A genuine company name, a fake buyer
A new account registers using the name and company number of a real, established construction firm. The email address is on a domain registered last week that looks almost the same as the firm's real one. The account applies for payment terms, is approved because the company's credit profile is strong, and places a large order for power tools and copper pipe from three suppliers, for delivery to an industrial unit that is not one of the firm's sites.
The goods are dispatched. The invoice goes unpaid. When you contact the real firm, they have never heard of the order.
Why trade marketplaces are targeted
B2B marketplaces combine things fraudsters like: goods that resell easily, payment terms instead of upfront payment, delivery to addresses other than the registered office, and suppliers who dispatch quickly once an order is confirmed. Impersonating a real company is easier than creating a fake one, because a real company passes credit checks.
Your buyer verification and credit checks look at the company. They may not check whether the person registering has anything to do with it.
| Warning sign | Why it matters |
|---|---|
| Email domain newly registered or lookalike | Common in impersonation |
| Delivery address unrelated to the company | Goods diverted to a drop point |
| Large first order of easily resold goods | Typical fraud pattern |
| Contact details differ from public records | Person may not work there |
| Urgency and pressure to dispatch | Social engineering |
What fraud costs
Direct losses: goods dispatched and never paid for, which fall on you or the supplier depending on your model. Supplier trust, if suppliers bear or share the loss. Time spent investigating and dealing with the impersonated company. And overcorrection: after a fraud, teams often tighten checks so much that genuine buyers are delayed or turned away.
How losses are shared and what checks you run are set by your terms and policy. The aim is to catch more fraud without slowing genuine buyers.
The fraud checks we build
- Registration signals: at sign-up, the email domain's age and similarity to the company's real domain, the match between contact details and public records, and the IP location are checked alongside your normal verification.
- Order signals: each order is scored on signals such as first order size, product mix, delivery address type and distance from the company's known sites, changes of delivery address after approval, and order timing.
- Risk rules: your team sets thresholds, and orders above them are held before suppliers are told to dispatch.
- Verification call-back: held orders prompt a check with the company through contact details from public records, not the ones on the account, following your procedure.
- Review queue: your team sees held orders with the signals that triggered them and releases or cancels them, and each decision improves the rules.
- Supplier alerts: suppliers are told when an order is on hold, so they do not dispatch it, and when it is released.
Checks can use services from your payment provider, such as Stripe Radar for card payments, and fraud or identity providers you choose, alongside rules specific to trade buying.
Orders after the checks are in place
Most orders pass without delay. The few that look wrong are held before goods leave, when a phone call to the real company can settle the question. Suppliers dispatch knowing risky orders have been checked. Your team learns which patterns appear in your categories and tightens the rules where they matter.
Could this happen on your marketplace?
- You offer payment terms to newly registered buyers.
- Delivery addresses are not compared with the company's known sites.
- Email domains are not checked for age or lookalikes.
- Suppliers dispatch as soon as an order is confirmed.
- You have had an order from an account impersonating a real company.