Discovering that we have made a bank transfer after receiving a fake email impersonating one of our suppliers requires swift action. In this type of fraud, the first few hours can be decisive in trying to trace and recover the money before the funds are sent to other accounts.
At Barcelona Penal, we are lawyers specialising in Criminal Law and have experience advising companies and individuals on scams, economic offences and fraud committed through technological means. One of the most significant attacks in the business sphere is known as BEC fraud, short for Business Email Compromise.
The problem is that we do not always receive an obviously fraudulent email. Criminals may know of a genuine invoice, the outstanding amount, the names of those involved and even the contents of previous conversations. Therefore, once the money has been sent, we must coordinate banking action, preservation of evidence and the criminal strategy from the outset.
Quick answer: if we have made a transfer to a fraudulent account after receiving an email impersonating our supplier, we must notify the bank immediately, ask it to activate the available procedures to try to recover the funds, confirm the IBAN change through an independent channel, retain the original email and all documentation, and prepare a criminal complaint as soon as possible. Recovery is not automatic and will depend, among other factors, on where the money is, how the transaction was authorised, and the banking and judicial steps that can be taken.
What is BEC fraud or supplier impersonation fraud?
BEC fraud is a form of cybercrime in which perpetrators manipulate business communications to make us send a payment to an account other than the genuine one.
If you have transferred money after receiving a fake supplier email, every hour matters. Contact our criminal lawyers now and we will explain the immediate steps to take to try to recover the funds and protect your rights.
One of the most common methods involves impersonating a supplier with whom there is a genuine business relationship and notifying us of an alleged change of bank account just before we are due to pay an invoice.
How they make the email look genuine
Perpetrators may register an address almost identical to the supplier's or, in more sophisticated attacks, gain unlawful access to a genuine email account.
If they have accessed communications, they may know about outstanding invoices, dates, amounts, finance staff and even the tone normally used between the two companies.
At the right moment, we receive an apparently normal email providing a new IBAN for the payment. We make the transfer believing we are paying the supplier, but the money ends up in an account directly or indirectly controlled by the criminals.
Why BEC fraud can be difficult to detect
Unlike a generic phishing email, a well-prepared BEC attack may contain no spelling mistakes, obvious threats or suspicious links.
In our experience, we must pay particular attention when the message contains information that only the parties should know. A genuine invoice, an exact amount or the continuation of a real conversation may indicate that this is not simply a lookalike domain, but that one of the email accounts may have been compromised.
This distinction is important both for the criminal investigation and for determining which security measures and additional obligations need to be examined.
What to do urgently if we have already sent the money
When we discover that the transfer has ended up in a fraudulent account, we do not recommend waiting until all documentation is ready. Banking procedures must begin immediately while we preserve the evidence and prepare the remaining steps.
Step 1: contact our bank immediately
We must notify the bank that we made a transfer as a result of fraud and ask it to urgently activate the available mechanisms to try to recover the funds.
In practice, we can ask our bank to contact the receiving bank and initiate the relevant recovery procedure or recall.
However, we must avoid a misconception: requesting recovery does not mean that we are automatically entitled to cancel a transfer that has already been executed.
Spanish payment services legislation establishes certain duties of cooperation and reasonable efforts to try to recover funds where an incorrect unique identifier has been used. For this reason, we recommend reporting the fraud immediately and also keeping a written record of our request.
Step 2: contact our genuine supplier
At the same time, we must speak to the supplier through a channel we know to be genuine. For example, we can use the telephone number already held in our records.
We do not recommend verifying the change using only the telephone number included in the email notifying the new IBAN.
This check enables us to confirm the fraud and begin determining whether the criminals merely used a false domain or whether an email account may have been compromised.
Step 3: retain the original email and all evidence
We must preserve the fraudulent email, previous conversations, invoices, transfer confirmations, the receiving IBAN and subsequent communications with the bank and supplier.
Where possible, we also recommend retaining the message in .eml format or equivalent. This format can retain full headers and other technical information that does not appear in a simple screenshot.
Screenshots remain useful, but we do not recommend relying on them as the only digital evidence we retain.
Step 4: prepare a sufficiently documented criminal complaint
After activating the initial banking procedures, we must prepare the criminal complaint.
In Barcelona, we can report the matter to the Mossos d'Esquadra as well as to other competent police forces. Depending on the circumstances, action before the relevant court may also be considered.
In our experience, a complaint concerning BEC fraud should not be limited to stating that we have been scammed. It is advisable to provide a clear chronology, identify the emails and domains used, attach the invoice and proof of payment, and provide all information available about the receiving account.
When the financial loss is substantial, we consider it particularly useful to prepare documentation from the outset that enables a rapid understanding of how the deception occurred and the initial path of the money.
Step 5: also consider assistance from INCIBE
The National Cybersecurity Institute (INCIBE) operates the 017 Cybersecurity Helpline and provides guidance to companies and professionals as well.
INCIBE has specifically documented BEC fraud cases involving invoices and fraudulent changes to bank accounts. Its support does not replace our criminal complaint or legal strategy, but it may be useful for managing certain technical aspects of the incident.
How to try to recover money from a fraudulent transfer
There is no mechanism that guarantees the return of the money on its own. We recommend examining the banking and criminal routes simultaneously.
Bank recovery must be attempted immediately
Our bank can contact the receiving bank and take steps aimed at trying to recover the funds.
Article 59 of Royal Decree-Law 19/2018 provides that, where an incorrect unique identifier has been provided, the payer's payment service provider must make reasonable efforts to recover the money and the payee's provider must cooperate in those efforts.
This does not mean that every transfer can be unilaterally reversed. We must therefore distinguish between the procedure to try to recover the funds and an alleged automatic right to reimbursement.
What happens if the bank cannot recover the money?
Article 59 itself contains a particularly relevant provision that many victims are unaware of.
Where it is not possible to recover the funds through the procedures provided for, our bank must provide us, upon written request, with the relevant information it holds so that we can bring legal action to recover the money.
From our perspective, this is another reason not to limit contact with the bank to a simple telephone call. We recommend retaining documentary evidence of all requests and responses.
When the money has already been moved, the criminal route becomes more important
Criminals may withdraw the funds or quickly transfer them to further accounts. At that point, the issue is no longer limited to recovering the money from the first receiving account.
The investigation may require identifying account holders, requesting bank transaction records and reconstructing the path taken by the funds.
In our experience, one mistake to avoid is waiting several days while relying solely on the bank to resolve the situation. Banking and criminal action should be coordinated from the outset when the scale of the fraud warrants it.
Can a bank be liable in BEC fraud?
One of the first questions we usually ask after the fraud is whether the bank must bear the loss.
We do not recommend giving an automatic answer. We need to know exactly how the transfer was made and what information the payer received before confirming it.
A transfer authorised through deception is not the same as an unauthorised transaction
We must distinguish between a transfer made without our consent and a transaction that we ourselves authorised because a third party deceived us.
This distinction has important consequences when analysing the liability regime for payment institutions.
Spanish Supreme Court Judgment 1733/2025 examined precisely an email containing a fraudulent IBAN
There is recent case law of particular interest for these cases.
Spanish Supreme Court Judgment 1733/2025 of 27 November examined a case in which a company made two transfers to the IBAN stated in an email sent by a third party impersonating the genuine supplier.
Taking account of the applicable legislation and the circumstances of that transaction, the Supreme Court concluded that the receiving institution which had executed the transfer in accordance with the provided IBAN was not liable for failing additionally to check whether the beneficiary's name matched the account holder's name.
For us, this ruling offers an important lesson: we cannot assume that a mere difference between the supplier's name and the IBAN account holder automatically makes the bank liable.
However, we must also bear one essential fact in mind: the transfers examined in that judgment were made in 2019. The regulatory environment for current transfers has changed.
Verification of payee changes the analysis from October 2025
Since 9 October 2025, payment service providers must offer the so-called verification of payee free of charge for euro transfers.
Before executing the transaction, the system checks whether the name we enter as beneficiary corresponds with the account holder associated with the IBAN.
The result may indicate a match, a close match, no match or that verification cannot be carried out.
This change is particularly relevant when examining a BEC fraud occurring in 2026. We must review what result was displayed before approving the transfer, what warning we received and whether the transaction proceeded despite a discrepancy.
We believe this element will become increasingly important in claims relating to fraudulent IBAN changes. It does not automatically make the bank liable, but neither can we now analyse a transfer as though this verification system did not exist.
How to assess whether the supplier email was fake
Investigating the email can help us demonstrate how the impersonation occurred and, in certain cases, identify whether an account was compromised.
We must review the sender's full domain
A difference of a single letter can easily go unnoticed. Criminals may replace visually similar characters, add hyphens, use subdomains or register different extensions.
We therefore recommend comparing the suspicious address with previous genuine emails and not only with the name visually displayed as the sender.
Technical headers may provide relevant information
Email headers contain information about the message's route and certain authentication mechanisms, including SPF, DKIM and DMARC.
These elements may be useful for a technical assessment. However, we do not recommend concluding that a message is genuine or fraudulent based solely on one of these checks being positive or negative.
We must assess the domain, headers, message content, previous conversations and all other available evidence together.
Knowing about a genuine invoice can be particularly significant
If the purported supplier knows exactly about an outstanding invoice, an amount, a description or a conversation that was not public, we must investigate how that information was obtained.
The supplier's account, our own account or another system through which the criminals accessed documentation may have been compromised.
This circumstance can significantly change the focus of the investigation.
What offences may arise in BEC fraud?
Not all BEC frauds need to receive precisely the same criminal classification. We analyse how the financial loss was caused and what computer-related actions were undertaken before determining which offences may apply.
Fraud by deception under Article 248 of the Criminal Code
Article 248 of the Criminal Code currently regulates fraud committed by a person who, acting for profit, uses sufficient deception to cause another person to make an error and induce them to carry out an act of disposal of assets to their own or another's detriment.
This classification may be particularly relevant where we ourselves voluntarily order the transfer because we believe we are following our supplier's genuine instructions.
The basic offence carries a sentence of six months to three years' imprisonment, without prejudice to any aggravating circumstances that may apply.
Computer fraud offences under Article 249
We must take account of an important amendment in relation to much of the older legal content available online.
Fraud offences involving certain computer manipulations are now contained in Article 249 of the Criminal Code, rather than the former Article 248.2.
Among other situations, Article 249 covers the use of interference, data alterations or other computer manipulations or similar devices to obtain an unauthorised transfer of assets.
For this reason, we do not recommend automatically labelling every BEC case as “computer fraud”. We must first establish how the fraud materially occurred.
Frauds exceeding €50,000 may be aggravated
We must also assess the circumstances set out in Article 250 of the Criminal Code.
Among other circumstances, the law provides for an aggravated offence where the value of the fraud exceeds €50,000. There are also other aggravating criteria that must be considered according to the case.
In business BEC frauds involving substantial sums, we consider it especially important to analyse from the outset the potential application of these aggravated offences.
Unauthorised access to computer systems
If the perpetrators actually gained access to an email account by circumventing security measures, we must also examine the potential application of Article 197 bis of the Criminal Code.
We must not confuse this situation with merely creating a similar address. Unauthorised access may explain how criminals came to know private conversations, documents and internal company information.
Money laundering and money mules
After receiving the funds, perpetrators may use intermediary accounts or so-called money mules to move them.
However, we must not assume that every subsequent movement automatically constitutes money laundering.
To assess the potential application of Article 301 of the Criminal Code, we must examine the specific conduct of each participant and their knowledge of the criminal origin of the money.
What happens if the funds are sent abroad?
The fact that the first fraudulent account is outside Spain does not mean we should abandon the investigation.
Becoming the victim of supplier impersonation fraud is more common than you think, and there are legal solutions. At Barcelona Penal, we provide specialist advice to file the right complaint and act as a private prosecutor with every safeguard.
Indeed, cross-border movement of money is a frequent feature of this type of offence.
There are judicial cooperation mechanisms within the European Union
Where the investigation affects another Member State, European instruments exist to obtain information, carry out investigative measures and adopt certain criminal cooperation measures.
The specific tool will depend on what needs to be investigated or secured at each stage.
Outside the European Union, the specific country must be assessed
Where the funds end up in countries outside the European Union, we must review the applicable judicial assistance treaties and mechanisms.
For this reason, it is particularly useful to have the IBAN, the bank's name, the receiving country, the amount and the exact transaction date from the outset.
Money mules may be the investigation's first point of contact
The first receiving account does not always belong to the person behind the fraud.
It may belong to an intermediary used to receive and forward the money. Identifying that person and understanding the subsequent transactions may be relevant to reconstructing the chain followed by the funds.
When we recommend acting as a private prosecutor
Filing a complaint brings the facts to the authorities' attention, but where we are victims of significant financial loss, we can also consider joining the proceedings as a private prosecutor.
Private prosecution enables us to participate actively
Joining the proceedings enables us to take part in them on the terms provided by law, access the case file, request investigative measures, appeal certain decisions and bring an accusation where appropriate.
We can also bring the civil action arising from the offence to claim compensation for the losses suffered.
In complex cases, we recommend considering joining the proceedings during the investigation stage
Where substantial sums, several accounts, international movements or complex technological operations are involved, we consider it advisable to assess joining the proceedings from the earliest stages.
This enables us to follow the progress of the proceedings and assess which further measures may be useful to identify those responsible or trace the funds.
What obligations may our company have if there has been a data breach?
Where BEC fraud has involved unauthorised access to a corporate email account, we must also assess whether a personal data breach has occurred.
Not every BEC fraud necessarily involves a breach, and not every breach must automatically be notified to the Spanish Data Protection Agency.
When we must notify the AEPD
Article 33 of the GDPR requires a breach to be notified to the supervisory authority where it is likely to result in a risk to the rights and freedoms of natural persons.
Where that obligation exists, we must make the notification without undue delay and, where possible, within 72 hours of becoming aware of the breach.
We must also document breaches internally, even where not all of them ultimately need to be notified.
When we must notify the affected individuals
Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, we must also assess the obligation to notify them of the incident without undue delay.
In our experience, where a corporate email account has been compromised, we must coordinate the criminal investigation with IT and data protection analysis. Resolving the transfer alone may leave other significant risks to the company unmanaged.
How we can reduce the risk of further BEC fraud
Once the incident has been managed, we must review why the deception bypassed our controls and what changes we can introduce.
We must not accept an IBAN change solely by email
This is probably the most important practical recommendation.
When a supplier notifies us of a new account number, we must verify it through an independent channel using contact details we already know.
An apparently genuine email should not by itself be enough to change a supplier's bank details.
We must pay attention to verification of payee
We must now also always review the check our bank performs between the beneficiary's name and the IBAN account holder.
If we receive a warning that the details do not match, our recommendation is to stop the transfer until the account has been confirmed directly with the supplier.
Multi-factor authentication and email security
We recommend using multi-factor authentication (MFA) on all corporate accounts and properly configuring mechanisms such as SPF, DKIM and DMARC.
We must also review anomalous logins, automatic forwarding rules and any suspicious changes within email accounts.
Dual validation for significant payments
Where we manage transfers involving substantial amounts, we consider it advisable to establish a second approval.
Combining IBAN confirmation through an independent channel, verification of payee and authorisation by a second person creates several barriers against the same attempted fraud.
How Barcelona Penal approaches BEC fraud
When a company or individual consults us after sending money to a fraudulent account, our first objective is to reconstruct exactly what happened.
We analyse the chronology of events, the transfer, emails, invoices, the receiving IBAN, the steps taken with the bank and all available technical information.
We then assess the criminal strategy and the measures that may be useful in trying to identify those responsible and trace the money.
Where appropriate, we also review the possible liability of third parties. For current transactions, it is particularly important to know what information the verification of payee service displayed before the transfer was confirmed.
In our experience, we must not automatically assume either that the bank has to return the money or that a claim against the institution can never exist. Each fraud requires an assessment of how the transfer was authorised, what information the payer received and how the institutions involved acted.
Nor do we recommend immediately assuming that we must pay the genuine supplier again where there is a dispute between the parties. We must first examine the contract, how the impersonation occurred, which system may have been compromised and what obligations each party had.
At Barcelona Penal, we are lawyers specialising in Criminal Law in Barcelona and have experience in proceedings involving scams, economic offences and cybercrime. We can act from the first steps, prepare the criminal complaint and act as private prosecutor throughout the proceedings.
Frequently asked questions about what to do if we have sent money following a fake supplier email
Do not wait until it is too late: the sooner you act, the greater the chances of tracing the money and holding those responsible accountable. Request an initial consultation with our criminal law team and start regaining control of the situation.
