The City of Monterey said this week that fraudsters are posing as its planning staff and demanding bogus permit fees — using real project addresses, case details and officials' names lifted straight from the public agendas the city is legally obligated to post.

The notice drops a Central Coast city into a scheme the FBI labeled a nationwide problem back in March, and one that has swept across Northern California this year. What makes it hard to stop isn't clever hacking — it's that the raw material is open-government transparency itself. California's Brown Act and public-records rules require cities and counties to publish planning-commission agendas, staff reports, property addresses and case numbers. Fraudsters simply read them, then email applicants a convincing invoice.

In a statement this week, Monterey officials said residents, property owners and contractors are getting emails that quote real details about actual development projects — architectural review permits, addresses, zoning specifics — and falsely claim a permit is cleared for final approval, pending an "application approval fee."

The messages arrive from lookalike addresses that are not city domains. One example the city flagged was planning.montereyca.gov@usa.com — close enough to read as official at a glance, but a consumer webmail domain, not the city's.

Assistant City Manager Nat Rojanasathira called it "a highly sophisticated scam" in the city's statement, saying the accuracy of the stolen project details is precisely what makes the fraud convincing. He stressed that genuine city payment requests only ever come from an @monterey.org or @monterey.gov address, and that the city would never route a payment or a receipt through a reply to an outside, non-government inbox.

The tell is the domain. The believability is the public record.

Monterey is not being singled out. On March 9, the FBI's Internet Crime Complaint Center issued a national public service announcement (external source, opens in a new tab) about criminals posing as municipal planning officials, with victims identified across the country. The bureau's write-up reads like a blueprint for the Monterey emails: notes that cite a target's real property address, case numbers and the true names of local officials, sent from usernames that echo a planning department but resolve to non-government domains like "@usa.com."

The FBI also flagged a tactic engineered to keep victims from checking: the fake invoices tell applicants to request payment instructions by email rather than phone — steering them away from a quick call that would expose the ruse. Money is demanded by wire transfer, peer-to-peer apps or cryptocurrency, and the messages lean on urgency, threatening permit delays.

The scheme has been circling the region for more than a year. The County of Monterey (external source, opens in a new tab) — a separate government from the city — warned repeatedly in 2025 that fake invoices were reaching Planning Commission applicants, describing bogus demands that ran into five figures, including one topping $14,000 and a later counterfeit invoice for $5,000. This year the same pattern surfaced up and down the map: Sonoma County's permitting agency posted its own national-alert notice (external source, opens in a new tab), Marin County towns like Corte Madera (external source, opens in a new tab) issued community alerts, Mountain View and Merced County warned applicants, and cities as far off as Minneapolis (external source, opens in a new tab) put up near-identical notices.

The through-line is that none of these governments can just stop publishing the information the scammers exploit. Planning agendas and staff reports are public by design and by law — the same transparency that lets neighbors track a project down the block is what lets a fraudster in another time zone write a credible fee demand.

That leaves verification as the only real defense. Monterey is urging anyone who gets a suspicious payment request not to reply or send money, to confirm the sender's address ends in @monterey.gov or @monterey.org, and to run anything questionable past its Planning Division at planning@monterey.gov. The FBI's guidance is blunter: don't trust letterhead, seals or names, and call the government office using the number on its official website — not any number or reply address in the email — before paying a cent.