Bank-Detail Substitution on Invoices: A Playbook for Prevention
The dominant SMB invoice fraud in Poland is bank-detail substitution. KSeF does not verify bank accounts. Here is how to detect and prevent it using the biała lista, cooling-off periods, and mandatory callbacks.
Bank-Detail Substitution on Invoices: A Playbook for Prevention
KSeF authenticates the issuer. It does not authenticate the bank account on the invoice. A valid, KSeF-accepted, UPO-carrying invoice can still display a fraudster's bank account number. The state verifies who issued the invoice. It does not verify where the money should go.
This gap is exploited. The dominant SMB-relevant fraud scheme in Poland is supplier bank-detail substitution: a fraudster intercepts communication between supplier and buyer, changes the bank account on the invoice or in the email, and redirects the payment. Documented losses include 40,000 EUR in a single Płońsk case (October 2025) and a foiled 1 million EUR transfer in Warsaw (March 2026).
The Threat Model
- Email interception: The fraudster gains access to the supplier's or buyer's email account and intercepts invoice emails. They modify the bank account in the PDF or in the email body.
- Fake supplier email: The fraudster registers a domain similar to the supplier's and sends a "new bank details" notice to the buyer.
- KSeF invoice with wrong account: Less common but possible: the fraudster issues a valid KSeF invoice with their own bank account in the payment details field.
- QR quishing: The fraudster replaces the KSeF QR code on a PDF visualisation with a QR code pointing to a phishing site.
Defensive Playbook
Check 1: Biała lista on payment day
The biała lista podatników VAT (white list of VAT taxpayers) is a Ministry of Finance registry of bank accounts associated with each VAT-registered NIP. Before paying any invoice above 15,000 PLN, check the supplier's bank account against the biała lista.
If the account is not on the biała lista:
- Do not pay
- Contact the supplier using a previously known phone number (not the one on the invoice)
- If the account was recently changed, wait 7 days (the ZAW-NR cure period) before paying
The 15,000 PLN threshold is statutory: payments above this amount to an account not on the biała lista cannot be deducted as a tax-deductible cost.
Check 2: Bank-detail-change cooling-off
When a supplier notifies a bank account change, implement a cooling-off period before the first payment to the new account:
- Verify the change. Call the supplier using a phone number from your existing records, not from the notification email.
- Wait 7 days. The ZAW-NR status on the biała lista lasts 7 days. After 7 days, the new account should appear on the list.
- Confirm in writing. Send a confirmation email to the supplier's known address asking them to confirm the change. Do not accept confirmation from the new email address.
Check 3: Mandatory callback for new payees
For any first payment to a new supplier, or the first payment to a changed account:
- Call the supplier. Use a phone number from your contractor database, not from the invoice.
- Verify the bank account verbally. Read back the last 4 digits of the account number.
- Log the verification. Record who verified, when, and how.
Check 4: Duplicate detection
If you receive two invoices with the same number but different bank accounts, treat the second as fraudulent. Contact the supplier directly. Do not pay either invoice until the legitimate account is confirmed.
What KSeF Does Not Do
KSeF does not:
- Verify that the bank account on the invoice belongs to the issuer
- Cross-reference bank accounts against the biała lista
- Alert the buyer if the bank account on a KSeF invoice differs from previous invoices
- Prevent scam invoices from being issued inside KSeF (a scam invoice assigned to the victim's NIP is a documented vector)
These are product features, not platform features. The state checks form. The product must check substance.
The Trust Narrative
"We verify what the state doesn't" is the positioning this gap enables. KSeF compliance is table stakes. Fraud prevention is the differentiator. The SMB tier has been underserved by fraud controls: enterprise AP departments run duplicate detection, bank-change flagging, and new-payee confirmation. Small businesses do not, because the tools are not packaged for them.
Plandesk packages the enterprise fraud stack for SMBs: bank-detail-change alerts with cooling-off, new-payee confirmation, fuzzy duplicate detection, and biała lista checks on payment day. The checks run automatically. The human confirms.
This material is information of a general nature and does not constitute legal or tax advice. For a specific situation, verify the current rules or consult a qualified adviser.