The FBI said it managed to freeze the money after the email attack on four public corporations involving $4 million in remittances to Retirement
El Nuevo Día – 14 Feb 2020 – JOANISABEL GONZÁLEZ joanisabel.gonzalez@elnuevodia.com Twitter: @jgonzalezpr

The Industrial Development Company reported to the Police the alleged loss of some $2.6 million.
The Office of the Comptroller denounced that it has been detecting deficiencies in the management of government systems for years that are never corrected.
The email attack suffered by the Retirement Systems Administration (ASR) that could have resulted in the theft of over $4 million in public funds in at least four public corporations will not affect the payment of pensions.
However, it is the most recent proof that the government exhibits significant flaws in its systems or a lack of will and resources to correct them, a deficiency that the Office of the Comptroller of Puerto Rico (OCPR) has pointed out for years and that has cost the treasury millions of dollars.
Likewise, according to fraud expert and certified public accountant Eduardo González Green, this new incident in the government represents another blow to its credibility in managing the money it safeguards and that, in turn, to the perception that the island has as an administrator of federal funds, especially those expected from Washington for reconstruction after Hurricane María.
“To hear this again only causes anger,” Comptroller Yesmín Valdivieso told El Nuevo Día, noting that the OCPR has spent more than a decade detecting deficiencies in the management of the information systems used by agencies, public corporations and municipalities, as well as in the management of bank accounts that are never corrected.
“There have been cases of agencies where employees left 10 years ago and still have access to their accounts,” the official rebuked.
“I fear this is more frequent than is said in Puerto Rico because people do not want to share it,” González Green indicated, for his part, in reference to the cyberattack that would have affected the ASR. “And reputation, with one click is enough.”
SAFE: PENSIONS AND MONEY
In a written statement, the Secretary of Public Affairs, Osvaldo Soto García, and the administrator of the Retirement Systems Administration (ASR), Luis M. Collazo Rodríguez, assured that the situation will not affect the payments that ASR pensioners receive.
Meanwhile, the Federal Bureau of Investigation (FBI), through its spokesperson Limary Cruz Rubio, indicated that this federal agency managed to “freeze” the money that is alleged to have been transferred to a fraudulent account, but did not offer more information on the case.
“Yes, we can confirm it. The money in the affected accounts was frozen, minimizing the impact to the public treasury,” Cruz Rubio indicated.

The statements by Soto García, Collazo Rodríguez and the FBI came yesterday, a day after the Puerto Rico Police made public the filing of a complaint by the Industrial Development Company (Pridco) to report the alleged loss of some $2.6 million.
In addition to Pridco, according to the government, two other agencies under the umbrella of the Department of Economic Development and Commerce (DDEC) would also have fallen for the scheme: the Tourism Company, this past December, and the Trade and Export Company (CCE). The fourth public corporation harmed would have been the Highways and Transportation Authority (ACT). In the case of the CCE and the ACT, the government did not offer figures.
Yesterday, at 9:00 a.m., El Nuevo Día requested from the Police a copy of the complaints that would have been filed. As of press time, the requested information had not yet been provided.
“The reality is that this administration did not open the door to this office so that the best practices that are needed can be implemented”
YESMÍN VALDIVIESO, COMPTROLLER OF PUERTO RICO
THE GOVERNOR, THE BOARD AND THE FEDERAL FUNDS
“This is a scheme. We have seen this in other places. Not only in Puerto Rico. Here, I do not want to elaborate because it is part of the investigation, (but) they are people who impersonate and use logos, official emails… so they are people who are experts in ‘hacking’ accounts, government agencies. So it is all part of the investigation that the FBI has,” Governor Wanda Vázquez Garced indicated.
“The information we have is that the FBI, with the quick action of the Secretary of Economic Development, we were able to trace (find the path of) the money and it is very likely that we can recover all the money,” the chief executive added.
Faced with this picture and despite the police report that reports the theft in mid-January, Vázquez Garced indicated that the government learned of this fraudulent scheme this past Monday.
Meanwhile, Resident Commissioner Jennifer González admitted that the incident is more of the same for Puerto Rico.
“I would like to say no, but a transfer of this magnitude raises terrible shadows over the processes in Puerto Rico and the processes for the use of public funds,” González said. “It is a very large cloud that affects the credibility of the processes.”
“We are aware of the situation that occurred, but we cannot comment on an investigation that is ongoing,” said the spokesperson for the Fiscal Oversight Board (JSF), Edward Zayas, adding that the fiscal body “will continue monitoring the incident.”
As the news of the cyberattack gained strength in public discussion and on social networks and this intersected with the allocation of federal funds in Puerto Rico, JSF director Andrew Biggs said on his Twitter account and in a personal capacity “that Puerto Rico's path out of bankruptcy and toward prosperity would have been improved with a fiscal board that was closer to the control board in Washington, D.C., with stronger powers.”
SILENT INTRUDER
According to González Green, it is increasingly evident that cyber pirates have become more sophisticated and are leaving their mark in Puerto Rico.
He related that recently, one of his clients that buys raw materials outside the island -which requires sending payments through electronic transfers- was the victim of an attack.
He explained that the pirates entered the company's accounting system, specifically the accounts payable, and managed to replicate an invoice from one of the suppliers that was about to be delivered. The pirates made a telephone call and the company's personnel -upon seeing the alleged invoice in their system- understood that the payment was in order and it was made.
According to González Green, the payment made by the company reached an account at a recognized bank on the mainland, but from there it was transferred to a bank account in China, representing a loss for the client.
“We keep thinking that this only happens in movies,” González Green said.
According to the fraud expert, although what happened at the ASR remains to be determined, his firm recently completed the investigation of the theft of some $4.5 million from another company on the island and the situation was identified because the banking institution notified the company of an atypical movement in its accounts. The prompt response prevented the loss, González Green explained.
“That red flag is effective at banks, which are very active and that is good, but the best thing is for it not to happen,” González Green said.
In the case of the government, according to González Green, the obsolescence of the accounting systems and the fact that the systems do not communicate -which would allow a payroll transaction to be reflected in an accounting ledger, for example- make them more vulnerable to this type of attack.
LIST OF GROSS DEFICIENCIES
But, according to Comptroller Valdivieso, responding to an email with an instruction to change a bank account at a government agency, a decision that would entail the transfer of millions of dollars, is not so simple.
She explained that, generally, when such a decision is made at a government agency, it is usually accompanied by a letter or directive, communicated to the officials concerned and disclosed on the pages of the Office of Management and Budget, the ASR itself or the Department of Treasury.
The problem, according to Valdivieso and the director of Information Systems Audits of the OCPR, Ivonne Plumey, is the reluctance to comply with the guidelines for technology management, to update the guidelines that exist and in certain cases, the lack of resources to make it feasible.
And the same happens with bank account controls, the officials assured.
Examples abound both in the central government and in public corporations and municipalities: conducting official transactions from personal accounts, not limiting the access of a user with specific functions and even allowing the same employee to perform various finance functions that require separate controls.
Valdivieso maintained that there have been cases of cyberattacks in municipalities in which their accounts have been emptied. But because in one of these municipalities the account reconciliation process was frequent and quick action was taken with the FBI, the money was recovered.
Gloria Ruiz Kuilan, Paola Arroyo, Javier Colón Dávila and Alex Figueroa Cancel collaborated on this report.
“The important thing is that we can recover the smallest cent of Puerto Rico's public funds”
WANDA VÁZQUEZ GARCED, GOVERNOR
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.