July 31, 2026 7:23 am

The premier news source for Snohomish County

Washington State Auditor’s Office urge Lynnwood to strengthen internal controls after 2024 cyberfraud loss

LYNNWOOD — A phishing scheme in 2024 led the City of Lynnwood to deposit $7,158 in payroll funds into a fraudulent bank account, exposing gaps in the city’s internal controls over electronic payments, according to a management letter from the Washington State Auditor’s Office.

internal controls
Image of a copy of the audit report with Lynnwood City Hall on January 19, 2026, in the background. Lynnwood Times | Mario Lotmore.

The letter dated October 20, 2025, summarized issues identified during the accountability audit covering January 1 through December 31, 2024. The matters were not elevated to formal findings in the public audit report but were deemed significant enough to require attention from city management and the City Council. The letter was referenced in the audit report and is a public record.

Auditors found the city lacked adequate internal controls to protect public funds from internal and external threats involving electronic payments. The city reported the phishing incident in 2025. It involved a payroll payment redirected after a fraudulent request that appeared to change an employee’s bank account information.

Since 2016, Washington local governments have reported more than $37 million in losses from cyberfraud schemes including phishing, spearphishing and business email compromises. In these schemes, external actors contact government staff while posing as known employees, managers, vendors or associates, then convince them to redirect legitimate payments or purchase gift cards.

The City of Lynnwood spent about $41.8 million on payroll in fiscal year 2024. Auditors examined controls over electronic payroll payments and identified three specific shortcomings:

  • The city’s policy requiring verification of bank change requests did not include all elements prescribed in the Budgeting, Accounting and Reporting System (BARS) Manual section 3.8.11.30;
  • Staff did not consistently or adequately follow the city’s intended procedures; and
  • Training was ineffective, with employees missing common red flags of phishing schemes.

The BARS Manual requires governments to adopt policies establishing effective internal controls for electronic funds transfers. These include bank-offered security measures to prevent unauthorized transfers, separate user IDs for those initiating or approving transactions, secure processes for creating and authenticating direct-deposit files, and validation of payment authorizations.

State auditors recommended that Lynnwood develop written policies and procedures for electronic payroll payments that incorporate the required BARS elements. The policies is to avoid reliance on information received through email, a medium traditionally vulnerable to unauthorized access. Auditors also urged the city to provide adequate communication and training, so staff can consistently follow verification requirements.

The management letter stated it is intended for the information and use of management and the governing body as recommendations to strengthen internal controls. Auditors said they look forward to reviewing the status of these matters in the city’s next audit.

The letter was disclosed in the City’s Finance Committee meeting on July 21, in connection with a broader financial review that identified underreported deficiencies and processes contributing to an additional $2.2 million budget deficit for 2026 than that was previously reported.

City officials have indicated they are revising internal processes and will work on the improvements.

Mario Lotmore
Author: Mario Lotmore

Tell Us What You Think

    Join Our Mailing List

    Verified by MonsterInsights