Threat reportPhishingTL-2026-3234

DeKalb County, Indiana Vendor Impersonation Email Payment Fraud (Oct 2026)

mediumMONITORING

DeKalb County, Indiana Vendor Impersonation Email Payment (TL-2026-3234), also tracked as DeKalb County cyber financial fraud, is a medium-severity phishing campaign, first published 2026-10-10. It has no confirmed attribution, affects DeKalb County, Indiana County government accounts payable / payment, maps to 5 MITRE ATT&CK techniques (T1566, T1586.002, T1657), and is covered by 9 detection rules and 5 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
5Indicators of compromise

Key facts for TL-2026-3234

Threat ID
TL-2026-3234
Also known as
DeKalb County cyber financial fraud
Severity
MEDIUM
Status
MONITORING
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
government administration, local-government
Target regions
North America, united states of america, Indiana
Detection rules
9
Indicators of compromise
5

How DeKalb County, Indiana Vendor Impersonation Email Payment works

On October 1, 2026, an unidentified actor impersonated a vendor by email to a DeKalb County, Indiana department and requested payment; the county released a fraudulent payment. The county states no internal or external systems or employee/citizen data were compromised, and 94% of the funds had been recovered by Tuesday, October 6, 2026.

DeKalb County, a northeast Indiana county, disclosed that it was the victim of cyber financial fraud on October 1, 2026. A threat actor impersonated a vendor via email and requested payment to a county department, and the county released the payment. Per the county's statement reported by KPC News (The Star) on 2026-10-06, there was no compromise of internal or external computer/network systems and no employee or citizen data was compromised. As of the Tuesday after discovery, 94% of the funds had been recovered and the county was continuing efforts to retrieve the remaining 6%.

The county convened a response team of the County Commissioners (Kellen Dooley, Jim Miller, Terry Yarde), County Attorney, IT Department, Treasurer's Office, Auditor's Office and Emergency Management/Homeland Security (Director Jason Meek). Notified parties: Indiana State Police, FBI, CISA, the Indiana State Board of Accounts, the county's insurance provider, and the financial institutions involved.

The sourced reporting does not state the dollar amount, the vendor's identity, the sender address/domain, the payment rail, whether a real vendor mailbox was compromised or the sender was spoofed/lookalike, or any attribution. The incident is classified as vendor impersonation / business email compromise (BEC)-style payment fraud, a pattern the FBI (PIN of 2021-03-17, coordinated with CISA) documented against state, local, tribal and territorial governments, which uses spoofed emails, phishing, compromised vendor accounts and credential harvesting to alter payment instructions. Those mechanics are context from the FBI advisory and are not confirmed for this incident.

This is the county's second publicly reported cyber incident in about 13 months. A separate September 2025 incident affected employee network login and drives; the county's later breach notice stated that information on the network may have been copied between August 21 and September 25, 2025, and offered credit monitoring. The 2025 incident is a distinct event, and the 2026 county statement says its systems were not compromised. No link between the two is stated in the sources.

MITRE ATT&CK techniques used in TL-2026-3234

Initial Access

T1566 Phishing

Resource Development

T1586.002 Email Accounts

Impact

T1657 Financial Theft

Defense Evasion

T1684.001 Impersonation; T1684.002 Email Spoofing

Affected products and versions in DeKalb County, Indiana Vendor Impersonation Email Payment

  • DeKalb County, Indiana — County government accounts payable / payment approval process (a county department)
    Vulnerable versions: Payment process without verified out-of-band confirmation of vendor payment requests

Remediation for DeKalb County, Indiana Vendor Impersonation Email Payment

Immediate actions

  • Freeze and recall any payment made after a vendor payment-instruction change; contact the originating and receiving financial institutions immediately to request a recall/hold
  • Report to FBI (IC3), Indiana State Police and the county insurer; preserve the original emails with full headers
  • Verify any payment request or banking-detail change through a known-good phone number or contact on file, never the contact details in the request

Workarounds

  • Flag inbound emails that request payment-detail changes or urgent payment and route them to manual verification
  • Alert on new mail rules, auto-forwarding and reply-to mismatches in finance mailboxes

Longer-term hardening

  • Require out-of-band callback verification and dual approval for new or changed vendor payment instructions
  • Maintain a vetted vendor master file and restrict who can change vendor bank details
  • Run recurring security awareness training for treasurer, auditor and accounts-payable staff on vendor impersonation
  • Enforce MFA on all email accounts and deploy email authentication (SPF/DKIM/DMARC) with lookalike-domain and external-sender flagging

Timeline of DeKalb County, Indiana Vendor Impersonation Email Payment

  • FBI TLP:WHITE Private Industry Notification, coordinated with CISA, warns of BEC attacks targeting SLTT governments using spoofed emails, compromised vendor accounts and altered payment instructions
  • Start of the window in which, per the county's 2025 breach notice, information on the DeKalb County network may have been copied by an unauthorized individual (separate earlier incident)
  • County secured the network after the September 2025 incident, which prevented employee login and disabled network drives
  • County response team (Commissioners, County Attorney, IT, Treasurer, Auditor, Emergency Management) engaged and notified Indiana State Police, FBI, CISA, State Board of Accounts, the county insurer and the financial institutions involved
  • Threat actor impersonated a vendor by email and requested payment to a DeKalb County department; the county released a fraudulent payment
  • County reports 94% of funds recovered as of Tuesday, continuing efforts to recover the remaining 6%; no compromise of systems or employee/citizen data; KPC News publishes the story

Sources cited for DeKalb County, Indiana Vendor Impersonation Email Payment

Detection coverage for TL-2026-3234

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3234 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
5 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats