishing fraud that led to two mistaken payments; district tightens controls

Southern Door County School District Board of Education · July 21, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Southern Door County School District disclosed a phishing scheme that produced two erroneous payments in 2025, said administrators, who described recovered funds (minus the deductible), law-enforcement action and multiple new safeguards including stopping email approvals, new vendor procedures and expanded staff training.

Administrators told the school board on July 20 that a phishing scheme led to two district payments in fall 2025 after someone impersonated a vendor and an email account the district associated with the superintendent.

The superintendent and business staff said the fraud involved invoices paid in September and October 2025. After the district identified the payments in November 2025 it contacted law enforcement, its bank and its insurer; the district said it has recovered its losses except for the insurance deductible. On July 6, 2026, authorities charged a woman from Ohio with two felony counts in Door County in connection with the incident; the district was informed of the charges on July 13, 2026.

Administrators described how the payment got through during a period of staff turnover and training gaps. They said the district had allowed some email approvals during a transition and had been relying on a contracted consultant (CESA 7) who was on-site part time; that combination, they said, allowed a fraudulent vendor to be entered and paid. The board pressed for details about approval levels and where the checks and balances failed.

The finance team outlined immediate and longer-term changes: requiring purchase orders for more purchases, formalizing vendor onboarding with a new vendor-request form and verification (including sam.gov checks), discontinuing email approvals, expanding blanket purchase orders where appropriate, adding additional reviews of invoices before payment and improving month-end close procedures. The district also said it upgraded email filtering, purchased new security tools and ran phishing-simulation training for staff; cybersecurity training will be folded into annual staff training.

Board members asked whether contracted consultants (CESA 7) share liability; administrators said they had not pursued that avenue. Some trustees pushed for faster public communication and transparency; administrators said they had not done a press release at the time, instead working with bank and insurer, and acknowledged in hindsight a public notice would have been appropriate.

The board did not take formal action on the matter at the meeting but approved placing personnel and any performance-related follow-ups in closed session for further review. The district said it will file the Act 12 and other required reports and continue cooperating with investigators.