The FBI issued a public service announcement warning of an emerging phishing and payment-fraud scheme in which criminals impersonate U.S. city and county planning/zoning officials to target businesses and individuals with active land-use, planning, or zoning permit applications. The attackers use publicly available permit information to make messages appear legitimate, referencing real details such as property addresses, permit or case numbers, and names of actual officials; emails may include official-looking formatting and PDF invoices with itemized “fees.”
Victims are directed to pay purported permit-related fees via wire transfer, peer-to-peer payment apps, or cryptocurrency, and the emails may instruct recipients to request payment instructions via email (rather than phone) to discourage verification with government offices. Reported indicators include sender addresses from non-governmental domains (e.g., lookalike domains) and urgency tactics tied to permit timelines. The FBI advised recipients to validate sender domains and independently confirm any outstanding fees by contacting the relevant city/county office, and to report incidents to the FBI’s IC3 with available details (e.g., sender email, dates, and any phone numbers used).

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
The FBI, via the Internet Crime Complaint Center, publicly warned of an emerging nationwide phishing scheme in which criminals impersonate U.S. city and county planning and zoning officials to steal permit payments. The alert said attackers use publicly available permit details to craft convincing emails and invoices, pressure victims to pay via wire transfer, peer-to-peer apps, or cryptocurrency, and advised recipients to verify requests through official government channels and report incidents to IC3.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
7 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcetherecord.media
Open sourcesecurityaffairs.com
Open sourceic3.gov
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.