A finance employee receives an urgent message from the CEO. A supplier announces new banking details. A bank representative tells a customer to move money to a “safe account.” Because the communication appears genuine, the victim completes the transfer.
The bank may correctly authenticate its customer while the customer is following instructions from an impersonator.
How Much Payment Fraud Occurs in Europe?
Payment service providers reported the following fraud across the European Economic Area:
| Year | Reported payment fraud |
|---|---|
| 2022 | €3.4 billion |
| 2023 | €3.5 billion |
| 2024 | €4.2 billion |
In 2024, payment service users ultimately bore approximately 85% of fraudulent credit-transfer losses. The European Central Bank and European Banking Authority connected much of this exposure to scams that manipulated victims into initiating transfers themselves.
Source: Joint ECB–EBA report on payment fraud.
These figures cover payment fraud reported by providers in the EEA, including the European Union, Iceland, Liechtenstein and Norway. They do not represent every fraudulent website, investment scam, identity theft, fake invoice or unreported loss across Europe.
What Is Authorised Push Payment Fraud?
Authorised push payment fraud, or APP fraud, happens when a criminal deceives a person or business into approving a bank transfer to an account controlled by the criminal. The genuine account holder completes the payment using valid credentials, so the transaction may initially appear legitimate to the bank.
Common examples include:
- CEO impersonation
- Fake vendor banking changes
- Invoice fraud
- Bank impersonation
- Investment scams
- Relationship scams
- Property-payment diversion
- Fake legal or financial advisers
APP fraud is different from an unauthorized payment. The victim’s account is not necessarily accessed illegally; the victim is manipulated into sending the money.
What Is CEO Fraud?
CEO fraud is a business email compromise scam in which a criminal impersonates a senior executive and pressures an employee to transfer money or disclose sensitive information. The request typically relies on urgency, authority and secrecy to discourage the employee from following normal verification procedures.
A fake executive may claim that the payment relates to:
- A confidential acquisition
- An urgent legal settlement
- A regulatory or tax matter
- A sensitive supplier payment
- A transaction that colleagues must not know about
- An emergency requiring normal controls to be bypassed
The employee is placed in a difficult position: questioning the instruction may appear to mean disobeying an executive or violating confidentiality.
Case study
How Did Pathé Netherlands Lose €19.2 Million to CEO Fraud?
In 2018, criminals impersonated senior leaders at Pathé, the French cinema company, and contacted executives at its Dutch subsidiary.
The messages described a confidential acquisition in Dubai and appeared to come from the company’s chief executive. The alleged transaction was presented as highly sensitive, discouraging the recipients from consulting colleagues through normal internal channels.
Pathé Netherlands transferred approximately €19.2 million through a series of payments before discovering the deception. Details of the incident later emerged through Dutch court proceedings involving former executives of the subsidiary.
Sources: Pathé Netherlands CEO-fraud case and Europol guidance on scams targeting employees.
What weakness did the Pathé scammers exploit?
The recipients needed to determine whether Pathé’s real leadership had authorized the transaction. Instead, they relied on communications that displayed the correct executive identity and included credible corporate context.
The demand for secrecy also prevented the most useful verification step: asking another authorized person to confirm the transaction.
No malware was required. The criminals turned executive authority and confidentiality into attack tools.
What can businesses learn from the Pathé fraud?
An extraordinary payment should require extraordinary verification, especially when the sender demands urgency or secrecy.
A secure process would require:
- Confirmation through a previously approved channel
- Authorization from more than one decision-maker
- Verification outside the original conversation
- A documented exception process
- A temporary hold when the request cannot be independently confirmed
Confidentiality should never eliminate financial controls.
Case study
How Did a European CEO-Fraud Network Steal Almost €38 Million?
Europol reported that a Franco-Israeli criminal network impersonated company leaders and persuaded employees to transfer almost €38 million within several days.
The criminals used an established money-laundering network to move the proceeds through accounts in the European Union, China and Israel.
This speed made recovery more difficult. By the time a victim recognized the deception, the money could already have been divided and transferred through multiple financial institutions and jurisdictions.
Source: Europol investigation into the €38 million CEO-fraud network.
Why did the banking system accept the transfers?
The employees authenticated themselves correctly and initiated the payments through legitimate banking systems.
The payment system verified who sent the money. It did not verify the identity of the person who persuaded the employees to send it.
This distinction explains why stronger payment authentication cannot independently prevent every impersonation scam.
What Is a Fake Vendor Email Scam?
A fake vendor email scam occurs when a criminal impersonates a trusted supplier and requests payment to a fraudulent bank account. The scammer may send a replacement invoice, announce new banking information or enter an existing email conversation after compromising a genuine supplier account.
The invoice itself may represent a real debt. The criminal changes only the account receiving the payment.
Warning signs can include:
- Unexpected changes to a supplier’s IBAN
- Requests from a slightly altered email domain
- Pressure to process an invoice immediately
- New contact details included in the request
- A destination account in an unexpected country
- Attempts to bypass established approval procedures
The absence of these signs does not prove that a request is genuine.
How Can a Business Verify New Vendor Banking Details?
A change to a supplier’s bank account should be treated as a high-risk request, even when the email and invoice appear professional.
Before updating payment information:
- Do not use the telephone number or link supplied in the request.
- Contact the vendor through details already stored in company records.
- Speak with an authorized vendor representative.
- Confirm the new IBAN and legal account name.
- Require approval from a second employee.
- Document who requested, verified and approved the change.
- Delay the payment if independent confirmation is unavailable.
Replying to the same email thread is not independent verification. A criminal may already control the supplier’s genuine mailbox.
Who Is Most Frequently Targeted by European Payment Scams?
Impersonation scams target people who can move money, alter financial records or approve sensitive decisions.
Common targets include:
- Finance and accounts-payable employees
- Procurement teams
- Employees permitted to change supplier information
- Executives with payment authority
- Small and medium-sized businesses
- E-commerce merchants
- Consumers receiving fake bank messages
- Property buyers and sellers
- Investors
- Victims of relationship scams
In ENISA’s financial-sector incident sample, phishing campaigns targeting individuals represented 38% of observed social-engineering incidents. Credit institutions were the impersonated organizations in 36% of those incidents.
Sources: ENISA financial-sector threat landscape and Europol Internet Organised Crime Threat Assessment.
How Is AI Changing Fraud and Impersonation Scams?
AI-assisted impersonation uses generated text, cloned voices, synthetic images or manipulated video to imitate trusted people and organizations. It allows criminals to personalize scams quickly, operate across multiple languages and remove many of the errors that once made fraudulent communications easier to recognize.
Generative AI can produce:
- Personalized phishing emails
- Copies of an executive’s writing style
- Cloned voices
- Synthetic identity documents
- Fake professional profiles
- Realistic photographs and videos
- Automated conversations with multiple victims
European authorities do not currently publish a reliable estimate of how much payment fraud is AI-generated. Victims may never discover whether AI helped create the communication.
The measurable risk extends beyond deepfakes. Correct grammar, consistent branding and natural speech are becoming less useful as signs of authenticity.
Can a Deepfake CEO Scam Be Detected Reliably?
Deepfake detection may identify signs that audio or video was artificially generated, but its output is generally an assessment—not proof of identity.
Generation technology also continues to improve. Businesses should therefore verify whether an authorized executive approved the request rather than relying entirely on whether the voice, image or video appears authentic.
What Is Europe Doing to Prevent Payment Fraud?
European institutions and businesses use several controls to prevent unauthorized payments and detect suspicious transfers.
Does Strong Customer Authentication Stop Payment Scams?
Strong Customer Authentication requires customers to verify many electronic payments using at least two independent authentication factors. It reduces certain unauthorized transactions, but it may not stop a scam when the real customer is deceived into approving the transfer.
In an APP scam, the authentication system may work correctly. It confirms the payer’s identity but not the identity of the person who requested the payment.
What Is Verification of Payee?
Verification of Payee compares the recipient name entered by the payer with the name connected to the destination IBAN. It helps identify mismatches before a euro credit transfer, but it does not verify the email, call or message that instructed the customer to make the payment.
The result may indicate:
- Match
- Close match
- No match
- Another status preventing a conclusive comparison
Source: ECB explanation of Verification of Payee.
A criminal may also register an account or legal entity using a deceptively similar name. A successful name-and-IBAN match establishes that the details correspond; it does not prove that the recipient is the company the victim intended to pay.
Do employee training and dual approval prevent fraud?
Employee training, payment limits, callbacks and dual approval reduce risk when followed consistently.
Their effectiveness can decline when a criminal uses urgency, executive authority or confidentiality to convince employees that normal procedures do not apply. Prevention therefore depends on controls being mandatory and embedded in the payment workflow.
Why Are Existing Payment-Fraud Controls Incomplete?
Current controls answer several important questions:
- Did the genuine customer approve the payment?
- Does the payee name correspond with the IBAN?
- Does the transaction resemble previous activity?
- Did the payment receive the required internal approval?
They may not answer the question that arises before the transaction:
Did the instruction genuinely come from the executive, supplier, adviser or institution it claimed to represent?
A payment can be correctly authenticated and sent to an account whose name matches the entered details while still resulting from impersonation.
How Can European Businesses Prevent CEO and Invoice Fraud?
Effective fraud prevention combines account security, payment controls and independent identity verification.
Protect business accounts
Use multifactor authentication, access monitoring, suspicious-login alerts and controls against unauthorized mailbox-forwarding rules.
Verify requests outside the original conversation
Contact the executive or supplier through an approved channel already held in company records.
Require multiple approvals
High-value transfers, new beneficiaries and bank-account changes should require more than one authorized decision-maker.
Treat secrecy as a risk signal
Confidential transactions still need documented approval. No executive should be able to eliminate financial controls through an email request.
Verify changes before entering them
Accounts-payable teams should confirm supplier banking changes before updating internal records—not only before releasing the eventual payment.
Verify authority, not appearance
A familiar name, logo, writing style, voice or face does not prove who is behind a communication.
What Should a Business Do After Sending Money to a Scammer?
Immediately contact the bank or payment provider and request a recall, freeze or fraud investigation. Preserve the emails, headers, invoices, telephone numbers, IBANs and transaction records. Report the incident to national law enforcement and the appropriate cybercrime or financial-fraud authority.
Businesses should also:
- Stop any pending payments connected to the request.
- Notify affected suppliers or customers.
- Secure potentially compromised accounts.
- Review forwarding rules and active login sessions.
- Preserve evidence before deleting or modifying messages.
- Determine whether personal data was exposed.
- Assess whether notification obligations apply under the GDPR or national law.
Recovery becomes more difficult once the funds pass through additional accounts or jurisdictions.
How Could Verified Digital Identity Reduce Payment Fraud?
Most fraud controls protect the payment account, analyze the transaction or train the person making the decision. A communication-verification layer addresses a different question:
Can the request be connected to the accountable person or organization it claims to represent?
Such a system could allow organizations to register:
- Legal identities
- Official domains and communication channels
- Authorized departments
- Approved representatives
- Permitted business purposes
- Payment-change procedures
- People authorized to approve sensitive requests
Recipients could verify those details before changing an IBAN, sending money or disclosing information.
For high-risk actions, confirming the communication channel would not be sufficient. The specific request would also need independent authorization.
How Does Gemisis Complement European Payment Controls?
Gemisis is building a verification and traceability layer for digital communications.
Organizations register their legal identities, authorized representatives, departments and official communication channels. When a recipient receives a supported email, call or message, Gemisis is intended to check whether the interaction corresponds with the claimed organization’s registered information.
For a sensitive payment request, the verification process could establish whether:
- The claimed organization is legally identifiable.
- The channel belongs to that organization.
- The sender is authorized to make the request.
- The particular instruction received the necessary approval.
- The recipient’s name corresponds with the destination account.
Verification of Payee checks the beneficiary information at the payment stage. Gemisis is intended to address the identity and authority behind the communication that caused the payment.
It would complement—not replace—Strong Customer Authentication, Verification of Payee, internal payment controls, bank monitoring and law enforcement.
What If a Scammer Compromises a Real Email Account?
A registered email address establishes that the account belongs to an organization. It does not prove that its authorized owner is currently controlling it.
If a criminal compromises a supplier’s genuine mailbox, the email may pass domain authentication and appear to originate from an approved channel. Sender verification alone could create false confidence.
Bank-account changes, acquisitions and high-value transfers therefore need request-level authorization through a separate trusted process. The approval must be connected to an authorized person, device and workflow—not merely a familiar email account.
Frequently Asked Questions
How much payment fraud occurred in Europe in 2024?
Payment service providers reported €4.2 billion in payment fraud across the European Economic Area in 2024, compared with €3.5 billion in 2023.
What is the difference between CEO fraud and APP fraud?
CEO fraud describes the impersonation method: a criminal pretends to be a senior executive. Authorised push payment fraud describes the transaction: the deceived victim personally approves a transfer to the criminal.
Does Strong Customer Authentication prevent APP fraud?
Strong Customer Authentication helps prevent unauthorized payments made with stolen credentials. It may not stop an authorized customer who has been deceived into transferring money to a scammer.
What does Verification of Payee check?
Verification of Payee compares the recipient name entered by the payer with the name associated with the destination IBAN. It does not authenticate the email, phone call or message that requested the transfer.
What is IBAN fraud?
IBAN fraud occurs when a criminal substitutes fraudulent bank-account details in an invoice or payment request. The victim believes they are paying a legitimate supplier, property seller or professional adviser but sends the money to an account controlled by the criminal.
How should a company confirm an invoice payment?
The company should verify unexpected invoices or bank-account changes through a trusted contact method already stored in its records. The confirmation should occur outside the original email conversation and involve an authorized supplier representative.