Recognising Business Fraud and Scams
Small firms are targeted constantly, and the successful attempts are rarely sophisticated. The common patterns and how to stop them.
Businesses are approached by fraudsters far more often than owners realise, and the attempts that succeed are usually simple rather than technical. Knowing the recurring patterns is most of the defence, and Action Fraud is the UK reporting point when something happens.
Invoice Redirection Is the Most Costly
A fraudster impersonates a supplier and emails new bank details, frequently with a plausible explanation. Payments then go to them. This costs UK businesses substantial sums and it is almost entirely preventable.
The defence is a rule rather than vigilance: never change payment details on the basis of an email. Ring the supplier on a number you already hold, not one in the message, and verify. Apply it every time, including when it is inconvenient.
Chief Executive Fraud
Image source: pexels.com
An urgent message appearing to come from the owner or a director instructs staff to make an immediate payment, usually stressing confidentiality and time pressure. Staff should know they will never be asked to bypass normal checks, and that verifying is always acceptable.
Fake Invoices and Unsolicited Services
Invoices arrive for directory listings, domain renewals, trade mark services or compliance documents that were never ordered. Newly registered companies are targeted heavily because Companies House records are public. Check every invoice against something you actually agreed.
Advance Fee and Grant Scams
Offers to secure funding, grants or contracts for an upfront payment. Legitimate grant bodies do not charge to apply and nobody can guarantee a competitive award. Any request for money before a service is delivered deserves suspicion.
Phishing Aimed at Email Access
Messages imitating your email provider, bank or a familiar service, designed to capture login details. A compromised email account is the starting point for most invoice fraud, because it lets the attacker read genuine correspondence and time their approach.
Two-Factor Authentication Is the Single Best Control
Enabling it on email, banking and accounting software prevents most account takeovers even where a password has been captured. It takes minutes and is the highest-value security step available to a small business.
Impersonation of HMRC and Government
Calls, texts and emails claiming tax is owed, or offering a refund, using threats or urgency. HM Revenue & Customs does not demand immediate payment by unusual methods or threaten arrest by phone. When in doubt, hang up and call back on a published number.
Mandate and Direct Debit Fraud
Unauthorised direct debits set up against your business bank account. Reviewing your account regularly is how these get caught, and they are frequently small enough to go unnoticed for months.
Recruitment and Supplier Vetting
Check new suppliers exist and have a trading history before paying deposits, and verify unusual customer orders — particularly large first orders with urgent delivery and unusual payment arrangements, which is a recognised pattern.
Build the Checks Into the Process
Dual authorisation on payments above a threshold, a rule on verifying bank detail changes, and a policy that nobody is criticised for slowing down to verify. Fraud succeeds through urgency, so removing the pressure to act fast is the structural fix.
Keep Software and Devices Updated
A large share of successful attacks exploit known weaknesses that were already patched. Enabling automatic updates on devices, browsers and business software closes most of that exposure for no cost and almost no effort.
Use a Password Manager
Reused passwords mean one breached service compromises several. A password manager makes unique credentials practical, and it is considerably more secure than the spreadsheet or notebook most small businesses actually use.
Train Whoever Handles Money
The person paying invoices needs to know these patterns explicitly. Most successful fraud relies on someone junior not wanting to question something that appears to come from above.
Verify Unusual Requests Even From Known Contacts
Compromised accounts mean a genuine email address can send a fraudulent message. The sender being familiar is not verification. Anything involving payment details, urgency or secrecy warrants a call on a number you already hold.
Limit Who Can Move Money
Restricting payment authority to named people, with dual approval above a threshold, removes the single most exploited weakness. It also protects staff, who are then never in the position of being pressured to act alone.
Beware Overpayment Refund Requests
Image source: pexels.com
A customer overpays, then asks for the excess refunded to a different account, before the original payment is reversed as fraudulent. Refund only to the original payment method, and only once funds have genuinely cleared.
Check Before Sharing Company Information
Callers claiming to be from your bank, a supplier or a government body may be gathering detail for a later approach. Take a name, end the call, and ring back on a published number rather than one you were given.
Watch for Domain and Email Lookalikes
Fraudsters register domains that differ from a supplier’s by one character, which is invisible at a glance. Checking the sending address carefully on any message about payment details is a habit worth building into the payment process itself.
Keep Evidence of What Happened
Preserve the emails, headers, invoices and any correspondence rather than deleting them in frustration. Banks, insurers and investigators all ask for it, and reconstructing the sequence afterwards from memory is close to impossible.
Review the Process Afterwards
An attempt that nearly succeeded is more informative than one that failed obviously. Looking at which check would have caught it, and adding that check, is what turns a near miss into a genuine improvement.
Tell Your Suppliers and Customers
If your email has been compromised, people who correspond with you are the next targets. Warning them promptly, by phone or from a different account, limits how far an attack spreads beyond you.
Insurance May Cover Some of It
Some policies cover cyber incidents and certain types of fraud, and some explicitly exclude them. Check what your cover actually includes before an incident, since the exclusions are where the disappointment happens.
Review Your Own Public Footprint
Staff names, roles, email formats and supplier relationships published on your website make impersonation easier. There is a balance between transparency and giving away the material for a convincing approach.
If It Happens, Act Immediately
Contact your bank straight away — funds can sometimes be recalled if reported within hours. Report to Action Fraud, change compromised passwords, and check for further unauthorised activity. Where personal data was exposed, Information Commissioner’s Office obligations may also apply.



