Supplier impersonation fraud — also called invoice redirection or payment diversion fraud — consists of posing as a regular supplier to hijack its payments: a message announces a "change of bank details", accounts payable updates the vendor record, and the next payment lands in the fraudster's account. The real supplier only notices when it chases the unpaid invoice, often weeks later. This guide is for whoever handles payments: recognise the attack, check the document you received, and above all follow the one procedure that defeats it.
The fraudster starts with reconnaissance: who your suppliers are, who processes invoices on your side, when payments fall due. Websites, tender notices, professional networks and, increasingly, a compromised mailbox at the supplier itself provide all of it.
Then comes the impersonation. In the simplest version the message comes from a look-alike domain — a doubled letter, .co instead of .com, an added hyphen. In the most dangerous version it comes from the supplier's real, hacked mailbox, as a reply inside a genuine thread: sender, history and signature are all authentic. Only the bank details are not.
The trigger is a mundane pretext: a change of bank, a merger, an accounting reorganisation, "following an audit". A bank details document is attached, sometimes an invoice. Then the pressure: a follow-up call, a close due date, a discount for fast payment. Fake IBAN fraud is the document side of this scenario; "CEO fraud", where the urgent transfer order comes from a supposed executive, is its cousin.
None of these proves fraud; any one of them is enough to trigger the verification described below.
The document is the only tangible thing you hold. Three checks take a few minutes:
No check of the document can establish who owns the account. Only one thing can: asking the supplier, through a channel the fraudster does not control.
Call a number you already had — the contract, an old invoice, the vendor record, the official website — never the one in the message or the one printed on the document you just received. Speak to someone you know, or failing that to the accounts department, and have them read the IBAN back. If the supplier's mailbox is compromised, this is also how they will find out.
Write the call-back into a procedure: every change of bank details is approved by two people after a logged phone confirmation, and the first payment to a new account waits for that approval whatever urgency is claimed. Urgency is the fraudster's tool; the procedure is yours.
Since 9 October 2025, banks in the euro area check that the payee name entered matches the IBAN holder before executing a transfer. That is an extra net, not a reason to skip the call: the fraudulent account is often opened under a name close to the supplier's, or in the name of a shell company.
Every hour counts: the funds are usually withdrawn or moved abroad within hours or days.
TrustyFile checks the document: IBAN check digits, consistency of company identifiers (SIRET, VAT), traces of editing, revisions, covered text. It catches the fabricated or altered bank-detail document, which is the most common case. It cannot know who owns a perfectly real account: that last link remains the phone call — and nothing replaces it.
Free IBAN checker: validates the mod-97 check digits, the expected length for the country and, for French IBANs, the RIB key. Everything runs in your browser.
Open the tool →
Free SIRET checker: validates the 14-digit French establishment number with the Luhn formula, including the special rule for La Poste establishments. Runs locally.
Open the tool →
Edited amounts, altered dates, swapped bank details: the technical evidence that gives away a tampered invoice PDF, and how to check for it.
Utility, telecom and internet bills used as proof of address: the technical checks that reveal an edited document, and when the checks simply cannot apply.
A PDF keeps a record of its successive saves: incremental revisions, ghost objects, two sets of metadata. Where to look to find out whether a file was edited.
The 2D-Doc barcode on tax notices, pay slips and official certificates: what it contains, what it actually proves, and why it is different from every other check.
Fake pay slips in rental files and loan applications: payroll software fingerprints, arithmetic checks and the French 2D-Doc barcode that expose an edited document.
Payment redirection fraud swaps the bank details on a genuine invoice. IBAN checksum, bank-code consistency and PDF tampering traces: how to check details received by email.
Check a Kbis against the public registers (SIREN, directors, registered office, company status), spot a forged PDF, and know what a genuine Kbis does not prove.
Landlord or agency: verify a tenant's French income-tax notice with the tax office's online service (SVAIR), the signed 2D-Doc code and the other documents in the file.
Checking a French subcontractor's attestation de vigilance: the 15-character security code on urssaf.fr, the six-month validity, and what the law requires of the client.
Analyse a document for free