[Spain] Warning after business email compromise scam diverted employee’s salary

[Spain] Warning after business email compromise scam diverted employee’s salary
10 Sep 2026

In Spain, the Guardia Civil has identified a suspect connected to a business email compromise scam that targeted a company in Alicante Province and has reminded businesses of the importance of verification and cybersecurity training for employees, The Leader reports.

The fraud originated with emails to the company’s HR department, apparently sent by an employee. The messages asked that her salary be paid into a different bank account.

The emails reportedly contained genuine personal information and appeared convincing, making the fraud more challenging for payroll staff to detect. Believing this was a legitimate request, the company transferred €2,000 to the account provided.

The cyber breach came to light when the company contacted the employee directly. The business reported the fraud using the Guardia Civil’s online reporting service. Cybercrime investigators immediately requested a freeze on the transferred funds.

After analysing the emails, investigators traced the movement of the money and examined the banking activity associated with the receiving account. Officers’ inquiries identified the account holder and allegedly established their involvement in receiving and accessing the stolen money.

The suspect was placed under investigation for alleged fraud, and the case has been referred to the appropriate court in Málaga.

The Guardia Civil reportedly urged businesses to independently verify requests to change bank details. It added that companies should be cautious of urgent emails or demands for confidentiality, carefully examine sender addresses and establish internal verification procedures before authorising transfers. It also advised regular cybersecurity training for employees.

Online reports of cyber-enabled fraud and other offences can be submitted securely through the Guardia Civil’s electronic headquarters and its Cyber Command service, which operates 24 hours a day.


Source: The Leader

 

In Spain, the Guardia Civil has identified a suspect connected to a business email compromise scam that targeted a company in Alicante Province and has reminded businesses of the importance of verification and cybersecurity training for employees, The Leader reports.

The fraud originated with emails to the company’s HR department, apparently sent by an employee. The messages asked that her salary be paid into a different bank account.

The emails reportedly contained genuine personal information and appeared convincing, making the fraud more challenging for payroll staff to detect. Believing this was a legitimate request, the company transferred €2,000 to the account provided.

The cyber breach came to light when the company contacted the employee directly. The business reported the fraud using the Guardia Civil’s online reporting service. Cybercrime investigators immediately requested a freeze on the transferred funds.

After analysing the emails, investigators traced the movement of the money and examined the banking activity associated with the receiving account. Officers’ inquiries identified the account holder and allegedly established their involvement in receiving and accessing the stolen money.

The suspect was placed under investigation for alleged fraud, and the case has been referred to the appropriate court in Málaga.

The Guardia Civil reportedly urged businesses to independently verify requests to change bank details. It added that companies should be cautious of urgent emails or demands for confidentiality, carefully examine sender addresses and establish internal verification procedures before authorising transfers. It also advised regular cybersecurity training for employees.

Online reports of cyber-enabled fraud and other offences can be submitted securely through the Guardia Civil’s electronic headquarters and its Cyber Command service, which operates 24 hours a day.


Source: The Leader

 

Leave a Reply

All blog comments are checked prior to publishing