Understanding How Scammers Stole $1M from the city of Pittsburg, California, reveals just how sophisticated modern online fraudsters have become. On February 12, city financial clerks wired $913,000 intended for the construction of the Dream Courts sports complex directly to offshore accounts. Officials only realized the money was missing five days later when the real construction company called asking for their payment. By altering a single letter in an email address and hacking an internal city account, cybercriminals successfully hijacked a major public project fund.
The Tactics Behind How Scammers Stole $1M in Public Funds
The attack was built on a clever combination of email spoofing and internal employee impersonation. Cybercriminals created a fake domain name for the contractor, Discovery Builders Inc., adding a single extra lowercase letter “l” to the company’s address.
After sending fake banking update details, the fraudsters went a step further by hacking the email account of an assistant to the city manager. Impersonating the assistant, they emailed a city finance worker to confirm that the new bank account details were verified, causing the clerk to wire the $913,000.

Tracking the Lost Cash and Recovering the Funds
Once the wire transfer went through, the funds were quickly split across a complex chain of international bank accounts. An investigation involving federal authorities traced the stolen money through 116 accounts linked to suspects in the United States and Nigeria.
In one instance, an unsuspecting worker in Illinois was tricked into receiving part of the stolen cash and converting $217,000 of it into Bitcoin through a fake job scheme. Fortunately, investigators froze the main receiving account quickly enough to help Pittsburgh recover around $696,000. The city expects its final loss to sit around $100,000 after insurance claims go through.
My Opinion
This $1 million heist shows why government agencies and private businesses cannot rely on email alone to transfer large amounts of money. A single typo in an email address should never be enough to drain nearly a million dollars out of a city’s account.
Cyber criminals spend months watching email chains, learning how staff talks to each other, and waiting for the right moment to strike. When a local government handles millions in taxpayer money, approving bank account changes through routine email messages is a disaster waiting to happen. An internal email, even one coming from an assistant city manager, is simply not proof that a change is real.
Every city finance department needs a simple rule: no banking details ever get changed without a verified phone call or an in-person meeting using verified records. If the city of Pittsburgh had required two staff members to call the contractor directly before clicking send on a $913,000 wire, this entire mess would have been avoided. As public projects get more expensive, local governments must update their security habits to match modern threats.
Bottom Line
The breakdown of How Scammers Stole $1M serves as a serious warning for municipal governments everywhere. Pittsburgh has since tightened its payment verification steps, updated workflow policies, and restructured its IT security team. While the Dream Courts project remains on track for completion, this costly incident demonstrates that strong security habits are just as important as software protections when safeguarding public money.





