
How We Verify B2B Buyers: A Suspected E.Leclerc Impersonation Case
Learn how international manufacturers can verify wholesale buyers, detect procurement impersonation, and avoid B2B email scams using a real-world case study.
Learn how international manufacturers can verify wholesale buyers, detect procurement impersonation, and avoid B2B email scams using a real-world case study.
I’m Leo, a sales specialist at ClipClop eBike. Most mornings look the same: a few wholesale emails, a catalog request, someone asking for MOQ and FOB pricing. That is normal work for an OEM factory selling overseas.
Then one inquiry arrived that looked almost too clean.
The sender used the name Jeandis SAS and introduced themselves as a deputy purchasing manager for JEANDIS SA, a supply center linked to E.Leclerc stores in Marmande, France. They asked for a catalog and price list. It included a French phone number, a Marmande address, a link to the E.Leclerc site, and a polished signature.
A known European retailer. A company that exists. A real street address. A purchasing-sounding request. Nothing cartoonishly fake.
That is why this kind of email is hard. The company in the signature can be genuine. The person writing to you may still be unverified.
I did not close the lead. I also did not treat it as qualified. I took it apart.
First I checked the company, not the email.
France’s official business directory lists JEANDIS SA as an active company under SIREN 383 339 595, established on 23 October 1991. The registered headquarters are at RN113 Avenue François Mitterrand, 47200 Marmande. The main activity is hypermarkets. The same records show an E.Leclerc Express site in Marmande under that company.
So the legal entity is real. That part holds.
What it does not prove is authority. A registry entry tells me a company exists. It does not tell me the person in my inbox works there, can source e-bikes, or is allowed to use that email address. That split — company versus contact — is the whole point of buyer verification.
Then I looked at the domain: jp@achat-jeandis.com. I could not independently tie that domain to JEANDIS SA from official company information. The headers showed the message was sent from achat-jeandis.com. SPF passed for that sending domain. There was also a DKIM signature from an email security provider.
On a busy sales day those green checks feel comforting. They should not.
SPF and DKIM answer a narrow question: was this message authorized by the domain that sent it? They do not answer the question a factory actually needs: does that domain belong to the company printed in the signature? A domain can send authenticated mail and still have no proven link to the retailer it is borrowing. Authentication validates infrastructure. It does not issue a purchasing badge.
We also found public discussion of E.Leclerc / JEANDIS impersonation activity involving the same domain. That is not a courtroom finding. It still raised the risk level. Once a domain has been discussed in an impersonation context, stop assuming and start verifying.
The wording added another layer. The sender wanted new products and a catalog. No models, quantities, annual volume, delivery window, compliance notes, or procurement process. A broad first email is not proof of fraud. Real buyers often start wide. A large retailer should still become specific before the lead is treated as serious.
I did not send our full pricing pack, share bank details, draft a contract, ship a free sample, or pay a third-party fee. I did not accept a purchase order on the email alone. I marked the inquiry as unverified and high risk.
That is the difference between collecting leads and qualifying them.
The process I use is simple.
Verify the legal entity in an official registry. Do not rely on files the buyer attaches.
Separate the company from the person. Ask both questions: Does this company exist? Does this person work there and have authority to buy?
Inspect the domain after the @. A name that contains the brand is not automatically official.
Use a channel you found yourself. Do not call only the number in the suspicious email. Find official contacts independently and ask whether that person and email are authorized.
Then test the commercial request. A real project usually develops specs, quantity, destination, compliance needs, payment terms, and a named owner.
No single warning sign is a verdict. Risk rises when several appear together: a real company with an unfamiliar domain; a catalog request with no quantity; urgency with no process; free samples before qualification; a request to pay an unknown third party; a sudden change of bank account; an employee who cannot be confirmed independently.
Do not reject every unusual email. Raise verification as risk rises.
Inside our team I keep one rule: verify the buyer before you optimize the deal. Sales teams move fast — company, product, price, MOQ, payment. Another layer sits in front: identity, authority, commercial intent. Only then should a factory talk samples, POs, and money.
This case does not prove that a named individual committed a crime.
What it does show is narrower. JEANDIS SA is a real French company with a documented E.Leclerc presence in Marmande. The inquiry used achat-jeandis.com and passed SPF for that domain. Public reporting has discussed impersonation risk around the same domain. The identity behind the email could not be treated as verified.
That is the standard I want other suppliers to use: independent verification, not panic and not blind trust.
Before you share sensitive commercial information, ask the dull questions: Who is the company? Who is the person? Do they work there? Is the domain actually tied to the company? Is the request specific? Can you confirm any of this through a channel you found yourself?
The most convincing business emails are not always the safest ones. A real company name, a real address, a tidy signature, and authenticated mail can sit next to an identity that is still unverified. A few minutes of checking can save a factory from a much larger loss.
Disclaimer
This article is based on a wholesale inquiry received by ClipClop eBike and on publicly available company and security information. Personal details have been omitted or generalized. This is not a legal finding or a criminal allegation against any individual or company.
More OEM field notes.

E-Bike Frame Materials in Brazil: Why the ClipClop L1 Uses 6061 Aluminum Instead of Carbon Fiber or Steel

Best E-Bike Brakes for Colombia in 2026

Stop Sending Skinny Bikes to Brazil: What I Learned the Hard Way at ClipClop
Send your brief. We will field-note back.
Reply includes the feasibility view, sample cost, MOQ, and the next step for your project. We aim to respond within 48 hours.