Spanish police arrested four suspects and broke up a cybercrime ring that laundered €140 million ($160 million) through investment fraud and business email compromise attacks.
What happened
Spanish Police dismantled a cybercrime and money-laundering organization that generated €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. Officers arrested four people in Spain, Portugal, and Panama. Investigators describe the scheme as industrial level, since it involved at least 800 bank accounts, 120 business accounts, and 67 external accomplices who acted as "money mules." Police traced €94 million ($107 million) through the network and linked another €61 million ($69.5 million) to the group, tying it specifically to BEC operations that took place in 2024.
Going deeper
Investigators launched the case after the police detected signs of money laundering in 19 companies linked to it. Once they identified the main suspects, police organized an international operation with support from Interpol and Europol. Officers then raided six premises in Barcelona, Girona, and Tarragona, as well as in the city of Porto in Portugal, and arrested another suspect in Panama. The two suspects arrested outside Spain left the country recently but continued to operate from their foreign bases in support of the cybercrime scheme. During the raids, agents seized 15 computers and over 170 smartphones, believed to have been used for executing thousands of fraudulent transfers.
What was said
Police describe the network's structure directly, stating, "The suspects created and managed a network of more than 800 bank accounts into which they received large amounts of illicit money defrauded from numerous victims."
They also explained how the money moved once it entered the system, "The funds were immediately dispersed and concealed through another network of bank accounts, creating chains of transactions that placed the criminal proceeds beyond reach and allowed the enormous amounts of stolen money to be hidden and laundered through available mule bank accounts in third countries."
Police also labeled the fraud tactics used against businesses, calling them "CEO fraud" and "false-invoice fraud," indicating the use of social engineering tactics, like impersonating high-ranking executives and diverting payments to bank accounts controlled by the fraudsters.
By the numbers
- €140 million ($160 million) generated through investment fraud and BEC attacks.
- 800+ bank accounts, 120 business accounts, and 67 money mules involved.
- €94 million ($107 million) directly traced through the network, plus €61 million ($69.5 million) linked to 2024 BEC operations.
- 15 computers and 170+ smartphones seized.
- €3 million ($3.4 million) in crime proceeds frozen and set to be returned to victims.
Why it matters
This case shows how BEC fraud has scaled from isolated incidents into full financial infrastructure, and US healthcare organizations have already experienced these types of attacks. In 2022, the Justice Department charged 10 defendants in a coordinated BEC and money-laundering operation that targeted Medicare, state Medicaid programs, private health insurers, and numerous other victims, resulting in more than $11.1 million in total losses.
In that scheme, fraudulent emails from accounts resembling those associated with actual hospitals were sent to public and private health insurance programs requesting that future reimbursements be sent to new bank accounts that did not belong to the hospitals, deceiving five state Medicaid programs, two Medicare Administrative Contractors, and two private health insurers into sending hospital reimbursements straight into accounts the fraudsters controlled. The proceeds were then laundered through shell companies and false identities, the same layering technique Spanish police describe dismantling.
That earlier case, and this new one, both point to a system-level risk that BEC doesn't need to breach a hospital's network to hurt patients. It only needs one convincing email changing payment instructions on a reimbursement that was already legitimately owed. That's consistent with what current data shows domestically, the FBI's 2025 IC3 Annual Report found that BEC generated about $3 billion in reported losses across all industries. When reimbursement funds are diverted for weeks or months before detection, that's money hospitals can't use for staffing, supplies, or care delivery.
The bottom line
Police say the Spanish network is now dismantled and its main operators are in custody, but the €3 million frozen so far is a small fraction of the €140 million the ring is accused of laundering. For US healthcare organizations, the 2022 Medicare and Medicaid case is a reminder that this isn't just a European problem, hospitals and insurers here have already been targeted by nearly identical tactics. Verifying any request to change payment or banking details, especially reimbursement instructions tied to Medicare, Medicaid, or private insurers, is an effective defense against losses that can affect patient care.
Learn more: Understanding the criminal network behind BEC attacks
FAQs
What is business email compromise (BEC)?
BEC is a scam where criminals impersonate a trusted contact, such as an executive or vendor, through spoofed or hijacked email accounts to trick victims into sending money or sensitive data.
How is BEC different from phishing?
BEC typically skips malicious links or attachments, relying instead on convincing impersonation and social engineering to make a fraudulent request look like routine business.
What is a 'money mule'?
A money mule is a person who allows their bank account to be used to receive and move fraudulent funds, often unknowingly, helping criminals distance stolen money from its source.
