Skip to main content

Noble Public Schools

#GoBears

Cybersecurity: Scams

For Staff · Tech Tips · Cybersecurity

The Scam That Looks Like Paperwork

Not every scam is sloppy or scary. The most expensive ones are calm, well-written, and look like ordinary office work — an invoice, a quick favor from the boss, a bank-details update. This page is the version that reached us, the four versions you will see again, and the one rule that stops all of them.

Part of Cybersecurity Awareness for Staff.

The Most Important Rule

An approval inside an email isn’t an approval. If an email says the boss already approved something, verify it directly with that person — in person or through another trusted method, not by replying to the email. If they really did approve it, you’ve lost thirty seconds. If they didn’t, you just saved the district a lot of money.

What Happened Here

A quick story from September 2026, in the words of the email that went to staff.

Our Accounts Payable inbox received an invoice for $49,760 from a supposed “consulting firm,” complete with what looked like a reply from Mr. Solomon approving the payment. The problem? Mr. Solomon never wrote a word of it. The company wasn’t real, and the entire email conversation was fabricated.

Nothing was paid because the person who received it did exactly the right thing: they walked over and asked Mr. Solomon, “Did you approve this?” That simple check stopped the scam.

How the Trick Works

  1. Pick a name you’d trust

    The Superintendent’s name is on our website and in board minutes. Scammers start with whoever is easiest to look up and hardest to say no to.

  2. Make up a bill

    A believable company name, a vague service (“advisory,” “consulting”), a big-but-not-shocking amount. Add an invoice and a W-9 so it looks like real paperwork.

  3. Write the boss’s “yes” yourself

    Type a fake reply from Mr. Solomon approving it, and paste it under your own note. This is the entire trick. Everything else is decoration.

  4. Send it to whoever pays bills, and wait

    If someone pays, the money goes out by wire and is gone within hours. If someone replies, the scammer knows they’ve found a live target.

What Gave It Away

  • The red banner covered the whole thing. Everything under it, including the “reply from Mr. Solomon,” arrived in that one outside email. A real reply from him would be in his mailbox, not pasted into a stranger’s.
  • The sender’s address didn’t match her company. Real vendors email you from their own company’s address, every time.
  • “Further to our previous correspondence.” There wasn’t any. Nobody in AP had heard of this person or this company, and the email wasn’t addressed to anyone by name.
  • The “approval” had no email address after the name. Every other message in the chain did. And it didn’t sound like him. Trust that instinct.
  • No purchase order. Nothing gets bought here without a PO issued before the work. Three questions ended it in thirty seconds: Do we have a PO? Did Mr. Solomon approve this? Has anyone heard of this company? All three: no.

You’ll See This Again, in Different Clothes

The details change; the shape doesn’t. A trusted name, a normal-sounding request, money or information on the line, and a quiet nudge to just take care of it. These are the versions that show up in school offices most often.

The Fake Invoice

“Mr. Solomon already approved it.”

A bill for something nobody ordered, with the boss’s “yes” pasted in. Ask the boss. Check for a purchase order.

The Gift-Card Errand

“I’m in a meeting and can’t talk.”

Looks like it’s from your principal or the Superintendent, often from a personal address or unknown number, asking you to buy gift cards and send the numbers. Call them at the number you have. They didn’t send it.

The Direct-Deposit Change

“I’ve switched banks.”

From what looks like a coworker, usually a personal address, usually right before payday. Call the employee. Never change bank details from an email alone.

The Vendor’s “New” Bank

“Please send future payments to…”

Sometimes from a real vendor whose email was broken into, so it all looks right. Call the vendor at a number you already had, not one in the email.

When in doubt, ask the person. Not the email. Walk over, or call a number you already have — never a number or address from the message. Scammers count on you being too busy or too polite to double-check. Nobody here will ever be upset that you asked.

If You Handle Invoices or Payments

These rules are the whole defense. None of them requires a technical eye.

  • No purchase order, no payment. Every real purchase has a PO before the work is done. No PO, not payable — whoever “approved” it.
  • New vendor? Call a number you find yourself — their real website or a prior contract — before the first payment.
  • Bank details changed? Same rule, every time, even from someone you know. Their email may have been broken into.
  • Approval lives in the PO system and in the approver’s own words to you — never in a quote someone else forwarded.
  • The W-9 proves nothing. It’s a blank IRS form anyone can type into. Real vendors send one when the business office asks during setup — which is also when we verify them.
  • If something already went out, tell us the same hour. Banks can sometimes stop a wire in the first few hours. Nobody gets in trouble for reporting fast; the only mistake is waiting.

Not sure? Report it anyway.

One click on the Phish Alert Report button sends it to Technology with everything we need. Not in Outlook? Open a ticket.

Open a Ticket

The Phone Version

The same trick works by voice, and increasingly the email and the phone call come as a pair.

The Two-Step Refund

Email first, then a call

You get a “receipt” for a purchase you never made, with a number to call to cancel. The friendly agent who answers just needs your card or banking details to process the “refund.” Never call the number in a suspicious email. If you’re worried about a charge, call the number on the back of your card.

The Caller Who Already Knows Things

Voice phishing

A caller who knows your name, your school, and your principal’s name isn’t proof of anything — all of it is on our website. Never give a password, a verification code, or account details on a call you didn’t place. Hang up and call back on a number you already have.

Why They Look So Good Now

Scammers use AI. They point AI tools at our website, board agendas, and social media, pull out names, titles, and how we phrase things, and generate a polished, personalized email in seconds — perfect spelling, a believable back-story, the right people named. The September invoice was a form letter with “Noble Public Schools” and the Superintendent’s name dropped in, almost certainly sent to many districts the same day. Watching for typos and clumsy English no longer works. What AI can’t fake is the answer you get when you walk over and ask.

Deepfake Voices and Video

Seeing isn’t believing

A cloned voice or altered video can make a principal, a celebrity, or a family member appear to say anything. Verify surprising requests through a channel you already trust before acting.

AI-Generated Images

Fake photos, fake charities

Look for odd hands, strange lighting, or details that don’t match. Fake disaster photos and fake donation pages appear within hours of real events.

AI Chatbots at Work

Use approved tools only

Never paste student records, staff information, or anything confidential into a chatbot, and double-check what it tells you. See ChatGPT for Teachers for the district’s guidance.

Handouts

Something Look Off? Ask.

Report suspicious email with the Phish Alert Report button, or open a ticket and we’ll take a look. You can always reach the Technology Department at (405) 872-7800 (extension 7800 from a district phone).

More: Cybersecurity Awareness for Staff · Security at Home and on Your Phone · Passwords and Two-Step Verification · All Tech Tips