BaFin Warns About Virtual IBANs — But the Problem Is Years Old

Bafin warns about virtual IBANs

BaFin Warns About Virtual IBANs - But the Problem is Years Old

On 27 July 2026, the German financial supervisor BaFin warned that virtual IBANs can become “Trojan horses” in the European payment system. According to BaFin, layered vIBAN structures may be systematically misused for money laundering and digital underground banking when banks and payment institutions lack sufficient information about the actual end users and payment flows.

The warning confirms the concerns EFRI raised in its earlier report, “Virtual IBANs — a Risk for Consumers?” Virtual IBANs can make a payment appear to be directed to an individual account while the funds are actually routed to a master account held by a bank, payment institution or electronic-money institution. When several providers are involved, the payer may not know who holds the underlying account, who identified the recipient or which institution is responsible when fraud occurs.

BaFin’s 2026 notice does not reveal a newly discovered risk. It formalises a risk pattern that had been visible for years and that BaFin itself had already addressed, at least in part, through a December 2020 order requiring institutions to record the end users behind vIBAN structures in the account information database.

In EFRI’s assessment, the supervisory failure lies in what followed: no publicly documented, timely and effective sector-wide enforcement; no retrospective review of high-risk vIBAN and comparable payment structures; and no victim-oriented response proportionate to the scale of the harm.

Deutsche Handelsbank: A Decade of Warning Signs

Years before BaFin expressly linked complex vIBAN structures to underground banking in its 2026 supervisory notice, EFRI had already encountered the same transparency and accountability gap in connection with Deutsche Handelsbank.

From at least 2016 through 2020, the Munich bank served as an important infrastructure provider for payment institutions and e-money companies. These providers maintained accounts with Deutsche Handelsbank and allocated payment accounts or individual payment identifiers to their merchant customers. EFRI documented numerous payments from fraud victims passing through this infrastructure to fraudulent investment and gambling schemes.

The payment flows identified by EFRI involved providers such as PPRO Financial, Paysafe, Connectum and Powercash21, which later began operating under the payabl. brand. EFRI’s records also show that accounts at Deutsche Handelsbank were used to receive funds for schemes including 24option and YESoption. (Note: Both PPRO and Paysafe nowadays have documented settlement relationships with Banking Circle, another vIBAN Provider). Victims were given what appeared to be ordinary German bank accounts. They were not informed about the payment institution, the master-account structure or the entities operating behind the IBAN.

Whether every identifier met today’s formal definition of a virtual IBAN is secondary. The structure displayed the same weakness now identified by BaFin: the bank providing the account infrastructure knew the payment provider, while the businesses ultimately using the payment details remained several layers removed from the bank.

This created a predictable accountability gap. The bank could point to the payment provider as its customer. The payment provider could point to the fraudulent merchant. The victim had a relationship with neither and was left to reconstruct the entire payment chain after the money had disappeared.

In 2021, the Bavarian government confirmed that Munich prosecutors were investigating suspected money laundering involving Deutsche Handelsbank. EFRI had begun submitting relevant account information to German authorities in early 2020 and filed a consolidated complaint concerning Deutsche Handelsbank and key customers in December 2020. The bank’s premises were searched in April 2021. Prosecutors had also identified at least seven account holders linked to regulatory warnings, including warnings concerning xTrader, OptionStars and Option888.

The authorities could not even state how many consumers had been harmed through accounts held at the bank. They admitted that no statistical data existed. This inability to quantify the damage is itself part of the regulatory failure: the authorities lacked the information required to measure the consumer harm created by the payment infrastructure they supervised.

BaFin did not publicly order Deutsche Handelsbank to improve its internal safeguards and comply with its customer due diligence obligations until 2 November 2020. The federal government later confirmed that BaFin had ordered no special anti-money-laundering inspection before 2019, although fraud payments and regulatory warnings had already been visible for years.

According to information available to EFRI, the money-laundering investigation ended without a public trial or judicial findings establishing personal responsibility on the part of the bank’s owners or managers. Deutsche Handelsbank discontinued its payment-services business in 2021 and returned its banking licence at the end of 2022. The banking business disappeared, but the victims’ losses remained. 

The Deutsche Handelsbank case shows that the transparency and accountability gap of virtual IBANs now described by BaFin had been visible for years. BaFin’s 2026 notice lists incomplete end-customer data, shell-company indicators, implausible transaction volumes, rapid account turnover, multiple intermediaries and fragmented cross-border payment structures as warning signs. These patterns had long been apparent in payment infrastructures used by fraudulent investment schemes.

Nor did BaFin lack regulatory instruments. Its notice relies largely on existing duties and expressly refers to its December 2020 data-storage order. The failure therefore lies not in discovering the risk too late, but in failing to enforce known requirements, review historic high-risk structures and avoid additional harm by acting much earlier. 

BaFin confirms that responsibility cannot simply be outsourced

BaFin now expects institutions operating vIBAN structures to understand who ultimately uses the accounts, how the payment model works and which risks arise from cross-border or multi-layered arrangements. Institutions must incorporate those risks into customer due diligence, transaction monitoring and, where necessary, enhanced due diligence.

This is an important clarification. A bank holding the master account cannot discharge its own AML duties merely by assuming that another payment provider somewhere in the chain knows the end user.

But BaFin’s warning remains primarily an AML measure. It does not answer the central question for fraud victims:

Who is responsible after the money has already passed through the virtual-IBAN structure?

New EU rules improve identification — not victim recovery

Regulation (EU) 2024/1624  introduces an EU definition of a virtual IBAN. From 10 July 2027, institutions issuing virtual IBANs will have to identify and verify their users. The institution servicing the underlying account must also ensure that it can obtain the relevant identification and verification information from the vIBAN issuer without delay and, at the latest, within five working days.

These rules close part of the regulatory gap identified by the EBA. They do not, however, establish:

  • a public mechanism for identifying the master-account institution;
  • an immediate fraud-tracing and freezing channel;
  • a direct right for victims to obtain allocation records;
  • clear civil liability within the vIBAN chain;
  • an obligation to review historic high-risk portfolios;
  • a compensation mechanism for victims.

Five working days may be acceptable for an ordinary regulatory information request. It is far too slow when fraud proceeds must be traced before they are transferred again.

Europe must examine the past, not only regulate the future

The BaFin warning should not result only in improved procedures for new vIBAN programmes. Supervisors should require retrospective reviews of existing and historic high-risk structures.

Institutions should identify virtual or merchant-specific IBANs used by unlicensed investment platforms, fraudulent merchants and opaque payment intermediaries. They should preserve the records linking each identifier to the master account, payment provider, merchant and beneficial owner. Where fraud complaints were repeatedly associated with the same infrastructure, the relevant institutions should be required to assist victims and law-enforcement authorities in reconstructing the payment flows.

The central issue is no longer whether regulators recognise the risks of virtual IBANs. They do.

The real questions are why these structures were allowed to serve fraudulent businesses for so long, what banks and payment providers knew about their end users, and how the victims will obtain the information and restitution they need.

BaFin has confirmed the risk. Europe must now address the consequences.

Leave a Comment

Find out more: