SME and digital disputes series — Ferrer-Bonsoms Abogados
A customer calls, angry, because they have paid an invoice the company never issued. A supplier writes, puzzled, because they have received an email from the “finance director” asking them to change the bank account details. Someone finds a website on Google with the company’s logo, its copy and even its team photos — but with a slightly different domain and a payment gateway that is not the company’s.
Corporate identity theft online is no longer a large-corporation problem. It mostly affects SMEs, because they are the ones with the least brand monitoring in place and the ones that take longest to detect it. And by the time it is detected, the damage is usually done: customers who have paid a third party, suspicious suppliers, negative reviews from people who were never real customers.
This article sets out the forms impersonation takes, the legal routes available in Spain, and the order in which to use them.
The most common forms of corporate impersonation
1. Cloned website or online store. A third party copies the design, copy and images of the corporate site and registers a similar domain (with a hyphen, a different extension, one extra letter). The aim is usually to collect payment for orders that are never fulfilled, or to harvest card details.
2. Fake profiles on social media and platforms. Accounts using the company’s trade name and logo to answer enquiries, advertise non-existent promotions or request personal data. This is particularly damaging in sectors where customers make first contact through social channels.
3. CEO fraud and supplier fraud. Emails imitating the real address of a director or a regular supplier (sometimes with a near-identical domain, sometimes from the genuine account if it has been compromised) instructing transfers or changes to bank details. This is the variant with the greatest direct financial impact.
4. Fake reviews tied to a usurped identity. Reviews posted by someone who was never a customer, sometimes accompanied by profiles built to look like one, and occasionally with an extortionate element: “I’ll take the review down if you pay.” Here it is the customer’s identity that is faked, not the company’s, but the harm falls on the business just the same.
The applicable legal framework
There is no single procedure. Four routes coexist and are used alternatively or cumulatively depending on the case.
Criminal route. Depending on how the conduct is structured, it may fall under usurpation of civil status (Article 401 of the Spanish Criminal Code), fraud (Articles 248 et seq.) where there has been deception causing a transfer of assets, and documentary forgery (Articles 390 to 399) where invoices, contracts or documents bearing the company’s apparent identity have been fabricated. A complaint is filed with the National Police, the Guardia Civil or directly with the duty court.
A realistic note: Article 401 requires impersonation with some degree of permanence and an appropriation of another’s legal position — mere misuse of a name is not enough. In many cases the natural fit is therefore fraud, where a third party has paid, or the civil and administrative routes.
Data protection route. Where the impersonation involves the use of personal data (a director’s, employees’ whose photographs appear on the cloned site, or customers’ obtained by deception), a complaint may be filed with the Spanish Data Protection Agency (AEPD), which also has expedited procedures for content removal in certain scenarios.
Platform takedown route (DSA). Regulation (EU) 2022/2065 (Digital Services Act) requires platforms and hosting providers to operate an accessible notice-and-action mechanism and to handle notices of illegal content diligently and with reasons given. This covers impersonating profiles, fraudulent advertising and — with nuances — manifestly fake reviews. A well-drafted notice, identifying the content by its exact URL and explaining why it is unlawful, obliges the platform to respond and creates a record for any subsequent claim if it fails to act.
In parallel, where a cloned domain is the problem, there is the route of complaint to the registrar and, where a trade mark is registered, domain-name dispute resolution proceedings.
Unfair competition route. Where the impersonator is a competitor or operates in the same market, the Spanish Unfair Competition Act offers cessation, removal-of-effects and damages actions, with the advantage of not depending on the pace of criminal proceedings.
What to do, in order
First: secure the evidence before doing anything visible. Full screenshots with the date and URL visible, copies of the emails including their complete technical headers (forwarding them is not enough), a record of the domains involved via a WHOIS query, and — where the amounts justify it — a notarial record or a web content certification service. Warning the impersonator before the evidence is secured usually results in everything being deleted.
Second: notify the platform or hosting provider, using the DSA notice-and-action mechanism, with exact identification of the content and legal reasoning. Keep the acknowledgement and the response.
Third: alert customers and suppliers. A short statement on the company’s official channels, stating the legitimate domain, the genuine bank accounts and which channels are never used to request certain data. This stops ongoing harm and strengthens the company’s position if an affected customer later brings a claim.
Fourth: file a criminal complaint where there has been financial loss or use of forged documents, with all the evidence already secured. If transfers have been made, notify the bank immediately: in some cases the transaction can still be blocked or recalled.
Fifth: complaint to the AEPD where personal data are involved.
Sixth: cease-and-desist letter and, where appropriate, civil or unfair competition proceedings for removal of effects and damages.
The particular case of fake reviews
Fake reviews deserve separate treatment, because the instinctive reaction — publicly replying that the person was never a customer — is the one that causes the most problems.
Before asserting that a review is fake, verify it internally. If the company publicly maintains that the reviewer was never a customer and it turns out they were (under a different name, through a third party, years ago), the position becomes very difficult to defend, and the reply itself may create a reputational problem bigger than the review.
Once confirmed that the review does not reflect a real experience, the route is notification to the platform. Directive (EU) 2019/2161 — the Omnibus Directive, already transposed into Spanish law — requires those providing access to consumer reviews to state whether they verify that the reviews come from consumers who actually used or purchased the product, and expressly prohibits publishing fake reviews or commissioning third parties to publish them. That duty is the basis for requiring diligent action from the platform.
Where a review contains specific, false factual allegations that damage reputation, there may additionally be a civil claim for interference with the legal person’s right to honour; and where money is demanded in exchange for removal, this is potential extortion, which does justify an immediate criminal complaint.
Prevention: what actually works
- Register the trade mark. Without a registered mark, many fast-takedown routes with platforms and registrars are simply unavailable.
- Register domains close to the main one (extension variants and common typos).
- Configure SPF, DKIM and DMARC correctly on corporate email: this is the single technical measure that most reduces CEO fraud and email impersonation.
- A written internal protocol for verifying changes to bank details: no supplier account change is executed without confirmation through a channel different from the one the request arrived on.
- Brand alerts and periodic review of listings and profiles.
Conclusion
Corporate identity theft is fought with speed and with order. Speed, because every day the content stays online multiplies the harm. Order, because acting before the evidence has been secured usually leaves the company with nothing to produce on the day it wants to claim.
Have you found a cloned website, a fake profile or reviews that do not correspond to real customers? At Ferrer-Bonsoms Abogados we support SMEs through the full response: securing evidence, takedown notices, criminal complaints and civil claims. Get in touch and we will review your case.
This article is part of our series on digital disputes affecting SMEs. See also our article on fake reviews and online reputation.
