Home - Article

Featured Article

January 22, 2026

In a Connecticut Port, Phishing, not Fishing Stole $16,000


Sometimes the difference between a routine payment and a financial loss comes down to details so small they are easy to overlook. A couple of letters. A familiar sender name. An email that looks right at a glance.

That was the case for the Connecticut Port Authority, which recently disclosed that a subtle change in a vendor email address led to more than $16,000 being sent to a fraudulent account. While most of the money was ultimately recovered, the incident underscores how vulnerable even established public agencies can be to phishing schemes that exploit trust and routine.

The authority oversees the New London State Pier and deep-water ports in Bridgeport and New Haven. Like many organizations, it processes a steady flow of vendor invoices, often under time pressure and with an assumption of good faith. That assumption is exactly what the attackers relied on.

Here’s the thing. This was not a sophisticated technical breach involving malware or ransomware. It was a social engineering attack, executed quietly and patiently, using email alone.

According to a report submitted to state auditors, the phishing incident centered on a legitimate invoice for recruitment services from Flagship Management. On Feb. 3, 2025, the invoice arrived via an email address that appeared correct: [email protected]. Nothing unusual there.

Nine days later, on Feb. 12, a follow-up email arrived asking about the status of the payment. The message stated that the “vendor is updating its payment information” and came from [email protected]. At a glance, the addresses looked nearly identical. In reality, those two extra letters redirected the payment to a fraudster.

The port authority processed the $16,666 payment using the updated information. The funds went through. Only later did anyone realize something was wrong.

“Discovery of this fraudulent payment was made on 04/11/2025 when the accurate vendor reached out regarding payment and the Finance Director reviewed the payment history,” wrote Finance Director Fayola Haynes in a Dec. 16, 2025 letter to state auditors. “It was only at this time that the varying domain accounts were observed.”

By then, the damage was done. The authority contacted its bank, which attempted to recover the funds, but the effort came up short. Haynes noted that the “fraudster had already withdrawn the funds from the recipient bank.” Ultimately, $14,166 of the $16,666 was recovered through an insurance claim, leaving the authority with a smaller but still meaningful loss.

The incident was reported to the Old Saybrook Police Department and the Federal Bureau of Investigation. As of the time of the report, Haynes said there had been “no updates” from either agency. Officials from the port authority did not respond to additional requests for comment.

What makes this case notable is how ordinary it was. No one clicked on a suspicious attachment. No credentials were knowingly handed over. Instead, the fraud relied on timing, familiarity, and the assumption that email equals authenticity. How many finance departments see follow-up emails like this every week?

The broader context makes the lesson even clearer. The Federal Trade Commission reports that cyber scams cost the U.S. $12.5 billion in losses in 2024, with phishing playing a major role. Experts estimate that phishing accounts for 36 percent of annual data breaches in the United States. Those numbers are not driven solely by small businesses or individual victims. Public agencies, utilities, and infrastructure operators are increasingly part of the statistics.

To its credit, the port authority did not treat the incident as a one-off embarrassment. Haynes told auditors that the authority has “undertaken steps to prevent a recurrence of a similar situation.” Those steps include reviewing policies and procedures, renewing focus on internal controls, improving security and data encryption, and planning to conduct monthly cybersecurity training and awareness sessions.

That last point matters more than it might sound. Training is often treated as a checkbox exercise. But phishing attacks evolve constantly, and the smallest variations are often the most dangerous. A domain name that differs by two letters is easy to miss unless employees are specifically trained to slow down and verify changes to payment instructions through a second channel.

Another takeaway is the role of outside service providers. Haynes noted that the port authority’s external IT services company identified the source of the breach and provided relevant documentation in April. That suggests monitoring and forensic capabilities were already in place, even if the initial fraud slipped through.

Still, prevention is always less costly than recovery. Insurance covered most of the loss this time. Next time, the amount could be higher, or the funds might be unrecoverable. Or the attack might not stop at a single payment.

So what should organizations learn from this?

First, never accept changes to vendor payment information based solely on email. Period. Verification through a known phone number or secure portal should be mandatory. Second, domain monitoring and email security tools can flag lookalike domains before they cause damage. Third, ongoing training needs to be practical and repetitive, not theoretical.

And finally, organizations should recognize that cybersecurity is not just a technology problem. It is a process and people problem. The attackers didn’t hack a server. They hacked trust.

As phishing scams continue to grow in volume and subtlety, working with a quality managed services provider can help reduce risk. Firms such as Apex Technology Services focus on layered security, user awareness, and process discipline that can make these kinds of attacks easier to detect before money leaves the account. No system is foolproof, but thoughtful safeguards can make a costly mistake far less likely.






SHARE THIS ARTICLE
Apex Technology Services
Choose from comprehensive, affordable solutions for IT consulting, network services and computer help desk support in Fairfield county including Norwalk, Darien, Stamford, Greenwich, Ridgefield and Bridgeport. Also Westchester county including Rye, New Rochelle, White Plains, Yonkers and New York including Manhattan and the five boroughs.
IT SERVICES

IT SERVICES

Apex Technology Services is a cutting edge MSP offering quality IT support to financial, medical, legal, Fortune 500 and government agencies while adhering to the highest of quality...

LEARN MORE
CYBERSECURITY Services

CYBERSECURITY

Apex Technology Services has the cybersecurity expertise to help your business in a world filled with attackers looking to shut down your business hold it ransom or steal your valuable...

LEARN MORE
CLOUD SERVICES

CLOUD SERVICES

Apex Technology Services delivers a combination of traditional IT functions such as infrastructure as a service (IaaS), applications, software, security, monitoring, storage...

LEARN MORE

Ranked Top 10 Network security Solution Provider

One Stop Shop For All Your Technology Needs


Contact us Now!