# DeKalb County, Indiana Vendor Impersonation Email Payment Fraud (Oct 2026)

> On October 1, 2026, an unidentified actor impersonated a vendor by email to a DeKalb County, Indiana department and requested payment; the county released a fraudulent payment. The county states no internal or external systems or employee/citizen data were compromised, and 94% of the funds had been recovered by Tuesday, October 6, 2026.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3234
- **ID:** TL-2026-3234
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 5 (full data via the Threadlinqs MCP server — Purple tier)

## Description

DeKalb County, a northeast Indiana county, disclosed that it was the victim of cyber financial fraud on October 1, 2026. A threat actor impersonated a vendor via email and requested payment to a county department, and the county released the payment. Per the county's statement reported by KPC News (The Star) on 2026-10-06, there was no compromise of internal or external computer/network systems and no employee or citizen data was compromised. As of the Tuesday after discovery, 94% of the funds had been recovered and the county was continuing efforts to retrieve the remaining 6%.

The county convened a response team of the County Commissioners (Kellen Dooley, Jim Miller, Terry Yarde), County Attorney, IT Department, Treasurer's Office, Auditor's Office and Emergency Management/Homeland Security (Director Jason Meek). Notified parties: Indiana State Police, FBI, CISA, the Indiana State Board of Accounts, the county's insurance provider, and the financial institutions involved.

The sourced reporting does not state the dollar amount, the vendor's identity, the sender address/domain, the payment rail, whether a real vendor mailbox was compromised or the sender was spoofed/lookalike, or any attribution. The incident is classified as vendor impersonation / business email compromise (BEC)-style payment fraud, a pattern the FBI (PIN of 2021-03-17, coordinated with CISA) documented against state, local, tribal and territorial governments, which uses spoofed emails, phishing, compromised vendor accounts and credential harvesting to alter payment instructions. Those mechanics are context from the FBI advisory and are not confirmed for this incident.

This is the county's second publicly reported cyber incident in about 13 months. A separate September 2025 incident affected employee network login and drives; the county's later breach notice stated that information on the network may have been copied between August 21 and September 25, 2025, and offered credit monitoring. The 2025 incident is a distinct event, and the 2026 county statement says its systems were not compromised. No link between the two is stated in the sources.

## MITRE ATT&CK

- T1566 Phishing
- T1684.001 Impersonation
- T1657 Financial Theft
- T1684.002 Email Spoofing
- T1586.002 Email Accounts

## Sources

- [County victim of cyber financial fraud (KPC News / The Star)](https://www.kpcnews.com/thestar/article_36fd4e1e-b9dc-4791-8570-94e28a9b52c4.html)
- [DeKalb County officials: Data breach may have included personal information (2025 incident)](https://www.yahoo.com/news/articles/dekalb-county-officials-data-breach-053742626.html)
- [FBI/CISA: Business Email Compromise Against State, Local, Tribal and Territorial Governments](https://www.ic3.gov/CSA/2021/210318.pdf)
- [FBI warns of BEC attacks increasingly targeting US govt orgs (BleepingComputer)](https://www.bleepingcomputer.com/news/security/fbi-warns-of-bec-attacks-increasingly-targeting-us-govt-orgs/amp/)
- [Ohio Auditor of State: Cybersecurity and fraud guidance](https://ohioauditor.gov/fraud/cybersecurity.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3234
