A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled account.
Social Engineering Examples·5 sources
On January 17, 2020, the Puerto Rico Industrial Development Company (PRIDCO), a government-owned economic-development corporation, wired more than $2.6 million to a fraudulent bank account after receiving an email claiming that the bank account used for remittance payments had changed and that funds should be sent to a new account. PRIDCO's finance director, Ruben Rivera, filed a complaint with Puerto Rico police (reported Wednesday, Feb 12, 2020), and executive director Manuel Laboy said the agency learned of the incident that week and reported it to the FBI.
Police (Jose Ayala, fraud unit of the bank robbery division) said the wider scam began in December 2019 when someone hacked into the computer of a female finance worker at Puerto Rico's Employee Retirement System, then impersonated her to email multiple agencies alleging bank-account changes. The two confirmed wire-loss victims were PRIDCO ($2.6M in January) and the Puerto Rico Tourism Company ($1.5M in January).
A separate $63,000 payment made in December is attributed inconsistently across AP's own reporting: the AP article citing Ayala attributes it to PRIDCO, while the AP article citing Laboy attributes it to a third implicated agency, the Puerto Rico Commerce and Export Company (Compania de Comercio y Exportacion). The scam attempted more than $4M in total; authorities reportedly froze at least $2.9M.
Puerto Rico's government said it suspended three employees for not following rigorous verification procedures: one at PRIDCO and two at the Commerce and Export Company. This is a well-documented, real incident reported by the Associated Press, The New York Times, and multiple outlets.
This was a business email compromise (BEC) built on a legitimate-looking bank-account-change request. Because the initial email chain originated from a real, compromised government employee's computer and account, the messages carried the trust and context of a known internal sender rather than an obvious external spoof. The lure exploited a routine finance process (updating banking details for remittance and pension payments), so the request looked like normal administrative housekeeping rather than an attack.
Staff acted on the emailed instruction and changed the payee account without independently verifying the change through a trusted out-of-band channel. Officials later acknowledged that rigorous procedures were not followed, pointing to missing callback and dual-approval verification as the control gap that let a single forged instruction redirect a multimillion-dollar payment.
Lure: an email stating that the existing bank account for remittance and pension payments should no longer be used and that funds must go to a new account. Tells and red flags: any banking-detail change requested by email, the request routed money to a newly specified account on the U.S. mainland, and it relied on the recipient trusting a familiar sender without confirming the change by phone using a previously known number.
A verified callback to the real counterpart would have exposed the fraud before the wire.
PRIDCO filed a police complaint and reported the loss to the FBI, which opened an investigation into how the Retirement System computer was compromised. Authorities reportedly froze at least $2.9 million of the targeted funds; full recovery was not publicly confirmed. Three government employees were suspended pending internal review (one at PRIDCO and two at the Commerce and Export Company), and Puerto Rico legislators demanded a probe amid the island's fiscal crisis.
A single forged bank-change email cost a cash-strapped government $2.6M in one transfer, illustrating how remittance and vendor bank-change fraud can hit public-sector finance teams as hard as corporations. It underscores that email requests to alter payment banking details must trigger mandatory out-of-band verification, and that a compromised internal account can be used to launder trust across an entire government ecosystem.
Require out-of-band verification (callback to a known, pre-established number) for any change to payee banking details, no exceptions. Enforce dual approval and a change-control workflow for vendor and remittance master-data updates. Treat emailed bank-change requests as high-risk regardless of sender familiarity, since accounts can be compromised. Deploy phishing-resistant MFA and endpoint protection to prevent finance-worker account takeover.
Train finance staff on BEC and bank-change fraud, and enable rapid FBI/IC3 reporting to improve the odds of freezing funds.
Social Engineering Examples. “Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020)”. Accessed 19 September 2026. https://socialengineeringexamples.com/pridco-bank-change-phishing-bec-2020
The attacker likely gathered information about which Puerto Rico government agencies relied on the Employee Retirement System as a finance intermediary for pension and remittance payments, consistent with the kind of OSINT (public budget documents, agency directories, prior correspondence) that would let an attacker identify a single finance mailbox whose compromise could reach multiple downstream agencies including PRIDCO and the Tourism Company.
The public and administrative record of which agencies route payments through which finance intermediaries is inherently hard to suppress; the realistic control is not hiding these relationships but hardening the payment-change process they get used against, which is addressed at Stage 5.
Per police, someone hacked into the computer and email account of a finance worker at Puerto Rico's Employee Retirement System in December 2019, consistent with a phishing email or credential-theft technique, though the specific intrusion method was not publicly detailed.
Phishing-resistant multi-factor authentication, endpoint detection and response, and regular security-awareness training for finance staff reduce the odds that a single email account takeover succeeds and goes unnoticed for weeks.
Using the compromised account's real inbox, contact list, and correspondence history, the attacker likely built or reused a bank-change notice that mimicked the Retirement System finance office's actual tone and addressed recipient agencies by name and role, making it read as routine administrative correspondence rather than fraud.
Because the pretext was built from inside a genuinely compromised, trusted account, message tone and sender familiarity cannot reliably distinguish it from a real request; the practical backstop is the same out-of-band verification requirement covered at Stage 5, applied regardless of how legitimate the email looks.
From the real, compromised Employee Retirement System email account, the attacker sent the forged bank-account-change email to multiple partner agencies, including PRIDCO and the Puerto Rico Tourism Company, trading on the recipients' trust in a known, legitimate sender rather than an obvious spoofed domain.
Email-authentication controls (DMARC, DKIM, SPF) and sending-pattern anomaly detection offer partial protection against spoofed domains, but they would not have flagged mail sent from a genuinely hacked, legitimate mailbox; the meaningful control again shifts downstream to Stage 5.
Finance staff at the receiving agencies processed the bank-change instructions as routine housekeeping tied to pension remittances, updating payee account details without independently verifying the change through a trusted out-of-band channel such as a callback to a previously known phone number.
Require mandatory out-of-band verification, a callback to a previously known, independently sourced phone number, plus dual approval for any change to vendor or remittance payee banking details, with no exceptions, before any funds move.
PRIDCO wired more than $2.6 million on January 17, 2020, and the Tourism Company separately wired $1.5 million that same month, to bank accounts on the U.S. mainland controlled by the attacker, completing the theft; a further $63,000 December payment (attributed inconsistently between PRIDCO and the Commerce and Export Company across sources) brought the total attempted take to over $4 million.
Rapid reporting to the bank, FBI, and IC3 can trigger transaction holds and account freezes after the fact, which is reportedly how at least $2.9 million was recovered here, but this is a last-resort mitigation that only works if the fraud is caught within hours to days, reinforcing why the Stage 5 control is the primary defense.
Browse by what this case has in common with others in the library.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
Operation Buckshot Yankee: a malware-laden USB drive plugged into a U.S. military laptop in 2008 spread the agent.btz worm onto…
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
Impersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.
A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders.
The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…
Treasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China.
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
A compromised Constant Contact account let Russia-linked Nobelium send USAID-spoofed phishing emails to 150-350 government and NGO organizations.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.