MT-103 Fraud: How Fake Proof of Funds Destroyed $40M in Deals

If a counterparty hands you an MT-103 as proof of funds, you should already be suspicious. The MT-103 is a payment confirmation message — it proves a payment was made, not that money exists. Fraudsters know this. Counterparties who don't, lose deposits.
Across the deals we reviewed in the last twelve months, fabricated proof-of-funds documents were the single largest category of attempted fraud, ahead of fake bills of lading and ahead of shell-company schemes. The dollar value is conservatively north of forty million USD in failed or aborted deals. The good news: the fraud patterns are repetitive, and almost every one of them can be caught in under five minutes if you know what to look for.
What an MT-103 actually is
An MT-103 is a SWIFT-formatted single customer credit transfer message. It is generated by a sending bank when it dispatches funds to a beneficiary. It is not a balance confirmation, it is not a guarantee, and it is not proof that anyone holds anything today. A real MT-103 confirms only that a payment was made on a specific date for a specific amount.
When a supplier or buyer offers an MT-103 as proof that they have $5M sitting in an account ready to deploy, they are either misinformed or they are testing whether you are. Either way, it isn't acceptable.
The four documents that actually prove funds
- Bank Comfort Letter (BCL) — issued on bank letterhead, addressed to the counterparty, confirming the account holder has funds available for a specified transaction. Must be verifiable directly with the issuing bank's trade finance desk.
- Tear sheet / account statement — current month, on bank letterhead, signed by an authorised bank officer with a callback number.
- Standby Letter of Credit (SBLC) — issued by a top-50 bank, in favour of the seller, governed by ISP98 or UCP600. Must be authenticated bank-to-bank.
- Proof of deposit confirmation — bank-to-bank communication confirming funds are blocked or earmarked, sent via SWIFT MT-799 or MT-760.
Anything else — screenshots, PDFs received over WhatsApp, "verified" wallet balances, MT-103 receipts from previous trades — is not proof of funds.
The seven red flags
1. The document arrived as a PDF over email or WhatsApp
Real bank documents are exchanged bank-to-bank or, at minimum, hand-delivered on letterhead with a verifiable signatory. PDFs are trivial to forge — there are public templates for every major bank.
2. The signatory cannot be reached at the bank's published switchboard
Always call the bank's main number from its public website, not the number on the document. Ask for the named signatory by department. If they don't exist, the document doesn't either.
3. The font, kerning or logo is subtly wrong
Fraudsters work from old templates. Bank logos get refreshed; fraud templates don't. Compare the document's letterhead against the bank's current corporate identity on its annual report.
4. The SWIFT BIC doesn't match the branch
Every BIC encodes country and city. A document claiming to be from "HSBC London" with a Hong Kong BIC is forged. The SWIFT BIC directory is publicly searchable.
5. The account number format is wrong for the country
UK accounts have an 8-digit account number and 6-digit sort code. UAE accounts use IBAN format starting with AE. German accounts use IBAN starting with DE. Account numbers that don't match the country's banking standard are a tell.
6. The document references "blocked funds" without a SWIFT message reference
Real fund blocks are confirmed via SWIFT MT-760 or MT-799 with a unique reference number that the receiving bank can authenticate. A letter that says "funds are blocked" without one is decoration, not evidence.
7. The amount is suspiciously round, or matches the deal value exactly
Real account balances are rarely exactly $5,000,000.00. Fraudsters mirror the deal value to look conclusive. Mismatched-but-sufficient balances are more credible than perfect ones.
How to verify in under five minutes
Three calls. First, the bank's published switchboard, asking for the trade finance desk. Second, the named signatory, requesting confirmation of the document reference. Third, your own bank's trade finance desk, asking them to authenticate the document bank-to-bank. If any of the three refuses or stalls, you have your answer.
What to do when you get one
Don't accuse — just escalate. Reply that your compliance team requires bank-to-bank authentication via MT-799 before the document can be accepted, and provide your bank's coordinates. Genuine counterparties will arrange it within 48 hours. Fraudsters will pivot to a different proof, demand urgency, or vanish. All three responses are useful.
The bottom line
Proof-of-funds fraud works because it exploits the gap between what looks official and what is actually verifiable. The defence isn't sophistication — it's process. Define which documents you accept, insist on bank-to-bank authentication for every one of them, and never let urgency override verification. The deals worth doing will survive a 48-hour authentication delay. The deals that don't, weren't deals.