He paid the craftsman’s invoice using the RIB received by email, at the very end of the project, just to settle the work before the new term began. A few days later, his bank informed him that the transfer had already been sent and that no automatic refund was planned. It didn’t matter whether the amount was 800 euros or 15,000: the bank’s response does not vary with the sum, only with the sending circumstances.
- Cybercriminals intercept invoices by email and replace the supplier’s RIB with their own, creating documents that look perfectly credible.
- An immediate phone call to the supplier on their usual number is enough to detect the fraud before the transfer is authorized.
- After a fraudulent transfer, the bank may refuse reimbursement by invoking the client’s responsibility, with no guarantee of recovering funds.
- The victim remains obliged to pay the real supplier even after paying money to a crook, creating a double dispute.
The mechanism of a fraud targeting individuals and artisans
The technique rests on intercepting or impersonating an exchange already in progress between a client and their supplier.
A cybercriminal intercepts an invoice in transit by email, discreetly replaces the real supplier’s RIB with their own, and waits for the victim to trigger the transfer. The document bears the correct logo, the right file number, sometimes even the correct amount to the exact euro. Only the bank account details have changed, tucked into an attachment that appears perfectly legitimate. And once the instruction is validated, a transfer sent to a fraudulent supplier RIB is legally a authorized operation when the company or individual themselves approved the instruction to the indicated account.
Artisans and small businesses stand on the front lines of this threat, both as targets and as indirect victims when a client pays into the wrong account. An artisan with three employees and two large projects per year fits the profile: five-figure invoices, no accounting department, no internal controls. The scale of the phenomenon is staggering: in the first half of 2025, the total amount of fraudulent transfers in France reached about 618 million euros, up 7% from 2024, for nearly 3.7 million fraudulent transactions.
Signals to alert before authorizing the payment
A detail almost always betrays the maneuver.
A change in bank details announced by email is the one signal that does not lie: no matter how well the message is written or whether it references the correct file, an email-driven change of RIB must always be verified. In addition, there are other cues that the victim rarely notices at the moment: a slightly different email address from the supplier’s usual one, an unusual or urgent tone in the payment request, or a justification such as an internal audit or a banking migration to explain the change. Taken in isolation these elements may seem harmless. Combined, they form the typical portrait of a scam in preparation.
The protective reflex is a single, simple action, almost too simple to think of under pressure: pick up the phone. You must call immediately the interlocutor using their usual number, the one saved in your contacts, never the number provided in the suspicious message. This verification takes two minutes.
Once the transfer has gone: what the bank can, or cannot, do
The first reflex is to alert the institution without delay.
You should contact the bank immediately to report the fraud, because funds can sometimes be frozen before they are transferred to the scammers’ account. At the same time, file a complaint with the appropriate authorities, whether police, gendarmerie or national cybersecurity services, and report the incident on the official cybermalveillance.gouv.fr platform. But nothing guarantees a favorable outcome or a precise processing time: each file hinges on its own circumstances—the timing of the report, the recipient bank, the nature of the anomaly. The bank’s response thus largely depends on how the payment order was issued and the victim’s responsiveness.
This is where the law becomes more complex than it seems. If the victim validated the transfer based on a scam involving a fake RIB, the bank may refuse reimbursement by citing the victim’s responsibility. Banks often invoke “gross negligence” on the part of the victim to refuse reimbursement, even though this criterion is increasingly challenged in court, which tends to recognize that the sophistication of modern scams cannot be equated with victim negligence. The outcome therefore depends on prevailing jurisprudence, the contract between the client and the bank, and the way the transfer was initiated.
One last trap remains, often neglected in the panic of reporting: the debt to the supplier has not disappeared.
A payment made in good faith to a fraudulent IBAN does not discharge the debtor: the debtor remains obliged to pay the rightful creditor. The fake RIB fraud thus frequently creates a second dispute, the real supplier still demanding payment, because a transfer to the crook does not automatically extinguish the obligation to the legitimate creditor. The Court of Cassation has ruled on the notion of an apparent creditor: a crook who usurps a supplier’s identity is not considered an “apparent creditor,” which rejects the argument that paying “in good faith” would discharge the obligation.
In the face of an artisan who sends their invoice by email, the only action that truly costs something is a thirty-second call on a number already known. Everything else—account contracts, internal procedures, case law—merely serves to limit the damage once the transfer has already left.
Sources: cybersecurite-management.fr | kohenavocats.com | lesclesdelabanque.com