top of page

Virtual IBANs: How They Work and How They Can Be Abused for Financial Crime

How vIBANs work

Virtual IBANs, or vIBANs, can make payments easier for businesses and their customers.

But they can also create an additional layer between the bank issuing the IBAN and the person actually using it.



To understand the risk, we first need to understand how a vIBAN works.


What is a virtual IBAN?


A virtual IBAN looks like an ordinary International Bank Account Number (IBAN).

But it does not necessarily represent a separate bank account.


Instead, it can be linked to an underlying payment account, sometimes referred to as a master account.


Let’s use a simple example.


A payment service provider (i.e. a payment institution or an EMI) has an account with a German bank. The bank provides the payment provider with multiple virtual IBANs.


The payment provider can then allocate individual vIBANs to its own customers:


How vIBANs work

If someone sends money to Customer A’s vIBAN, the payment is routed to the payment provider’s underlying or master account held with the bank. The vIBAN allows the payment provider to identify that the funds belong to Customer A and credit them accordingly.


Customer A therefore does not necessarily have a separate account with the bank. The bank holds the payment provider’s master account, while Customer A has the relationship with the payment provider.


There are perfectly legitimate reasons for using this structure. For example, vIBANs can make it easier for businesses to identify incoming payments, allocate them to the correct customer and automate reconciliation.


What does the person making the payment see?


This is where the structure becomes particularly interesting.


To someone making a payment, Customer A’s vIBAN can look like an ordinary IBAN, in our example, a German one. The payer may therefore believe that Customer A has an account with the German bank associated with that IBAN.


But that may not be the case.


BaFin has specifically identified this issue. It has explained that these arrangements can create the appearance that the end customer’s account is held with the bank rather than with the payment provider.


That difference matters. Not only in Germany, but across the whole European Union.


How can a vIBAN be abused?


Imagine that Customer A is a fraudster. The fraudster is a customer of a payment provider and has been allocated a German vIBAN - issued by a reputable bank.


They advertise a product online. A victim agrees to buy it and receives payment instructions:


Send the money to DE12 3456…


The victim sees a German IBAN. They may reasonably assume that the recipient has an account in Germany with the bank.


They make the payment.


But the fraudster does not necessarily have an account with the German bank.


The payment is routed through the vIBAN arrangement to the payment provider’s underlying account, and the corresponding funds become available to the fraudster through the payment provider.


The structure therefore looks more like this:


How vIBANs can be misused for fraud

The payment provider itself does not have to be involved in the fraud. Its customer may simply be abusing a legitimate payment product.


What has BaFin identified?


BaFin has previously reported cases where German banks issued vIBANs to intermediary payment service providers, many of which were located abroad, and those providers passed the vIBANs on to their own customers.


According to BaFin, law enforcement authorities increasingly reported the misuse of these arrangements in online shopping fraud.


The person making the payment could believe that the account was maintained in Germany, while the money was ultimately being paid to an account abroad. BaFin also reported that perpetrators often could not be identified.


It has additionally reported indications that vIBANs had been misused for terrorist financing.

This highlights a much broader AML problem: visibility.


Who does the bank actually know?


Think again about the structure:


Bank → Payment Provider → End Customer


The bank has a relationship with the payment provider.

The payment provider has a relationship with the end customer.

The end customer is the person actually using the vIBAN.


This creates some important questions for the bank.


  • How much information does it have about the end customers using the vIBANs it has issued?

  • Can it identify the person associated with a particular vIBAN?

  • Does it understand how the vIBAN is being used?

  • Can its transaction monitoring identify unusual activity at the appropriate level?

  • And what happens when the activity behind a vIBAN does not make sense?


The answers become particularly important when the payment provider and its end customers are located in other jurisdictions.


The vIBAN is not the problem


It is important not to draw the wrong conclusion. vIBANs are not inherently suspicious.

They are useful payment tools with legitimate commercial purposes.


The risk comes from how the product is structured, who can access it and how much visibility the financial institution has over the people ultimately using it.


This is also why financial institutions should not treat the introduction of a product such as vIBANs as only a commercial or technology decision.


Before offering the product, they need to understand how it could be abused.


Questions should include:


↳ Who will ultimately receive the vIBANs?

↳ What information will we have about those users?

↳ Which jurisdictions will be involved?

↳ Can we link activity to an individual vIBAN and end customer?

↳ Can our monitoring identify unusual patterns of activity?

↳ Who investigates activity involving the underlying customer?

↳ What happens when the payment provider cannot provide sufficient information about an end customer?


These are product-risk and financial crime-risk questions, not simply technical ones.


The wider AML lesson


There is a wider lesson from the vIBAN example.


Knowing your direct customer does not necessarily mean you understand everyone who can access your financial infrastructure through that customer.


Financial products increasingly involve multiple providers, platforms, intermediaries and end users.


Every additional layer can change what an institution can see. That means an effective product risk assessment should do more than assign a product a low, medium or high risk rating.


It should ask:


  • How could someone abuse this product?

  • What would that abuse look like in practice?

  • Would we be able to see it happening?


A product can have a perfectly legitimate purpose and still create an opportunity for financial crime. Understanding how the product really works is the first step towards understanding the risk.

 
 
bottom of page