
BEC in LatAm: when the "CEO" email costs $200,000
Spanish-language Business Email Compromise works because payment processes trust email. Controls that save accounts payable in real SMBs.
FBI IC3 reports BEC losses in billions; in Puerto Rico we see cases where a vendor "changes" bank account by email and accounting pays a real invoice to a fake account. Krebs on Security has profiled groups studying LinkedIn and financials before writing flawless Spanish.
Not mass phishing — targeted fraud
Not mass phishing — targeted fraud. Attacker compromises mailbox or spoofs similar domain, waits for real large payment threads, inserts new instructions. MFA on email reduces mailbox compromise; it does not prevent fooled users if process is weak.
Process controls > filters: whitelist of vendor bank account
Process controls > filters: whitelist of vendor bank accounts verified in person, dual approval above threshold ($10k, $25k — define per cash flow), ban changing payment data by email only, callback to phone on file. Train accounting with real local examples (anonymized).
Technically: DMARC reject, "EXTERNAL" banner on mail, detection of hidden forward rules in M365/Google, alerts when inbox rules are created. Monitor typosquatting domains of your brand — registering common variants costs little vs reputation.
If fraud occurs: contact bank immediately (ACH/wire recall window is short), report IC3, preserve email headers, involve legal before internal accusations. BEC is crime; emotional response without process worsens recovery.

Operations and execution — connecting strategy with what the team ships every week.


