Case Library / Phishing / Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020)
Phishing Confirmed

Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020)

A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled account in January 2020.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On January 17, 2020, the Puerto Rico Industrial Development Company (PRIDCO), a government-owned economic-development corporation, wired more than $2.6 million to a fraudulent bank account after receiving an email claiming that the bank account used for remittance payments had changed and that funds should be sent to a new account. PRIDCO's finance director, Ruben Rivera, filed a complaint with Puerto Rico police (reported Wednesday, Feb 12, 2020), and executive director Manuel Laboy said the agency learned of the incident that week and reported it to the FBI. Police (Jose Ayala, fraud unit of the bank robbery division) said the wider scam began in December 2019 when someone hacked into the computer of a female finance worker at Puerto Rico's Employee Retirement System, then impersonated her to email multiple agencies alleging bank-account changes. The two confirmed wire-loss victims were PRIDCO ($2.6M in January) and the Puerto Rico Tourism Company ($1.5M in January). A separate $63,000 payment made in December is attributed inconsistently across AP's own reporting: the AP article citing Ayala attributes it to PRIDCO, while the AP article citing Laboy attributes it to a third implicated agency, the Puerto Rico Commerce and Export Company (Compania de Comercio y Exportacion). The scam attempted more than $4M in total; authorities reportedly froze at least $2.9M. Puerto Rico's government said it suspended three employees for not following rigorous verification procedures: one at PRIDCO and two at the Commerce and Export Company. This is a well-documented, real incident reported by the Associated Press, The New York Times, and multiple outlets.

How the Attack Worked

This was a business email compromise (BEC) built on a legitimate-looking bank-account-change request. Because the initial email chain originated from a real, compromised government employee's computer and account, the messages carried the trust and context of a known internal sender rather than an obvious external spoof. The lure exploited a routine finance process (updating banking details for remittance and pension payments), so the request looked like normal administrative housekeeping rather than an attack. Staff acted on the emailed instruction and changed the payee account without independently verifying the change through a trusted out-of-band channel. Officials later acknowledged that rigorous procedures were not followed, pointing to missing callback and dual-approval verification as the control gap that let a single forged instruction redirect a multimillion-dollar payment.

The Lure & the Tell

Lure: an email stating that the existing bank account for remittance and pension payments should no longer be used and that funds must go to a new account. Tells and red flags: any banking-detail change requested by email, the request routed money to a newly specified account on the U.S. mainland, and it relied on the recipient trusting a familiar sender without confirming the change by phone using a previously known number. A verified callback to the real counterpart would have exposed the fraud before the wire.

Outcome

PRIDCO filed a police complaint and reported the loss to the FBI, which opened an investigation into how the Retirement System computer was compromised. Authorities reportedly froze at least $2.9 million of the targeted funds; full recovery was not publicly confirmed. Three government employees were suspended pending internal review (one at PRIDCO and two at the Commerce and Export Company), and Puerto Rico legislators demanded a probe amid the island's fiscal crisis.

Why It Matters

A single forged bank-change email cost a cash-strapped government $2.6M in one transfer, illustrating how remittance and vendor bank-change fraud can hit public-sector finance teams as hard as corporations. It underscores that email requests to alter payment banking details must trigger mandatory out-of-band verification, and that a compromised internal account can be used to launder trust across an entire government ecosystem.

Defenses

Require out-of-band verification (callback to a known, pre-established number) for any change to payee banking details, no exceptions. Enforce dual approval and a change-control workflow for vendor and remittance master-data updates. Treat emailed bank-change requests as high-risk regardless of sender familiarity, since accounts can be compromised. Deploy phishing-resistant MFA and endpoint protection to prevent finance-worker account takeover. Train finance staff on BEC and bank-change fraud, and enable rapid FBI/IC3 reporting to improve the odds of freezing funds.

Sources
  • Official: Puerto Rico govt loses $2.6M in phishing scam. Associated Press Secondary. AP news wire (authoritative, first-party official quotes, but not a first-party government or court document) citing PRIDCO finance director Ruben Rivera's police complaint and executive director Manuel Laboy; core facts confirmed on fetch: $2.6M, Jan 17 transfer, remittance bank-change email, FBI reported.
  • Puerto Rico online scam targeted more than $4M amid crisis. Associated Press Secondary. AP news wire citing police fraud-unit director Jose Ayala; confirmed on fetch to detail the compromised Employee Retirement System computer, impersonation, and the two victims (PRIDCO and Tourism Company), explicitly stating PRIDCO sent $63,000 in December plus $2.6M+ in January while Tourism Company sent $1.5M in January to accounts on the U.S. mainland. NOTE: this article attributes the $63,000 December payment to PRIDCO, conflicting with the AP 'suspended' article below, which attributes it to the Commerce and Export Company.
  • 3 employees suspended in $4M Puerto Rico online scam. Associated Press Secondary. AP news wire, confirmed on fetch: PRIDCO's Laboy says rigorous procedures were not followed; three employees suspended (one at PRIDCO, two at the Commerce and Export Company, which per this article sent the $63,000). Directly conflicts with the AP Ayala article on the $63,000 attribution.
  • $2.6 Million for Puerto Rico's Pension Fund Went to Hackers Instead. The New York Times Secondary. Confirmed on fetch (partially paywalled preview plus search index text): corroborates victim, amount, forged-email method, and pension-fund destination of the money.
  • Puerto Rico Government Loses $2.6m in Phishing Scam. Infosecurity Magazine Secondary. Security-trade corroboration, confirmed live on fetch, describing the bank-change email lure and the fraudulent new account. No genuinely first-party or government document (the police complaint itself, an FBI or IC3 record, or a court filing) is publicly cited in any of these sources.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: The attacker likely gathered information about which Puerto Rico government agencies relied on the Employee Retirement System as a finance intermediary for pension and remittance payments, consistent with the kind of OSINT (public budget documents, agency directories, prior correspondence) that would let an attacker identify a single finance mailbox whose compromise could reach multiple downstream agencies including PRIDCO and the Tourism Company.
Countering Stage 1: The public and administrative record of which agencies route payments through which finance intermediaries is inherently hard to suppress; the realistic control is not hiding these relationships but hardening the payment-change process they get used against, which is addressed at Stage 5.
2
Initial account compromise: Per police, someone hacked into the computer and email account of a finance worker at Puerto Rico's Employee Retirement System in December 2019, consistent with a phishing email or credential-theft technique, though the specific intrusion method was not publicly detailed.
Countering Stage 2: Phishing-resistant multi-factor authentication, endpoint detection and response, and regular security-awareness training for finance staff reduce the odds that a single email account takeover succeeds and goes unnoticed for weeks.
3
Pretext crafting: Using the compromised account's real inbox, contact list, and correspondence history, the attacker likely built or reused a bank-change notice that mimicked the Retirement System finance office's actual tone and addressed recipient agencies by name and role, making it read as routine administrative correspondence rather than fraud.
Countering Stage 3: Because the pretext was built from inside a genuinely compromised, trusted account, message tone and sender familiarity cannot reliably distinguish it from a real request; the practical backstop is the same out-of-band verification requirement covered at Stage 5, applied regardless of how legitimate the email looks.
4
Delivery: From the real, compromised Employee Retirement System email account, the attacker sent the forged bank-account-change email to multiple partner agencies, including PRIDCO and the Puerto Rico Tourism Company, trading on the recipients' trust in a known, legitimate sender rather than an obvious spoofed domain.
Countering Stage 4: Email-authentication controls (DMARC, DKIM, SPF) and sending-pattern anomaly detection offer partial protection against spoofed domains, but they would not have flagged mail sent from a genuinely hacked, legitimate mailbox; the meaningful control again shifts downstream to Stage 5.
5
Exploitation of process gap: Finance staff at the receiving agencies processed the bank-change instructions as routine housekeeping tied to pension remittances, updating payee account details without independently verifying the change through a trusted out-of-band channel such as a callback to a previously known phone number.
Countering Stage 5: Require mandatory out-of-band verification, a callback to a previously known, independently sourced phone number, plus dual approval for any change to vendor or remittance payee banking details, with no exceptions, before any funds move.
6
Fraudulent wire execution and payout: PRIDCO wired more than $2.6 million on January 17, 2020, and the Tourism Company separately wired $1.5 million that same month, to bank accounts on the U.S. mainland controlled by the attacker, completing the theft; a further $63,000 December payment (attributed inconsistently between PRIDCO and the Commerce and Export Company across sources) brought the total attempted take to over $4 million.
Countering Stage 6: Rapid reporting to the bank, FBI, and IC3 can trigger transaction holds and account freezes after the fact, which is reportedly how at least $2.9 million was recovered here, but this is a last-resort mitigation that only works if the fraud is caught within hours to days, reinforcing why the Stage 5 control is the primary defense.
Quick Facts
Victim
Puerto Rico Industrial Development Company (PRIDCO), a government-owned corporation
Location
San Juan, Puerto Rico (funds sent to fraudulent account on the U.S. mainland)
Date
2020-01-17
Impact
$2.6M wired by PRIDCO on Jan 17, 2020 (public pension remittance funds), the largest single loss in a broader scam that attempted more than $4M across Puerto Rico agencies. The Puerto Rico Tourism Company separately wired $1.5M in January. A $63,000 December payment is attributed inconsistently by AP: one AP article (citing police fraud-unit director Jose Ayala) attributes it to PRIDCO, while another AP article (citing PRIDCO's Manuel Laboy) attributes it to the Commerce and Export Company; sources conflict, so it is not confirmed to be PRIDCO's. Authorities reportedly froze at least $2.9M. Net unrecovered loss not publicly confirmed.
Status
Confirmed
Case Type
Real-World Incident
Sector
Government & Public Sector
Related

Related Cases

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money…

Incident 2020Read →

Toyota Boshoku European Subsidiary $37M BEC (2019)

A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…

Incident 2019Read →

Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township

A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into…

Incident 2021Read →