OCALA, FL (352today.com) – On August 4, 2026, Ocala City Councilman Jim Hilty and City Manager Pete Lee had a pointed exchange at the regular city council meeting over whether residents should have been told before that day’s scheduled city council meeting that the city had lost a large vendor payment to a scam. Hilty said the public was owed an explanation that night. Lee said the investigation was still open and that going public before a full report would be premature.

Five weeks later, Internal City Auditor Vincent Iovino’s September 8 report put a sharper point on both the money and the delay. The report states the fraud could have been stopped.

“In summary, the incident could have been stopped at the onset if the EFT verification process was followed correctly. The initial slow response to initiate the Incident Response Plan was attributed to the former Fiscal Operations Manager’s efforts of concealment through his misleading statements. The City’s insurance carrier reduced the original loss of $277,779.81 to $27,799.81.” Iovino wrote.

That finding is now the center of the story Hilty forced into the open in August.

What the public first heard

At the end of the Aug. 4 city council meeting, Hilty said the city “was fleeced out of almost $500,000” and that a fraud case dating to the spring “obviously was covered up for whatever reasons.” He told Lee the meeting was the moment to be transparent rather than waiting for council members to ask.

Lee answered that it was not a cover-up. He said he had told Hilty the day before that he would not raise the matter that night because the probe was unfinished, and that he was “certainly not trying to not be transparent. I’ve been transparent with every one of you.”

Council member Jay Musleh sided with waiting. After talking with Lee and learning an internal audit had started, Musleh said a complete report would better serve the public with a timeline, corrective steps, and the insurance outcome rather than a partial airing without those facts.

The city later issued a statement saying leadership had learned of a fraudulent scheme that resulted in the theft of $277,799.81, that no city systems were compromised, and that the internal auditor, insurers, and other agencies were still investigating. It said releasing more detail too soon could hurt the investigation and recovery.

Neither the vendor nor the employees were named.

What Iovino later documented

The payment that started the debacle was $492,056.44, sent on April 30, 2026, to a scammer instead of a city vendor.

According to Iovino’s Sept. 8 report, city staff had asked to switch that vendor from paper checks to electronic bank payments. A scammer had already taken over the vendor’s email. The Multi-State Information Sharing and Analysis Center (MS-ISAC), a cybersecurity group that helps local governments, confirmed the compromise was on the vendor’s side.

The scammer intercepted the emails, sent the city a fake Electronic Funds Transfer form, and staff entered the scammer’s bank account. City procedure required a call to the vendor on a phone number already on file before any bank change. That call was not completed. Iovino’s conclusion: The incident could have been stopped there.

Why the official response came late

On May 5, 2026, the scammer’s bank called a city finance employee, said the name on the account did not match, and asked whether the payment should be stopped. It was not stopped immediately.

Iovino wrote that the former Fiscal Operations Manager then minimized what had happened. The report cites an Ocala Police Department email labeled “Fraud Attempt,” a detective’s note that the manager said the transfer failed and no money was lost, and repeated assurances to other officials that the funds would come back and that there was “no risk.” The manager also left his supervisor off key bank emails. The report says those statements suppressed escalation.

“The former Fiscal Operations Manager delay to initiate the payment recall process contributed to the City’s inability to recover all the funds. Additionally, he excluded his supervisor from email communications related to the EFT breach and suppressed escalation by using terms such as ‘attempted fraud’ and by suggesting that the threat actor’s bank would return all funds,” Iovino wrote.

The matter was referred to the city attorney.

The city’s Incident Response Plan did not start until July 23, 2026, about 80 days after the first bank warning when the city’s partnering bank said only $214,256.64 would be returned. That is when Lee was fully informed, according to the audit, and when he activated the plan. That timeline matches what Lee told council in August: He learned of the loss in late July.

The insurance number Hilty and Musleh asked for

After the partial bank recovery, the remaining hole was about $278,000. On July 24, 2026, the city’s HR Risk Manager filed a crime-insurance claim. The carrier paid $250,000.

Iovino’s official summary: Insurance reduced the remaining loss from $277,779.81 to $27,799.81.

That is the figure the August argument was waiting on. Musleh had said he wanted to know whether the claim would be paid and what the final loss would be before a full public accounting. The September 8, 2026 report answers that question.

What changed after the money was gone

The vendor-banking procedure (SOP 870) was updated in August 2026. Iovino recommended regular tabletop exercises so finance, procurement, IT, police, and the city’s bank can rehearse an EFT scam together and know when a real-time loss should trigger the Incident Response Plan, instead of a weeks-long wait.

Council will hear the report at its Sept. 15, 2026 city council meeting.

The vendor still has not been named. In Iovino’s report, as at the August meeting, it remains “the Vendor”: the company that was supposed to be paid, whose email was hijacked, and whose $492,056.44 went to the scammer until the bank and the insurer clawed most of it back.

The full report can be viewed here.