Menu
Browse

Cyber Incident Victim: Chester Upland School District

Date:

Dec 2020

Location:

United States of America

Summary

The Chester Upland School District suffered a business email compromise (BEC) attack in which threat actors, including an individual linked to Nigeria, infiltrated its email system and created a fraudulent mirror account impersonating an employee. Using this access, the perpetrators sent an official-looking request to divert approximately $3 million in state education funds to a bank account controlled by a Florida-based "money mule," who was herself manipulated through a romance scam. The theft was partially thwarted by intervention from the Department of Treasury, preventing further financial losses.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In December 2020, Chester Upland School District in Pennsylvania fell victim to a business email compromise (BEC) scheme involving unauthorized access to its email systems. An attacker associated with Nigeria infiltrated the district’s email infrastructure and created a fraudulent "mirror" account replicating an employee’s legitimate email address. Using this impersonated account, the threat actor sent an official-looking email request to the Pennsylvania Department of Education, directing the diversion of state funds intended for the school district. The fraudulent communication successfully deceived authorities into transferring approximately $3 million in public education funds. A Florida-based individual, later identified as a "money mule," facilitated the movement of stolen funds after being recruited through a separate romance scam orchestrated by the attackers. The theft targeted scheduled disbursements from state coffers to the district over the fiscal year.

Cyber Incident Image

Delaware County District Attorney Jack Stollsteimer publicly disclosed the incident on August 26, 2022, confirming the theft’s international origins and the money mule’s unwitting involvement. The Department of Treasury intervened during the attack, preventing additional financial losses beyond the confirmed $3 million. No technical details regarding the initial email system breach, detection methods, or containment procedures were disclosed in available reports. The incident impacted the district’s operational funding stream, though specific consequences such as service disruptions or recovery costs were not quantified. Law enforcement emphasized the exploitation of both technical vulnerabilities and human manipulation through the romance scam to execute the financial fraud.

Sources
Sources available to members
1 source