The Payment That Nearly Went Out: A Richmond Company and a Supplier Who Wasn’t

The Payment That Nearly Went Out: A Richmond Company and a Supplier Who Wasn’t - Xeinadin Richmond case study

Date:

Location:
Richmond

Share this article:

An email, a plausible reason, and a familiar voice on the phone. A Richmond finance team came within one click of paying £38,000 to a criminal.

At a glance

How do I stop my business paying a fake invoice?

The single most effective step is a firm rule: never change a supplier’s bank details, or make an unusual payment, on the strength of the message that requested it. Verify independently by calling a number you already hold, not one from the email or the call. Then add a second approver for larger payments, so no one person can release funds alone. Most invoice fraud is defeated by that pair of habits.

It is fraud where you are tricked into authorising a payment yourself, believing you are paying a genuine supplier, customer or colleague. Because you approved it, it behaves differently from a stolen card, which is why the reimbursement rules matter and why prevention rests on your own checks rather than the bank’s.

Yes, and increasingly so. Smaller firms are attractive precisely because they often lack layered controls, and a single person can usually release a payment alone. The techniques once reserved for large targets are now used routinely against businesses of every size.

Those are the essentials. How close a Richmond finance team came to losing £38,000, and what stopped them, shows why the rule matters more than the sharpest eye.

Why these get through

The instinct afterwards is to assume the victim was careless. Almost always, they were not.

These frauds succeed because they do not look like fraud. There is no misspelled link, no obvious threat, none of the tell-tales that awareness training taught everyone to spot. Instead there is a reasonable request, from a known contact, arriving at a moment when a payment to that very supplier is genuinely due. The criminal has often been reading the email traffic quietly for weeks, which is how the timing lands so well. What is being attacked is not your password. It is your trust, and your understandable wish to be helpful and prompt.

Urgency is the other lever. A reason to act today, a note that the supplier is chasing, a hint that a delay would be embarrassing, all of it is designed to move you past the pause where a check would happen. Once you understand that urgency is the weapon, a small piece of the defence is already in place.

The bank-detail switch

The single most common move is the one in our scenario: a request to change the account a regular payment goes to. It is effective because it does not ask for anything unusual on the surface. Suppliers do change banks. Details do get updated. The fraud hides inside a routine event.

This is why the safest rule is also the simplest. A change of bank details is never actioned on the strength of the message that requested it. Not the email, not the letter, not the call. The request and the verification must travel down two different roads, so that a criminal who controls one road still cannot complete the con.

A familiar voice is no longer proof

The follow-up call used to be reassuring. It is now part of the toolkit. Voice cloning has reached the point where a short clip of someone speaking, easily lifted from a video call or a public talk, is enough to generate a convincing imitation. Video can be faked too.

The most widely reported case involved a multinational engineering firm whose finance employee joined a video call with what appeared to be several senior colleagues, all of them synthetic, and authorised transfers of around £20 million. The scale is unusual. The technique is not, and it is steadily working its way down to businesses of every size. The lesson for a Richmond company with a lean finance team is not to be frightened of the technology, but to stop treating a recognised voice or face as sufficient authority to move money. It no longer is.

The controls that actually work

None of the defences here is expensive or clever. They are habits, applied consistently, and consistency is what defeats a con that relies on a single unguarded moment.

Underneath the table sits one structural safeguard worth building in: dual authorisation on payments above a threshold you set. When two people must release a payment, the fraud has to deceive both at once, which is far harder. Good cloud accounting and payment systems support this natively, and it costs nothing but a moment of discipline.

If the money has already gone

Speed matters more than anything else in the first hour. Contact your bank immediately and ask them to attempt a recall, because funds can sometimes be frozen before they are moved on. Report the matter to Action Fraud, and preserve every email, message and note while it is fresh.

There is more protection than there used to be. Under the mandatory reimbursement rules that took effect in October 2024, many victims of authorised push payment fraud can claim their money back where the payment was made through Faster Payments or CHAPS between UK accounts. The scheme covers individuals and, importantly, micro-enterprises and small charities, up to a cap per claim, currently £85,000. It does not cover international payments. None of this is a substitute for prevention, and reimbursement is never guaranteed, but it means a business that acts quickly and in good faith is not always left to absorb the whole loss.

Building the habit before it is tested

The Richmond company did not pay the £38,000. The bookkeeper, uneasy about changing details on the strength of an email, rang the supplier on the number from an old invoice. The real supplier had not moved banks and knew nothing about it. The near miss became the reason the firm finally wrote its payment controls down, so that the next time, and there is usually a next time, the safe response did not depend on one person’s good instinct on a busy afternoon.

That is the through-line of so many of these situations, and of others that look quite different on the surface. In our case study on how a Kingston engineering firm discovered its loan account problem at year end, and again in the one on two restaurant sites and one hidden loss, a profitable business was caught out by something nobody had made anyone responsible for watching. Controls are simply the act of deciding, in advance and in calm, who watches what.

If your payment process still rests on trust and memory, it is worth putting something firmer in place before it is tested. Our financial control and outsourcing and business advice teams help owner-managed businesses across Richmond and Surrey design controls that are strong enough to matter and light enough to actually be followed.

You cannot reliably tell from the email itself, because convincing fakes copy logos, signatures and writing style. The only dependable test is to verify through a separate channel, by calling the supplier on a number you already have on file, never one supplied in the request.

Possibly. Contact your bank at once to attempt a recall. Under the reimbursement rules introduced in October 2024, many victims, including micro-enterprises, can reclaim losses on UK Faster Payments or CHAPS transfers up to a cap. It is not guaranteed and does not cover international payments, so acting fast and in good faith is essential.

Dual authorisation means two people must approve a payment before it is released. For anything above a threshold you set, it is one of the most effective safeguards, because a fraud then has to deceive two people at once rather than one. Most cloud accounting and banking systems support it at no extra cost.

Key takeaways

This case study is a composite, drawn from situations we see regularly across the area. It does not describe a single identifiable client, and any resemblance to a particular person or business is coincidental. It is general information, not advice for your circumstances, and it is not a security or legal opinion. Reimbursement rules and thresholds change and depend on the detail of each case, so they should be confirmed as current before you rely on them. For guidance tailored to you, please speak to us directly.

Name

Subtitle
Developer
Location
They are focussed on creating a future-focused and relationship-driven culture, that keeps its promises to you, our team members, and partners.
Xeinadin