A person reviewing email messages on a laptop computerBaldwin County officials say fraudulent emails are targeting people with active Planning and Zoning cases.

The email looks right. It cites the correct case number. It names the correct parcel. It refers to a hearing date that really is on the calendar. And then it asks for a payment to be wired somewhere.

That is the scheme Baldwin County officials are now warning about. The Baldwin County Commission says it has received several reports of fraudulent emails tied to active Planning Commission cases, aimed at property owners and at the professionals — engineers, surveyors, developers, contractors and attorneys — who file on their behalf.

The messages, according to the commission, may contain legitimate case numbers, property information or other publicly available details in order to make fraudulent payment requests appear credible. The county’s central point is blunt: accurate information inside an email is not evidence that the email is real.

What the County Is Actually Saying

Stripped to its essentials, the commission’s warning contains four hard rules that applicants can check any suspicious message against:

  • Baldwin County accepts payment for permits only through its official CitizenServe Portal or in person at Baldwin County office locations.
  • The Baldwin County Commission does not request wire transfers at any time.
  • Anyone who receives an email directing them to submit a permit payment through another method should not send payment and should not provide financial information.
  • Applicants should independently contact the Baldwin County Commission to verify any questionable payment request.

Suspected fraud should also be reported to the FBI’s Internet Crime Complaint Center, the county said.

The value of a rule like “we never request wire transfers” is that it does not depend on the recipient spotting anything subtle. It converts a judgment call — does this email feel legitimate? — into a fact check that anyone can perform in a second. If the request is for a wire, it is not the county.

This Is a National Pattern, Not a Local Glitch

The FBI’s Internet Crime Complaint Center, known as IC3, issued a nationwide public service announcement in March 2026 warning about this type of fraud targeting planning, zoning and permitting applicants across the country. Baldwin County pointed to that advisory in its own notice.

The underlying crime has a name in federal terminology: business email compromise, usually shortened to BEC. It is not a technically sophisticated attack. There is no malware in the classic version of it and often nothing for antivirus software to catch. The entire mechanism is a convincing message that redirects a payment the victim was already planning to make.

IC3, which collects public reports of internet crime and routes them to law enforcement, has consistently identified business email compromise as one of the costliest categories of cybercrime it tracks, with aggregate reported losses running into the billions of dollars a year nationally. The losses are large not because individual victims are careless but because the payments involved are legitimate in every respect except their destination.

See also  Before the Candidates Arrive: Mobile's Civic Class Names the Issues for the 2009 City Elections

Why Planning and Zoning Files Are an Ideal Target

Local land-use processes are, by design and by law, public. That transparency is a feature of government — and it is also a free research library for a fraudster.

A planning commission generates a remarkable amount of usable material in the ordinary course of business:

  • Agendas and staff reports that list case numbers, applicant names, property addresses and parcel identifiers.
  • Meeting minutes that record what was approved, denied or continued, and when.
  • Published fee schedules that make it possible to name a plausible dollar amount.
  • Notices to adjacent property owners, which reveal who else is connected to a case.
  • Consultant and engineering firm names on submitted plans, which reveal who the applicant is working with.

Combine those and it becomes possible to write a message that reads exactly like routine correspondence: the right case, the right site, the right stage of the process, the right kind of fee. The only false element is the payment instruction.

The timing advantage is the second half of it. Land-use cases run on a schedule that is published in advance. Someone watching an agenda knows roughly when an applicant is expecting to hear something and when a fee would plausibly come due. An invoice that arrives at the moment a person is already anticipating one is far more likely to be paid without a second look.

How These Emails Are Built

The mechanics of business email compromise are worth understanding, because they explain why the messages survive a quick glance.

The most common technique is a lookalike domain. An address is registered that differs from the real one by a character or two — a swapped letter, an added hyphen, a different suffix — and mail sent from it passes ordinary authentication checks because the domain genuinely belongs to the sender. Nothing is technically forged. The name in the “From” field, which is the only part most email clients display, can be set to whatever the sender wants.

A second technique is display-name spoofing, where the visible sender name matches a real official or department while the actual address underneath does not. On a phone, where the address is often hidden entirely, that difference is invisible unless the recipient deliberately expands the header.

A third and more damaging variant involves a compromised mailbox somewhere in the chain — not necessarily the county’s. If any participant in a project has had an account accessed, an attacker can read genuine correspondence, learn the vocabulary and cadence of a real thread, and then insert a payment request into a conversation that has been running for weeks. Nothing about that message looks new, because it is not new. Only the banking details are.

See also  MAWSS: Online Service Requests Temporarily Down Amid System Upgrade

Finally, there is the request itself. Wire transfers are the preferred instrument for a reason. A wire is fast, is treated as final once it settles, and does not carry the chargeback protections that come with a credit card. Recovery, when it happens at all, depends on freezing the funds before they move again — which is a race measured in hours, not weeks.

Concrete Steps for Property Owners and Applicants

The defense against this fraud is procedural rather than technical. A handful of habits eliminate almost all of the risk.

Verify out of band, every time. Do not reply to the email, and do not call a number printed inside it. Look up the county’s phone number independently — from a bookmark, a prior invoice, printed correspondence or the official website typed in by hand — and call to confirm the request. This single habit defeats the entire category, because the fraudster controls only the channel the message arrived on.

Pay through the published channel and nowhere else. Baldwin County has named its two acceptable methods: the official CitizenServe Portal, or in person at a county office. Any instruction that routes around those two options is a reason to stop, regardless of how the message is worded.

Treat any change in payment instructions as suspect by default. A new account number, a new bank, a “temporary” account during a system upgrade, or an urgent request to use a different method are the classic markers of this fraud. Legitimate changes survive verification; fraudulent ones do not.

Read the full sender address, not the display name. Expand the header on a phone. Compare the domain character by character against a message you know is genuine. Note that a reply-to address can differ from the address the mail appears to come from.

Be alert to manufactured urgency. Language about a case being pulled from an agenda, an application lapsing, a deadline expiring today, or a permit being voided is designed to prevent the phone call that would expose the scheme. Real deadlines can be confirmed by the office that set them.

Escalate internally before you send. Firms that handle client payments should require a second person to approve any wire, any first-time payee and any change to existing payment details. Most successful losses involve one person acting alone under time pressure.

If a payment has already gone out, move immediately. Contact the originating bank and ask for a recall, then file a report with IC3 at ic3.gov and notify local law enforcement. The FBI has a process for attempting to freeze fraudulent transfers, and its usefulness declines sharply with time. Reporting within the first day or two matters far more than the completeness of the report.

See also  Mobile's Push for a New Animal Shelter Runs Into Resistance Over Consultant-Driven Overhaul

Reporting Helps Even When the Money Is Gone

People who catch one of these emails before losing anything often assume there is nothing to report. There is.

Complaints filed with IC3 are how the pattern behind an individual message becomes visible. A single fraudulent invoice sent to one Baldwin County applicant is close to untraceable in isolation. The same lookalike domain appearing in complaints from a dozen counties in a dozen states is a case. That aggregation is precisely what produced the March 2026 advisory in the first place, and it is why the county is asking recipients to forward suspected fraud to IC3 as well as to the commission.

Reporting to the county has a separate purpose. It tells staff which cases are being targeted and what details the fraudsters already have, which helps the county warn the specific applicants most likely to be hit next.

Why It Matters Here

Baldwin County is one of the fastest-growing counties in Alabama, and growth of that kind runs directly through the planning and permitting office. Subdivisions, commercial sites, rezonings, variances and infrastructure approvals all move through the same process, and every one of them generates the paperwork that makes this fraud possible — and payments large enough to be worth stealing.

The people most exposed are not necessarily the least careful. They are the ones with the most active files: builders, developers, engineering firms and property owners in the middle of a project who receive legitimate county correspondence often enough that one more message does not stand out.

The county’s advice reduces to a single habit. Before any permit-related payment leaves an account, confirm it by phone using a number you looked up yourself, and send it only through the CitizenServe Portal or in person. An email that contains the right case number has proven only that its author can read a public agenda.