Today, 9 October 2025, Verification of Payee went live across the euro area. Every credit transfer, instant or standard, now triggers a check: does the beneficiary name the payer typed match the account they are paying? Match, close match, no match; the payer decides with eyes open. Decades of invoice fraud and misdirected payments met their structural countermeasure this morning.
Fraud will migrate, not retire
Fraudsters respond to infrastructure the way water responds to walls. With name-mismatch redirection closing, attack energy shifts upstream: compromise the invoice before it is sent, impersonate the supplier during onboarding, socially engineer the "updated bank details" email from inside a real relationship. VoP verifies the payment; it cannot verify the relationship.
Verify the relationship, too
The upstream defence mirrors the downstream one. Verify the supplier exists (registry-live KYB), verify the person claiming to represent them is real (chip-level KYC) and authorised (mandate checks), and make contractual changes go through qualified signatures where identity is re-verified at the moment of signing. Then a fraudulent bank-detail change requires forging a government chip rather than an email footer.
Payments closed their gap today. Onboarding and contracting are next.
