St. Charles Parish lost over $1.2 million to a vendor email compromise
- Organization
- St. Charles Parish Government
- Exploit
- Business Email Compromise
- Industry
- Government
St. Charles Parish Government in Louisiana disclosed in early September 2024 that it had been defrauded after one of its vendors was hacked. Attackers compromised the vendor's email system and then sent the parish falsified banking documentation that changed where an invoice payment should be directed.
The parish transferred the money to the fraudulent account. The parish did not name the vendor or state the amount of the payment. Sources told WWL Louisiana it was more than $1 million. A later report from the Louisiana Legislative Auditor put the payment at $1,264,603 and dated it 23 August 2024. The scheme came to light when the vendor contacted the parish to ask why it had not been paid.
Parish officials said their own systems had not been compromised and remained secure. Local and federal law enforcement opened an investigation. A cybersecurity specialist quoted by The Times-Picayune said such schemes typically begin with an employee at the supplier being tricked into surrendering an email password, after which the attacker can read correspondence and alter invoices and payment instructions.
The auditor's report, published in November 2025, found that the parish had no adequate controls over changes to vendor banking information and did not detect the fraud promptly. By then the parish had recovered $360,180 through the financial institution involved and a further $500,000 through insurance, and had put new internal controls in place.