A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled account in January 2020.
Reviewed by the Social Engineering Examples team.
On January 17, 2020, the Puerto Rico Industrial Development Company (PRIDCO), a government-owned economic-development corporation, wired more than $2.6 million to a fraudulent bank account after receiving an email claiming that the bank account used for remittance payments had changed and that funds should be sent to a new account. PRIDCO's finance director, Ruben Rivera, filed a complaint with Puerto Rico police (reported Wednesday, Feb 12, 2020), and executive director Manuel Laboy said the agency learned of the incident that week and reported it to the FBI. Police (Jose Ayala, fraud unit of the bank robbery division) said the wider scam began in December 2019 when someone hacked into the computer of a female finance worker at Puerto Rico's Employee Retirement System, then impersonated her to email multiple agencies alleging bank-account changes. The two confirmed wire-loss victims were PRIDCO ($2.6M in January) and the Puerto Rico Tourism Company ($1.5M in January). A separate $63,000 payment made in December is attributed inconsistently across AP's own reporting: the AP article citing Ayala attributes it to PRIDCO, while the AP article citing Laboy attributes it to a third implicated agency, the Puerto Rico Commerce and Export Company (Compania de Comercio y Exportacion). The scam attempted more than $4M in total; authorities reportedly froze at least $2.9M. Puerto Rico's government said it suspended three employees for not following rigorous verification procedures: one at PRIDCO and two at the Commerce and Export Company. This is a well-documented, real incident reported by the Associated Press, The New York Times, and multiple outlets.
This was a business email compromise (BEC) built on a legitimate-looking bank-account-change request. Because the initial email chain originated from a real, compromised government employee's computer and account, the messages carried the trust and context of a known internal sender rather than an obvious external spoof. The lure exploited a routine finance process (updating banking details for remittance and pension payments), so the request looked like normal administrative housekeeping rather than an attack. Staff acted on the emailed instruction and changed the payee account without independently verifying the change through a trusted out-of-band channel. Officials later acknowledged that rigorous procedures were not followed, pointing to missing callback and dual-approval verification as the control gap that let a single forged instruction redirect a multimillion-dollar payment.
Lure: an email stating that the existing bank account for remittance and pension payments should no longer be used and that funds must go to a new account. Tells and red flags: any banking-detail change requested by email, the request routed money to a newly specified account on the U.S. mainland, and it relied on the recipient trusting a familiar sender without confirming the change by phone using a previously known number. A verified callback to the real counterpart would have exposed the fraud before the wire.
PRIDCO filed a police complaint and reported the loss to the FBI, which opened an investigation into how the Retirement System computer was compromised. Authorities reportedly froze at least $2.9 million of the targeted funds; full recovery was not publicly confirmed. Three government employees were suspended pending internal review (one at PRIDCO and two at the Commerce and Export Company), and Puerto Rico legislators demanded a probe amid the island's fiscal crisis.
A single forged bank-change email cost a cash-strapped government $2.6M in one transfer, illustrating how remittance and vendor bank-change fraud can hit public-sector finance teams as hard as corporations. It underscores that email requests to alter payment banking details must trigger mandatory out-of-band verification, and that a compromised internal account can be used to launder trust across an entire government ecosystem.
Require out-of-band verification (callback to a known, pre-established number) for any change to payee banking details, no exceptions. Enforce dual approval and a change-control workflow for vendor and remittance master-data updates. Treat emailed bank-change requests as high-risk regardless of sender familiarity, since accounts can be compromised. Deploy phishing-resistant MFA and endpoint protection to prevent finance-worker account takeover. Train finance staff on BEC and bank-change fraud, and enable rapid FBI/IC3 reporting to improve the odds of freezing funds.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money…
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…
A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into…