Threat reportPhishingTL-2026-3234
DeKalb County, Indiana Vendor Impersonation Email Payment Fraud (Oct 2026)
DeKalb County, Indiana Vendor Impersonation Email Payment (TL-2026-3234), also tracked as DeKalb County cyber financial fraud, is a medium-severity phishing campaign, first published 2026-10-10. It has no confirmed attribution, affects DeKalb County, Indiana County government accounts payable / payment, maps to 5 MITRE ATT&CK techniques (T1566, T1586.002, T1657), and is covered by 9 detection rules and 5 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 5MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 5Indicators of compromise
Key facts for TL-2026-3234
- Threat ID
- TL-2026-3234
- Also known as
- DeKalb County cyber financial fraud
- Severity
- MEDIUM
- Status
- MONITORING
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, local-government
- Target regions
- North America, united states of america, Indiana
- Detection rules
- 9
- Indicators of compromise
- 5
How DeKalb County, Indiana Vendor Impersonation Email Payment works
On October 1, 2026, an unidentified actor impersonated a vendor by email to a DeKalb County, Indiana department and requested payment; the county released a fraudulent payment. The county states no internal or external systems or employee/citizen data were compromised, and 94% of the funds had been recovered by Tuesday, October 6, 2026.
DeKalb County, a northeast Indiana county, disclosed that it was the victim of cyber financial fraud on October 1, 2026. A threat actor impersonated a vendor via email and requested payment to a county department, and the county released the payment. Per the county's statement reported by KPC News (The Star) on 2026-10-06, there was no compromise of internal or external computer/network systems and no employee or citizen data was compromised. As of the Tuesday after discovery, 94% of the funds had been recovered and the county was continuing efforts to retrieve the remaining 6%.
The county convened a response team of the County Commissioners (Kellen Dooley, Jim Miller, Terry Yarde), County Attorney, IT Department, Treasurer's Office, Auditor's Office and Emergency Management/Homeland Security (Director Jason Meek). Notified parties: Indiana State Police, FBI, CISA, the Indiana State Board of Accounts, the county's insurance provider, and the financial institutions involved.
The sourced reporting does not state the dollar amount, the vendor's identity, the sender address/domain, the payment rail, whether a real vendor mailbox was compromised or the sender was spoofed/lookalike, or any attribution. The incident is classified as vendor impersonation / business email compromise (BEC)-style payment fraud, a pattern the FBI (PIN of 2021-03-17, coordinated with CISA) documented against state, local, tribal and territorial governments, which uses spoofed emails, phishing, compromised vendor accounts and credential harvesting to alter payment instructions. Those mechanics are context from the FBI advisory and are not confirmed for this incident.
This is the county's second publicly reported cyber incident in about 13 months. A separate September 2025 incident affected employee network login and drives; the county's later breach notice stated that information on the network may have been copied between August 21 and September 25, 2025, and offered credit monitoring. The 2025 incident is a distinct event, and the 2026 county statement says its systems were not compromised. No link between the two is stated in the sources.
MITRE ATT&CK techniques used in TL-2026-3234
Initial Access
Resource Development
Impact
Defense Evasion
Affected products and versions in DeKalb County, Indiana Vendor Impersonation Email Payment
- DeKalb County, Indiana — County government accounts payable / payment approval process (a county department)
Vulnerable versions: Payment process without verified out-of-band confirmation of vendor payment requests
Remediation for DeKalb County, Indiana Vendor Impersonation Email Payment
Immediate actions
- Freeze and recall any payment made after a vendor payment-instruction change; contact the originating and receiving financial institutions immediately to request a recall/hold
- Report to FBI (IC3), Indiana State Police and the county insurer; preserve the original emails with full headers
- Verify any payment request or banking-detail change through a known-good phone number or contact on file, never the contact details in the request
Workarounds
- Flag inbound emails that request payment-detail changes or urgent payment and route them to manual verification
- Alert on new mail rules, auto-forwarding and reply-to mismatches in finance mailboxes
Longer-term hardening
- Require out-of-band callback verification and dual approval for new or changed vendor payment instructions
- Maintain a vetted vendor master file and restrict who can change vendor bank details
- Run recurring security awareness training for treasurer, auditor and accounts-payable staff on vendor impersonation
- Enforce MFA on all email accounts and deploy email authentication (SPF/DKIM/DMARC) with lookalike-domain and external-sender flagging
Timeline of DeKalb County, Indiana Vendor Impersonation Email Payment
- FBI TLP:WHITE Private Industry Notification, coordinated with CISA, warns of BEC attacks targeting SLTT governments using spoofed emails, compromised vendor accounts and altered payment instructions
- Start of the window in which, per the county's 2025 breach notice, information on the DeKalb County network may have been copied by an unauthorized individual (separate earlier incident)
- County secured the network after the September 2025 incident, which prevented employee login and disabled network drives
- County response team (Commissioners, County Attorney, IT, Treasurer, Auditor, Emergency Management) engaged and notified Indiana State Police, FBI, CISA, State Board of Accounts, the county insurer and the financial institutions involved
- Threat actor impersonated a vendor by email and requested payment to a DeKalb County department; the county released a fraudulent payment
- County reports 94% of funds recovered as of Tuesday, continuing efforts to recover the remaining 6%; no compromise of systems or employee/citizen data; KPC News publishes the story
Sources cited for DeKalb County, Indiana Vendor Impersonation Email Payment
- County victim of cyber financial fraud (KPC News / The Star)
- DeKalb County officials: Data breach may have included personal information (2025 incident)
- FBI/CISA: Business Email Compromise Against State, Local, Tribal and Territorial Governments
- FBI warns of BEC attacks increasingly targeting US govt orgs (BleepingComputer)
- Ohio Auditor of State: Cybersecurity and fraud guidance
Detection coverage for TL-2026-3234
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3234 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.