IBAN

substitution fraud

 

 

Tips for protecting your business from IBAN substitution fraud

IBAN substitution fraud poses a serious threat to financial security. Businesses and organisations that carry out a large number of banking transactions are particularly vulnerable.

 

Phishing email / SMS
Phishing email / SMS

Fraudulent messages that appear to come from a legitimate partner and contain a pre-substituted IBAN for payment.

Spoofing email / telephone
Spoofing email / telephone

Impersonation of a legitimate company or bank by email or telephone, requesting a change to the payee's IBAN.

Account takeover (BEC)
Account takeover (BEC)

Access to a genuine email account in order to monitor correspondence and send fraudulent payment instructions at just the right moment.

Social engineering
Social engineering

Impersonation of a trusted employee or partner, persuading you to change an IBAN because of a supposed "problem" with the bank account.

Fake invoices
Fake invoices

Documents that look identical to genuine ones but contain a substituted IBAN.

Malicious software
Malicious software

Trojans and viruses that swap the IBAN during a transaction.

Organisational safeguards

To protect your business, implement the following organisational practices in your company's workflows:

  • Staff training – Conduct regular security training sessions and keep them up to date with the latest threats. Train employees to recognise signs of fraud.
  • Dual transaction control – Implement a procedure requiring every significant transaction to be approved by more than one employee.
  • Verification through an independent channel – Confirm banking details with the recipient by phone before making a payment. Never rely solely on email.
  • Financial transaction policy – Develop a clear internal policy with specific verification and approval steps.
  • Reporting procedures – Establish procedures for immediately notifying the competent authorities of suspicious transactions.
  • Periodic data review – Regularly update your counterparties' banking details and maintain active communication with your banking partners.

 

Technical safeguards

Combine organisational measures with technical solutions for maximum protection of financial transactions:

  • Security software and firewalls – Install and maintain up-to-date antivirus software and firewalls to prevent unauthorised access to data.
  • Two-factor authentication – Implement 2FA for all financial transactions and access to sensitive financial data.
  • Transaction monitoring – Use systems that analyse anomalies and suspicious behaviour in real time.
  • Encrypted communications – Encrypt all financial data and emails to prevent interception and tampering.
  • Email security (DMARC/DKIM/SPF) – Implement technologies that protect against spoofing and phishing. Enable anti-spam and anti-malware filters.

Useful information