Executive Summary
In March 2026, the FBI issued a public alert regarding a sophisticated phishing campaign where cybercriminals impersonated city and county planning officials to defraud property owners. By leveraging publicly accessible permit records, these actors sent emails to individuals with active applications, demanding payments for fictitious permit fees via wire transfers, peer-to-peer transfers, or cryptocurrency. The emails were meticulously crafted, incorporating real permit details to enhance credibility, leading victims to authorize payments that bypassed traditional fraud detection mechanisms. This scheme resulted in significant financial losses and highlighted vulnerabilities in existing payment verification processes.
The urgency of this issue is underscored by the rapid escalation of government impersonation scams, which nearly doubled in reported losses to approximately $798 million in 2025. The increasing sophistication of these attacks, particularly their ability to exploit publicly available data and evade standard fraud detection systems, necessitates immediate attention and the development of more robust security measures to protect individuals and businesses from such fraudulent activities.
Why This Matters Now
The rise in government impersonation scams, exemplified by the recent fake permit fee scheme, underscores the urgent need for enhanced verification processes and public awareness to prevent substantial financial losses.
Attack Path Analysis
Attackers identified property owners with active permit applications using public records, then sent phishing emails impersonating city officials to request fraudulent fees. Victims, believing the emails to be legitimate, authorized wire transfers to attacker-controlled accounts. The attackers then laundered the funds through a network of mule accounts to obscure the money trail. Finally, the stolen funds were withdrawn or transferred to other accounts, completing the financial theft.
Kill Chain Progression
Initial Compromise
Description
Attackers identified property owners with active permit applications using public records and sent phishing emails impersonating city officials to request fraudulent fees.
MITRE ATT&CK® Techniques
Financial Theft
Social Engineering: Impersonation
Compromise Accounts: Email Accounts
Email Collection
Phishing
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Detect and respond to unauthorized changes to critical systems
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Incident Handling
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct impersonation targets with fraudulent permit fee schemes exploiting public records, requiring enhanced egress security and email authentication to prevent business email compromise attacks.
Real Estate/Mortgage
Primary victim sector for fake permit fee scams targeting property owners with active applications, vulnerable to social engineering through legitimate-appearing municipal communications and wire fraud.
Construction
High-risk sector frequently requiring legitimate municipal permits and fees, making contractors susceptible to government impersonation schemes demanding fraudulent planning and zoning payments via wire transfers.
Financial Services
Critical infrastructure enabling mule account operations for fraud monetization, requiring enhanced beneficiary screening and anomaly detection capabilities to identify unauthorized destination accounts and prevent wire fraud.
Sources
- The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Futurehttps://www.recordedfuture.com/blog/fbi-fake-permit-feesVerified
- FBI warns of phishing attacks impersonating US city, county officialshttps://www.bleepingcomputer.com/news/security/fbi-warns-of-phishing-attacks-impersonating-us-city-county-officials/Verified
- FBI Warns of Phishing Scams Impersonating Local Government Officials.https://www.infortech.com/2026/03/10/fbi-warns-of-phishing-scams-impersonating-local-government-officials/Verified
- FBI Warns Criminals Impersonating City and County Officialshttps://buildingconnections.seattle.gov/2026/06/01/fbi-warns-criminals-impersonating-city-and-county-officials/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to exploit implicit trust within the network, thereby reducing the blast radius of the attack.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit implicit trust within the network would likely be limited, reducing the blast radius of the attack.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges within the network would likely be constrained, reducing the scope of potential damage.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be limited, reducing the risk of widespread compromise.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels would likely be constrained, disrupting their coordination efforts.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data or funds would likely be limited, reducing the success of the theft.
The financial impact on victims would likely be reduced due to constrained attacker capabilities.
Impact at a Glance
Affected Business Functions
- Permit Processing
- Financial Transactions
- Customer Communications
Estimated downtime: N/A
Estimated loss: N/A
No sensitive data exposure reported; the scam primarily involves fraudulent financial transactions.
Recommended Actions
Key Takeaways & Next Steps
- • Implement email filtering solutions to detect and block phishing attempts impersonating officials.
- • Educate employees and clients on recognizing phishing emails and verifying payment requests.
- • Establish strict verification processes for financial transactions, especially those requested via email.
- • Monitor and analyze outbound financial transactions for signs of money laundering activities.
- • Collaborate with financial institutions to track and freeze suspicious transactions promptly.



