An email, a plausible reason, and a familiar voice on the phone. A Richmond finance team came within one click of paying £38,000 to a criminal.
It is an ordinary Tuesday. Your bookkeeper flags an email from a supplier you have paid for years. Their bank has changed, the message says, and could you please update their details before the next payment run. The logo is right, the signature is right, the name at the bottom is the person you always deal with. An hour later the phone rings. It is that same supplier, or so it sounds, politely checking the change has gone through so the next invoice is not delayed. Everything about it is normal. The £38,000 is due on Friday. There is no reason to think twice, and that is precisely the point.
At a glance
- Invoice redirection fraud works by impersonating a genuine supplier and asking you to change their bank details.
- Losses from authorised push payment fraud, where victims are tricked into sending money themselves, reached £576 million in the UK in 2025.
- The defence is procedural rather than technical. Verify any change of bank details by calling a number you already hold, never the one on the message.
- Voice, and now video, can be convincingly faked, so a familiar voice is no longer proof of who you are dealing with.
- Payments above a sensible threshold should require two people to release them, and if money has gone, contact your bank at once.
How do I stop my business paying a fake invoice?
The single most effective step is a firm rule: never change a supplier’s bank details, or make an unusual payment, on the strength of the message that requested it. Verify independently by calling a number you already hold, not one from the email or the call. Then add a second approver for larger payments, so no one person can release funds alone. Most invoice fraud is defeated by that pair of habits.
Two questions people usually ask next:
What is authorised push payment fraud?
It is fraud where you are tricked into authorising a payment yourself, believing you are paying a genuine supplier, customer or colleague. Because you approved it, it behaves differently from a stolen card, which is why the reimbursement rules matter and why prevention rests on your own checks rather than the bank’s.
Are small businesses really a target?
Yes, and increasingly so. Smaller firms are attractive precisely because they often lack layered controls, and a single person can usually release a payment alone. The techniques once reserved for large targets are now used routinely against businesses of every size.
Those are the essentials. How close a Richmond finance team came to losing £38,000, and what stopped them, shows why the rule matters more than the sharpest eye.
Why these get through
The instinct afterwards is to assume the victim was careless. Almost always, they were not.
These frauds succeed because they do not look like fraud. There is no misspelled link, no obvious threat, none of the tell-tales that awareness training taught everyone to spot. Instead there is a reasonable request, from a known contact, arriving at a moment when a payment to that very supplier is genuinely due. The criminal has often been reading the email traffic quietly for weeks, which is how the timing lands so well. What is being attacked is not your password. It is your trust, and your understandable wish to be helpful and prompt.
Urgency is the other lever. A reason to act today, a note that the supplier is chasing, a hint that a delay would be embarrassing, all of it is designed to move you past the pause where a check would happen. Once you understand that urgency is the weapon, a small piece of the defence is already in place.
The bank-detail switch
The single most common move is the one in our scenario: a request to change the account a regular payment goes to. It is effective because it does not ask for anything unusual on the surface. Suppliers do change banks. Details do get updated. The fraud hides inside a routine event.
This is why the safest rule is also the simplest. A change of bank details is never actioned on the strength of the message that requested it. Not the email, not the letter, not the call. The request and the verification must travel down two different roads, so that a criminal who controls one road still cannot complete the con.
A familiar voice is no longer proof
The follow-up call used to be reassuring. It is now part of the toolkit. Voice cloning has reached the point where a short clip of someone speaking, easily lifted from a video call or a public talk, is enough to generate a convincing imitation. Video can be faked too.
The most widely reported case involved a multinational engineering firm whose finance employee joined a video call with what appeared to be several senior colleagues, all of them synthetic, and authorised transfers of around £20 million. The scale is unusual. The technique is not, and it is steadily working its way down to businesses of every size. The lesson for a Richmond company with a lean finance team is not to be frightened of the technology, but to stop treating a recognised voice or face as sufficient authority to move money. It no longer is.
The controls that actually work
None of the defences here is expensive or clever. They are habits, applied consistently, and consistency is what defeats a con that relies on a single unguarded moment.

Underneath the table sits one structural safeguard worth building in: dual authorisation on payments above a threshold you set. When two people must release a payment, the fraud has to deceive both at once, which is far harder. Good cloud accounting and payment systems support this natively, and it costs nothing but a moment of discipline.
Every business that has come to us after one of these thought the same thing beforehand, that it would be obvious. It is not obvious, because it is built to look ordinary. The firms that stay safe are not the ones with the sharpest eye on the day. They are the ones with a rule that does not depend on anybody’s eye at all: no change of bank details without a call-back, no exceptions, no matter who seems to be asking.
Donovan Crutchfield, ACA, Area Managing Partner, Xeinadin Richmond
If the money has already gone
Speed matters more than anything else in the first hour. Contact your bank immediately and ask them to attempt a recall, because funds can sometimes be frozen before they are moved on. Report the matter to Action Fraud, and preserve every email, message and note while it is fresh.
There is more protection than there used to be. Under the mandatory reimbursement rules that took effect in October 2024, many victims of authorised push payment fraud can claim their money back where the payment was made through Faster Payments or CHAPS between UK accounts. The scheme covers individuals and, importantly, micro-enterprises and small charities, up to a cap per claim, currently £85,000. It does not cover international payments. None of this is a substitute for prevention, and reimbursement is never guaranteed, but it means a business that acts quickly and in good faith is not always left to absorb the whole loss.
Building the habit before it is tested
The Richmond company did not pay the £38,000. The bookkeeper, uneasy about changing details on the strength of an email, rang the supplier on the number from an old invoice. The real supplier had not moved banks and knew nothing about it. The near miss became the reason the firm finally wrote its payment controls down, so that the next time, and there is usually a next time, the safe response did not depend on one person’s good instinct on a busy afternoon.
That is the through-line of so many of these situations, and of others that look quite different on the surface. In our case study on how a Kingston engineering firm discovered its loan account problem at year end, and again in the one on two restaurant sites and one hidden loss, a profitable business was caught out by something nobody had made anyone responsible for watching. Controls are simply the act of deciding, in advance and in calm, who watches what.
If your payment process still rests on trust and memory, it is worth putting something firmer in place before it is tested. Our financial control and outsourcing and business advice teams help owner-managed businesses across Richmond and Surrey design controls that are strong enough to matter and light enough to actually be followed.
More common questions
How can I tell if an email asking to change bank details is genuine?
You cannot reliably tell from the email itself, because convincing fakes copy logos, signatures and writing style. The only dependable test is to verify through a separate channel, by calling the supplier on a number you already have on file, never one supplied in the request.
Can I get the money back if we have already paid a fraudster?
Possibly. Contact your bank at once to attempt a recall. Under the reimbursement rules introduced in October 2024, many victims, including micro-enterprises, can reclaim losses on UK Faster Payments or CHAPS transfers up to a cap. It is not guaranteed and does not cover international payments, so acting fast and in good faith is essential.
What is dual authorisation, and do we need it?
Dual authorisation means two people must approve a payment before it is released. For anything above a threshold you set, it is one of the most effective safeguards, because a fraud then has to deceive two people at once rather than one. Most cloud accounting and banking systems support it at no extra cost.
Key takeaways
- These frauds are built to look ordinary. They attack your trust and your helpfulness, not your passwords.
- One rule prevents most of them: no change of bank details, and no unusual payment, without a call-back to a number you already hold.
- Add dual authorisation on larger payments, and if money does go, contact your bank within the hour.
ABOUT THE AUTHOR
Donovan Crutchfield, ACA, is Area Managing Partner at Xeinadin Richmond. He advises owner-managed businesses across Richmond upon Thames, Twickenham, Kingston and the wider South West London and Surrey area, helping them put practical financial controls in place without drowning the business in process. Connect with Donovan on LinkedIn.
This case study is a composite, drawn from situations we see regularly across the area. It does not describe a single identifiable client, and any resemblance to a particular person or business is coincidental. It is general information, not advice for your circumstances, and it is not a security or legal opinion. Reimbursement rules and thresholds change and depend on the detail of each case, so they should be confirmed as current before you rely on them. For guidance tailored to you, please speak to us directly.



