News
12 min read

E-invoicing checks: spotting fraud in ZUGFeRD and XRechnung

Learn how to spot manipulated IBANs in ZUGFeRD and XRechnung. Protect your SME reliably against invoice fraud from 2025 onwards.

A schematic depiction of a digital e-invoice check in which a magnifying glass points to a diverging IBAN between the PDF and the XML.
A schematic depiction of a digital e-invoice check in which a magnifying glass points to a diverging IBAN between the PDF and the XML.

Mandatory e-invoicing from 2025: new rules for the Mittelstand

From 1 January 2025 a fundamental legal change applies in Germany: for turnover between domestic companies in the B2B sector, the electronic invoice (e-invoice) becomes mandatory. In its 2024 guidance, the German Federal Ministry of Finance made it unmistakably clear that from this cut-off date, simple PDF documents, image files or scanned paper invoices no longer count as electronic invoices in everyday business, but as other invoices[1]. For you as a managing director or IT manager in a mid-sized company this means an immediate legal obligation: from the first day of the year, your business must be technically able to receive structured XML-based invoices, to process them without errors and to archive them in an audit-proof manner within the meaning of the GoBD.

  • Mandatory receipt from 1 January 2025 for all domestic B2B turnover, with no transitional period for the recipient[1].
  • The structured format must comply with the European standard EN 16931 or be agreed between the parties involved and must allow the complete extraction of all mandatory details into a standard-compliant format (Section 14 (1) UStG, Germany's VAT Act).
  • Transitional rules apply exclusively to issuing invoices: until 31 December 2026, all companies may continue to send paper or simple PDF invoices with the recipient's consent. Until 31 December 2027 this only applies to companies with total turnover of no more than 800,000 euros in the preceding calendar year; for data exchange via EDI the deadline likewise runs until the end of 2027 (Section 27 (38) UStG).

This legal change is, however, far more than a purely administrative task. Because modern e-invoices consist of machine-readable XML data that is transmitted in the background, invisible to the human eye, entirely new and highly specific attack surfaces for fraud arise for companies. Cybercriminals increasingly use automated methods to manipulate bank details in XML data records unnoticed. To counter these risks effectively, close interlocking of your IT infrastructure with modern verification mechanisms is indispensable. With our services in the field of cybersecurity we support you in hardening and protecting your systems. CAVRIX also helps your business to combine IT security and compliance efficiently in a mid-sized setting, so that you both meet the legal requirements in full and stay safe from sophisticated digital fraud scenarios.

How IBAN fraud works: the scam with manipulated PDFs

Classic invoice fraud has developed into a highly precise attack method in the digital age. Cybercriminals usually use unencrypted email communication or compromised email accounts at suppliers in order to intercept invoices sent in PDF format. Before the document reaches you or your accounting department, the attackers use automated tools to swap out nothing more than the bank details (IBAN) shown. The actual invoice content, the company logo, the line items and the totals remain absolutely identical. During manual invoice checking this fraud practically never comes to light, because all visual features correspond to the familiar invoice. Managing directors in German mid-sized companies in particular bear responsibility here for establishing appropriate control processes.

  • Compromise: attackers monitor a supplier's email traffic unnoticed through hacked mailboxes or intercept unencrypted mail.
  • Manipulation: a legitimate PDF invoice is intercepted and only the bank details are swapped for a fraudulent account.
  • Delivery: the manipulated PDF file is forwarded to your company without delay so as not to arouse suspicion.
  • Payment: your accounting department settles the seemingly correct invoice manually, so the money flows straight into the criminals' account.

Reports from practice show that these are not theoretical scenarios but a real threat to German mid-sized companies. Invoice fraud regularly leads to considerable financial damage in mid-sized companies. Affected companies often lose large sums on seemingly everyday purchases, because the manipulations usually only come to light days after the value date. Such attacks show painfully how vulnerable manual approval is without technical support. To minimise these risks in your supply chain, proactive cybersecurity is essential.

This is exactly where the statutory e-invoicing obligation from 2025 comes in. While a human easily overlooks the subtle change of an IBAN on a PDF document, structured formats such as ZUGFeRD or XRechnung can be reconciled with your master data by machine, character by character. If you automate this reconciliation, you systematically prevent expensive misdirected payments and protect your company against the devastating financial consequences of digital identity theft.

ZUGFeRD and XRechnung: the security risk of hybrid formats

The statutory e-invoicing obligation from 2025 confronts German mid-sized companies with new infrastructural challenges. While XRechnung is designed as a purely structured, machine-readable XML document, the ZUGFeRD format takes a hybrid route. It combines a visual PDF view for humans with an embedded XML file for machine processing. Both formats can meet the EN 16931 standard: XRechnung is a national implementation of this standard, and since version 2.0 ZUGFeRD builds on EN 16931, the Cross Industry Invoice standard from UN/CEFACT and the PDF/A-3 file format. What matters is that the ZUGFeRD profile used contains all mandatory details under Section 14 (4) UStG in the structured part and that the PDF and the XML are identical in content. This two-track structure does, however, harbour a specific weak point that criminals increasingly exploit for targeted invoice fraud through manipulated bank details.

The primary risk of hybrid formats lies in the potential divergence between what you see on the screen and what your accounting software actually processes. In this form of attack, cybercriminals specifically manipulate the raw XML data embedded in the PDF. While you see the correct, familiar bank details of your service provider on the visible PDF, the automated software reads the bank details directly from the XML data record. The misdirected payment therefore happens entirely unnoticed. In its letter of 15 October 2024, the German Federal Ministry of Finance (BMF) clarified that with hybrid formats the structured XML part is decisive and takes precedence over the visual document in the event of a divergence[2]. This means that manual visual checks of the PDF are ineffective both legally and operationally if the underlying data layer has been manipulated.

FormatStructureSecurity risk
XRechnungPure XML document (machine-readable)The lack of direct visualisation makes fast manual checking of manipulated payment data harder.
ZUGFeRDHybrid PDF/A-3 with embedded XML fileDiscrepancy (semantic gap) between the visually displayed PDF IBAN and the XML IBAN actually processed.

For managing directors and IT managers in mid-sized companies, this discrepancy represents a considerable security and liability risk. Manual checking quickly reaches its limits here. To close such gateways for fraud and manipulation, you need proactive cybersecurity for your business. Only automated invoice checking that reconciles PDF and XML data and verifies the IBAN protects your company effectively against fraudulent redirections.

The weak point in detail: when the PDF view and the XML data diverge

The hybrid ZUGFeRD format combines a human-readable PDF view with an embedded, machine-readable XML data record. This dual structure is meant to accelerate the digitalisation of your processes, but it creates a specific weak point: what is known as the divergence attack. When attackers intercept an invoice in transit, they usually change the IBAN in only one of the two layers, that is either in the visible PDF or in the embedded XML data record. If the other layer remains untouched, the manipulation goes unnoticed in a one-sided check. Because simple automated checking systems frequently only test the XML structure against formal criteria, they raise no alarm in this case. For managing directors in mid-sized companies this means an unnoticed but considerable financial risk.

The actual security gap only arises through a manual media break in your accounting. When your staff type or copy the bank details manually from the visible PDF view in order to approve the transfer in the banking portal, they bypass the digital checking process completely. No automatic reconciliation takes place that would reveal the divergence between the XML code and the displayed text. Criminals bank on precisely this human interface. Modern protection of your corporate assets therefore requires holistic cybersecurity at system level that reveals such discrepancies immediately.

  • The divergence attack: attackers deliberately forge only the visual PDF, while the XML part remains untouched and inconspicuous for standard system checks.
  • The manual media break: your accounting staff type the IBAN straight from the visual PDF view and thereby override the automated controls of your ERP system.
  • The missing validation: without automated checking that reconciles the XML data record directly with the rendered PDF data, the divergence remains invisible and the money flows into the fraudsters' account.

Digital verification: how to spot manipulated bank details

With the statutory e-invoicing obligation from 2025, the risk of highly precise invoice fraud in mid-sized companies rises considerably. The hybrid ZUGFeRD format in particular harbours an often overlooked weak point: it combines a human-readable image document in PDF format with a machine-readable XML data record. Cybercriminals exploit this in targeted attacks by manipulating the bank details in the XML code while the visual PDF remains unchanged. Because modern ERP systems and accounting software read payment data fully automatically and directly from the XML data record in order to pre-fill transfers, the manipulated IBAN is adopted entirely unnoticed. A manual comparison on screen no longer offers protection here, because the displayed PDF invoice shows the correct IBAN of the genuine bank account while, in the background, the money flows into the fraudster's account. To protect yourself and your business against this kind of invoice fraud, you need a continuous digital checking routine that reveals inconsistencies immediately.

Automated, three-stage digital verification protects your accounting reliably against financial damage:

  • Structural comparison of PDF and XML: an automated system compares the IBAN in the XML data record character by character with the IBAN in the visual PDF document, in order to block divergences immediately and issue a warning.
  • Master data reconciliation: the extracted IBAN is automatically reconciled with your historically grown and verified supplier master data, with every change requiring manual verification.
  • Risk verification: unknown bank details are isolated, checked for country-specific inconsistencies and only released for payment after documented approval.

This automated reconciliation ensures that fraudulent transfers are reliably prevented before financial damage occurs. Because manual spot checks are error-prone in a hectic working day and cost time, complete invoice checking is today part of IT security in your company. As a partner for cybersecurity in mid-sized companies, CAVRIX supports you in safeguarding your company effectively and minimising liability risks for managing directors. That way you meet regulatory obligations such as NIS2 and protect your business against losses in the long term.

Holistic protection for SMEs: cybersecurity, compliance and Managed IT

Effective protection against digital invoice fraud cannot be viewed in isolation. It requires a completely safeguarded and continuously monitored IT infrastructure. In the Allianz Risk Barometer 2024, cyber incidents rank first among business risks worldwide with 36 percent of mentions; among the German respondents they likewise take first place. To prevent fraudulent manipulation of your new e-invoices such as ZUGFeRD and XRechnung permanently, IT security, legal requirements and day-to-day administration have to mesh seamlessly.

How the CAVRIX security architecture protects you

CAVRIX unites these disciplines in one intelligent platform. We combine proactive cybersecurity and NIS2-compliant compliance with the flexible advantages of our Managed IT. Instead of managing confusing point solutions manually, our holistic approach actively protects your email mailboxes against unauthorised access and intercepts sophisticated phishing attacks before manipulated documents can even reach your systems. Through the Command Center you keep an eye on your company's current security status and all active verification tasks at any time.

  • Preventive email protection: continuous monitoring of your mailboxes and automatic filtering of suspicious messages for effective defence against business email compromise and CEO fraud.
  • Integrated document verification: automated real-time reconciliation of the XML and PDF structures of incoming e-invoices, in order to expose manipulated IBANs and forged invoice issuers immediately and reliably.
  • NIS2-compliant compliance: automatic logging of all checking steps carried out, to create complete audit trails and reports for your compliance documentation.

With this holistic and future-proof IT strategy you close the dangerous security gaps that the statutory e-invoicing obligation from 2025 can create in your company. You not only minimise the risk of direct financial damage from manipulated bank details, you also noticeably relieve your own IT resources. Get in touch with us today at info@cavrix.de for personal advice and find out how to raise your invoice checking and your general cyber security to a NIS2-compliant level.

Best practices: how to make your accounting fraud-proof

The purely technical switch to digital formats falls short if the organisational processes in the background have weak points. As a managing director or IT manager, your company's financial security lies directly in your hands. To rule out fraudulent manipulation of bank details effectively, consistent implementation of the four-eyes principle in all payment processes is indispensable. No invoice should be released for payment without being checked and approved by at least two independent people. Alongside this, the German Federal Office for Information Security (BSI) recommends continuously raising awareness among accounting staff of invoice fraud and social engineering scenarios, so that suspicious divergences in documents are recognised early.

  • Introducing clear control processes: establish binding workflows for verifying new bank details whenever master data changes.
  • Regular staff training: continuously raise awareness in your accounting and purchasing teams of forged payment requests.
  • Automated data reconciliation: use digital verification tools to reconcile the machine-readable XML data of ZUGFeRD and XRechnung directly with your master data.
  • Hardening the IT infrastructure: protect your ERP systems and email mailboxes against attacks in order to prevent documents from being intercepted and altered unnoticed.

Alongside strict internal processes, modern fraud protection requires complete monitoring of your entire IT infrastructure. With the CAVRIX Command Center we offer you an AI-native interface through which you keep an eye on your business's security and compliance status in real time and receive critical security alerts directly. That way you make sure your accounting systems and email channels stay protected against unauthorised access. Robust cybersecurity forms the foundation for preventing fraudulent manipulation of your invoice data from the outset. For specific questions about fraud prevention or for personal advice on e-invoice checking, you can reach our experts directly by email at info@cavrix.de.

Frequently asked questions

What is the difference between ZUGFeRD and XRechnung?

XRechnung is a purely structured XML format that is readable by machines. ZUGFeRD is a hybrid format: it contains a visual PDF component for humans and an integrated XML file for automated processing.

How can fraudsters manipulate a ZUGFeRD invoice?

Fraudsters intercept unencrypted emails and change the IBAN in only one layer of the ZUGFeRD invoice, that is either in the visible PDF or in the embedded XML. Anyone who checks only the other layer does not notice the divergence and transfers money to the wrong account.

Does the e-invoicing obligation apply to my small company too?

Yes. Since 1 January 2025, all domestic B2B companies in Germany must be able to receive e-invoices such as ZUGFeRD or XRechnung. For issuing them, a transitional rule applies until 31 December 2026 for all companies and until 31 December 2027 for companies with previous-year turnover of no more than 800,000 euros. The obligation to receive them, by contrast, has no transitional period.

How does automated invoice checking protect me against IBAN fraud?

Automated invoice checking compares the IBAN in the machine-readable XML data directly with the IBAN in the visible PDF document and reconciles it with your supplier master data. Whenever there is a divergence, the system stops the payment and raises the alarm.

Which security measures should my company implement immediately?

You should introduce automated checking software for ZUGFeRD and XRechnung, raise your staff's awareness of how to recognise invoice fraud, secure your email communication and establish clear approval processes (such as the four-eyes principle).

Where can I get support in safeguarding my invoice checking?

As an expert for cybersecurity, compliance and Managed IT, CAVRIX supports German mid-sized companies with secure digitalisation. You can contact us directly at any time at info@cavrix.de in order to make your IT and accounting fraud-proof.

Sources

  1. bundesfinanzministerium.de
  2. ecovis-kso.com

Where does your company stand?

30 minutes, free, no commitment. We show you where you stand.