Case Library / Phishing / Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020)
Phishing Confirmed

Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020)

A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled account.

Share:

Social Engineering Examples·5 sources

What Happened

On January 17, 2020, the Puerto Rico Industrial Development Company (PRIDCO), a government-owned economic-development corporation, wired more than $2.6 million to a fraudulent bank account after receiving an email claiming that the bank account used for remittance payments had changed and that funds should be sent to a new account. PRIDCO's finance director, Ruben Rivera, filed a complaint with Puerto Rico police (reported Wednesday, Feb 12, 2020), and executive director Manuel Laboy said the agency learned of the incident that week and reported it to the FBI.

Police (Jose Ayala, fraud unit of the bank robbery division) said the wider scam began in December 2019 when someone hacked into the computer of a female finance worker at Puerto Rico's Employee Retirement System, then impersonated her to email multiple agencies alleging bank-account changes. The two confirmed wire-loss victims were PRIDCO ($2.6M in January) and the Puerto Rico Tourism Company ($1.5M in January).

A separate $63,000 payment made in December is attributed inconsistently across AP's own reporting: the AP article citing Ayala attributes it to PRIDCO, while the AP article citing Laboy attributes it to a third implicated agency, the Puerto Rico Commerce and Export Company (Compania de Comercio y Exportacion). The scam attempted more than $4M in total; authorities reportedly froze at least $2.9M.

Puerto Rico's government said it suspended three employees for not following rigorous verification procedures: one at PRIDCO and two at the Commerce and Export Company. This is a well-documented, real incident reported by the Associated Press, The New York Times, and multiple outlets.

How the Attack Worked

This was a business email compromise (BEC) built on a legitimate-looking bank-account-change request. Because the initial email chain originated from a real, compromised government employee's computer and account, the messages carried the trust and context of a known internal sender rather than an obvious external spoof. The lure exploited a routine finance process (updating banking details for remittance and pension payments), so the request looked like normal administrative housekeeping rather than an attack.

Staff acted on the emailed instruction and changed the payee account without independently verifying the change through a trusted out-of-band channel. Officials later acknowledged that rigorous procedures were not followed, pointing to missing callback and dual-approval verification as the control gap that let a single forged instruction redirect a multimillion-dollar payment.

The Lure & the Tell

Lure: an email stating that the existing bank account for remittance and pension payments should no longer be used and that funds must go to a new account. Tells and red flags: any banking-detail change requested by email, the request routed money to a newly specified account on the U.S. mainland, and it relied on the recipient trusting a familiar sender without confirming the change by phone using a previously known number.

A verified callback to the real counterpart would have exposed the fraud before the wire.

Outcome

PRIDCO filed a police complaint and reported the loss to the FBI, which opened an investigation into how the Retirement System computer was compromised. Authorities reportedly froze at least $2.9 million of the targeted funds; full recovery was not publicly confirmed. Three government employees were suspended pending internal review (one at PRIDCO and two at the Commerce and Export Company), and Puerto Rico legislators demanded a probe amid the island's fiscal crisis.

Why It Matters

A single forged bank-change email cost a cash-strapped government $2.6M in one transfer, illustrating how remittance and vendor bank-change fraud can hit public-sector finance teams as hard as corporations. It underscores that email requests to alter payment banking details must trigger mandatory out-of-band verification, and that a compromised internal account can be used to launder trust across an entire government ecosystem.

Defenses

Require out-of-band verification (callback to a known, pre-established number) for any change to payee banking details, no exceptions. Enforce dual approval and a change-control workflow for vendor and remittance master-data updates. Treat emailed bank-change requests as high-risk regardless of sender familiarity, since accounts can be compromised. Deploy phishing-resistant MFA and endpoint protection to prevent finance-worker account takeover.

Train finance staff on BEC and bank-change fraud, and enable rapid FBI/IC3 reporting to improve the odds of freezing funds.

Sources
  • Official: Puerto Rico govt loses $2.6M in phishing scam. Associated Press Secondary. AP news wire (authoritative, first-party official quotes, but not a first-party government or court document) citing PRIDCO finance director Ruben Rivera's police complaint and executive director Manuel Laboy; core facts confirmed on fetch: $2.6M, Jan 17 transfer, remittance bank-change email, FBI reported.
  • Puerto Rico online scam targeted more than $4M amid crisis. Associated Press Secondary. AP news wire citing police fraud-unit director Jose Ayala; confirmed on fetch to detail the compromised Employee Retirement System computer, impersonation, and the two victims (PRIDCO and Tourism Company), explicitly stating PRIDCO sent $63,000 in December plus $2.6M+ in January while Tourism Company sent $1.5M in January to accounts on the U.S. mainland. NOTE: this article attributes the $63,000 December payment to PRIDCO, conflicting with the AP 'suspended' article below, which attributes it to the Commerce and Export Company.
  • 3 employees suspended in $4M Puerto Rico online scam. Associated Press Secondary. AP news wire, confirmed on fetch: PRIDCO's Laboy says rigorous procedures were not followed; three employees suspended (one at PRIDCO, two at the Commerce and Export Company, which per this article sent the $63,000). Directly conflicts with the AP Ayala article on the $63,000 attribution.
  • $2.6 Million for Puerto Rico's Pension Fund Went to Hackers Instead. The New York Times Secondary. Confirmed on fetch (partially paywalled preview plus search index text): corroborates victim, amount, forged-email method, and pension-fund destination of the money.
  • Puerto Rico Government Loses $2.6m in Phishing Scam. Infosecurity Magazine Secondary. Security-trade corroboration, confirmed live on fetch, describing the bank-change email lure and the fraudulent new account. No genuinely first-party or government document (the police complaint itself, an FBI or IC3 record, or a court filing) is publicly cited in any of these sources.
Cite this case

Social Engineering Examples. “Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020)”. Accessed 19 September 2026. https://socialengineeringexamples.com/pridco-bank-change-phishing-bec-2020

Attack Chain & Defense
1Reconnaissance
What happened

The attacker likely gathered information about which Puerto Rico government agencies relied on the Employee Retirement System as a finance intermediary for pension and remittance payments, consistent with the kind of OSINT (public budget documents, agency directories, prior correspondence) that would let an attacker identify a single finance mailbox whose compromise could reach multiple downstream agencies including PRIDCO and the Tourism Company.

The control that would have stopped it

The public and administrative record of which agencies route payments through which finance intermediaries is inherently hard to suppress; the realistic control is not hiding these relationships but hardening the payment-change process they get used against, which is addressed at Stage 5.

2Initial account compromise
What happened

Per police, someone hacked into the computer and email account of a finance worker at Puerto Rico's Employee Retirement System in December 2019, consistent with a phishing email or credential-theft technique, though the specific intrusion method was not publicly detailed.

The control that would have stopped it

Phishing-resistant multi-factor authentication, endpoint detection and response, and regular security-awareness training for finance staff reduce the odds that a single email account takeover succeeds and goes unnoticed for weeks.

3Pretext crafting
What happened

Using the compromised account's real inbox, contact list, and correspondence history, the attacker likely built or reused a bank-change notice that mimicked the Retirement System finance office's actual tone and addressed recipient agencies by name and role, making it read as routine administrative correspondence rather than fraud.

The control that would have stopped it

Because the pretext was built from inside a genuinely compromised, trusted account, message tone and sender familiarity cannot reliably distinguish it from a real request; the practical backstop is the same out-of-band verification requirement covered at Stage 5, applied regardless of how legitimate the email looks.

4Delivery
What happened

From the real, compromised Employee Retirement System email account, the attacker sent the forged bank-account-change email to multiple partner agencies, including PRIDCO and the Puerto Rico Tourism Company, trading on the recipients' trust in a known, legitimate sender rather than an obvious spoofed domain.

The control that would have stopped it

Email-authentication controls (DMARC, DKIM, SPF) and sending-pattern anomaly detection offer partial protection against spoofed domains, but they would not have flagged mail sent from a genuinely hacked, legitimate mailbox; the meaningful control again shifts downstream to Stage 5.

5Exploitation of process gap
What happened

Finance staff at the receiving agencies processed the bank-change instructions as routine housekeeping tied to pension remittances, updating payee account details without independently verifying the change through a trusted out-of-band channel such as a callback to a previously known phone number.

The control that would have stopped it

Require mandatory out-of-band verification, a callback to a previously known, independently sourced phone number, plus dual approval for any change to vendor or remittance payee banking details, with no exceptions, before any funds move.

6Fraudulent wire execution and payout
What happened

PRIDCO wired more than $2.6 million on January 17, 2020, and the Tourism Company separately wired $1.5 million that same month, to bank accounts on the U.S. mainland controlled by the attacker, completing the theft; a further $63,000 December payment (attributed inconsistently between PRIDCO and the Commerce and Export Company across sources) brought the total attempted take to over $4 million.

The control that would have stopped it

Rapid reporting to the bank, FBI, and IC3 can trigger transaction holds and account freezes after the fact, which is reportedly how at least $2.9 million was recovered here, but this is a last-resort mitigation that only works if the fraud is caught within hours to days, reinforcing why the Stage 5 control is the primary defense.

Quick Facts
Victim
Puerto Rico Industrial Development Company (PRIDCO), a government-owned corporation
Company
Puerto Rico Industrial Development Company
Location
San Juan, Puerto Rico (funds sent to fraudulent account on the U.S. mainland)
Date
2020-01-17
Impact
$2.6M wired by PRIDCO on Jan 17, 2020 (public pension remittance funds), the largest single loss in a broader scam that attempted more than $4M across Puerto Rico agencies.
The Puerto Rico Tourism Company separately wired $1.5M in January. A $63,000 December payment is attributed inconsistently by AP: one AP article (citing police fraud-unit director Jose Ayala) attributes it to PRIDCO, while another AP article (citing PRIDCO's Manuel Laboy) attributes it to the Commerce and Export Company; sources conflict, so it is not confirmed to be PRIDCO's. Authorities reportedly froze at least $2.9M. Net unrecovered loss not publicly confirmed.
Status
Confirmed
Case Type
Real-World Incident
Sector
Government & Public Sector
Explore more

Related Cases

Browse by what this case has in common with others in the library.