ArticlesAccounting and VAT

Fake IBAN change: the fraud that targets your accounts

An invoice you already received arrives again, identical to the original, with a different IBAN. The message replies to a real email thread and the amount is right. The payment lands in a fraudster’s account. Here is how to spot it and what to do if it is too late.

Topic
Accounting and VAT
Published on
Reading time
3 min

How it works

It starts with a hacked business email account, often your supplier’s. The attacker looks for invoices that were sent, copies one, swaps the IBAN for their own and sends it again to the customer in the issuer’s name. Any excuse will do: “we have changed banks”.

Because the message slots into a real conversation, nothing looks wrong. The National Cyber Security Centre (NCSC) calls this business email compromise.

The QR code proves nothing

In January 2023, the NCSC described a case where the fraudsters had changed the IBAN and adapted the invoice’s QR code. The destination account was Swiss, which made the fraud hard to spot. A QR-bill contains whatever its author put in it: it does not prove that the author is your supplier.

Why it is more convincing in 2026

In its review of the first half of 2026, the NCSC notes that attackers use artificial intelligence to carry out increasingly personalised attacks. It also reports many phishing cases around Microsoft 365 that let attackers take over business email accounts. The spelling mistakes that used to give a fake message away are no longer a reliable sign.

Warning signs

  • A change of account announced by email, even in the middle of a usual exchange.
  • An invoice you already received that comes back with one single difference: the bank details.
  • A request to pay quickly, in a tone that discourages checking.
  • An account holder whose name does not exactly match the supplier’s.

The rule that stops almost everything

A new IBAN is confirmed by phone, on the number you already know. Never by replying to the email, never on the number it gives. That is exactly what the NCSC recommends.

Two additions make it solid:

  • a written rule for payments: any change of bank details is approved by a second person;
  • two-factor authentication on every email account in the business, so that a stolen password is not enough.

If you have already paid

  1. 01Call your bank immediately: it may still be able to stop the transfer.
  2. 02Report it to your local police. Suisse ePolice shows the nearest station.
  3. 03Warn the supplier: their email account has probably been hacked.
  4. 04Report the case to the NCSC with its online form. It can pass IBANs used for fraud on to law enforcement.

If your own email account was used, change the passwords and have your IT environment analysed. Check the forwarding rules too: attackers often create one to receive a copy of every email. Finally, warn your customers that they may receive fake invoices in your name.

Protect your customers too

One sentence on your invoices and contracts defuses many attempts: “Our bank details never change by email. If in doubt, call us.” A customer who has been warned checks before paying.

What Qompta does

Qompta sends nothing over the internet. Your invoices are exported as PDF with their QR-bill and you send them yourself. The original stays encrypted on your computer: if a customer doubts an invoice received in your name, you can compare the IBAN and the amount with the version you actually issued.

Read next

A question about your project?

Write to us: we answer in writing, with a scope and an estimate.

Write to us