The Guardia Civil, through its Cyber Command, has solved a suspected cyber fraud case committed against a business in the province of Alicante. The scam used a technique known as ‘business email compromise’ (BEC). Investigators managed to track down the alleged perpetrator behind the fraud, who successfully diverted the payroll payment of a female employee by spoofing her email address.
The incident began when the human resources department received a series of emails that one of the firm’s employees had apparently sent. The messages requested an update to the bank account details where her wages were normally paid. According to the force, the messages were drafted in a highly convincing manner and included real personal information belonging to the staff member, making it exceptionally difficult for the payroll team to spot the impersonation.
Believing the request was genuine and came directly from the employee, the company completed a transfer of 2,000 euro to the new account number provided in the emails. Shortly afterwards, staff contacted the worker directly to verify the change, only to discover she had neither asked to update her banking details nor sent any emails to human resources.
Realising they had fallen victim to identity fraud and that the funds had been sent to a fraudulent account, the company submitted an official report via the Guardia Civil online portal. Upon receiving the notification, the specialised Cyber Command team immediately requested a block on the transferred funds. Specialist officers then conducted a detailed analysis of the electronic communications, traced the movement of the money, and examined the banking operations involved.
Through these actions, officers successfully identified the account holder and established their involvement in receiving and handling the stolen funds. The suspect is now being investigated for fraud, and the case proceedings have been forwarded to the relevant court in Malaga.
