The summer transfer window of 2026 saw about €8.5 billion changing hands in international deals. However, in such a vast market, millions can vanish due to a single fake email, altered invoice, or fraudulent IBAN. Scammers intercept transfer payments, impersonate agents, or completely fabricate transfers from scratch. Often, money disappears without a trace while the obligations for payment remain intact.
Intercepted millions: from Romania to Qatar
At first glance, modern transfer deals appear to be securely protected. Clubs utilise FIFA's Transfer Matching System (TMS), which stores all contract details, payment schedules, and banking information. However, TMS does not facilitate the transfer of millions; at some point, one party must initiate the payment themselves. This is the moment when criminals strike.
An illustrative example involves Romanian winger Florinel Coman's move from FCSB to Qatari club Al-Gharafa in June 2024. After sending correct banking details, scammers sent a modified set of documents from a new address masquerading as a hotel in Cologne.
- The new invoice specified €5 million to be sent to a bank in Vietnam, to an account registered in Ho Chi Minh City.
- The documents featured errors in the club name FCSB and used a different font, yet the Qatari club transferred the funds to the fraudulent account.
- Due to a contractual penalty of €1 million for late payment and the fact that the real seller never received the funds, the Court of Arbitration for Sport (CAS) mandated Al-Gharafa to repay the entire amount.
Similar scams have ensnared clubs across Europe:
- Lazio lost approximately €2 million in the final installment for Stefan de Vrij's transfer from Feyenoord due to a fake letter with new banking details.
- Ferencvaros, while buying Stepan Loncar from Rijeka, inadvertently transferred nearly €1 million to a Spanish account at Santander, despite suspicious discrepancies in email addresses. Ultimately, CAS divided responsibility between the clubs due to ignored warning signs.
- Malmo had to pay twice for Gabriel Busanellu from Chapecoense (€400,000 ended up in a Slovak fraudulent account), as the club overlooked mismatches in TMS data.
Virtual agents and entirely fabricated transfers
Scammers go further and employ fake intermediaries. Just ten days after Robert Lewandowski's transfer to Barcelona in 2022, the Catalan club received a letter from an alleged agent, Pini Zahavi, demanding a €1 million commission to be sent to an account in Cyprus under a Dutch lawyer's name. The transfer was halted thanks to the vigilance of the bank's compliance department and club staff.
An even more radical level of fraud involves completely fictitious transfers:
- In winter 2025, Bastia midfielder Julien Maghiotti rushed to training and flew to Germany following news of a loan to Eintracht (Braunschweig), only to find out that the German club had never expressed interest and the player was being asked for €10,000 for a 'medical examination.'
- Similar schemes have affected clubs in Malta, with Dutch side Groningen encountering fraudsters impersonating technical director Mo Allah, sending fake offers to agents, causing players to head to Schiphol Airport in anticipation of non-existent contracts.
- A similar case arose with Serbian footballer Bojan Cekaric, who received a fake offer from Norwegian club Viking and was asked for €8,200 for a medical check-up.
The key lesson for the football business
These stories highlight a simple truth: to steal millions, hackers don't need to breach the entire security system of world football. Often, it suffices to convince one specific club employee that the person on the other end of the email correspondence is indeed who they claim to be.
The most reliable form of protection remains basic vigilance: if banking details unexpectedly change during a multi-million pound transfer (for instance, if funds are requested to be sent to Vietnam instead of Romania), it’s essential to contact partners through an alternative communication channel — a direct phone call, rather than responding to a suspicious email.