Earlier this year, a UK energy company paid a routine supplier invoice as normal, except the bank details on it had been quietly changed by a fraudster who’d got into the loop. £700,000 went straight to the criminal’s account instead of the supplier’s. No malware, no hacked network, no dramatic breach headline. Just a well-timed message that looked exactly like the kind of thing an accounts team processes every day without a second thought.

That case isn’t an outlier. Invoice and mandate fraud now accounts for roughly 55% of all fraud reported in the UK, and figures released this year show over £41 million lost across just over 2,300 cases in 2025 alone. It’s become the default way criminals target businesses, precisely because it doesn’t require breaking into anything. It only requires one person in your accounts process to trust an email that looks right.

Why this keeps working

There are three flavours of this scam, and it’s worth knowing all three. Fake invoice fraud is a bill from a supplier you’ve never actually dealt with, often copying real branding closely enough to pass a quick glance. Mandate fraud is a criminal posing as a genuine supplier and asking you to update their bank details before the next payment. Invoice interception is the most convincing version: a fraudster has actually compromised a real supplier’s email account, and intercepts or amends a real, expected invoice with new payment details. In all three cases, the request looks routine, arrives at a plausible moment, and asks for something your team is used to doing without escalation.

What makes this particular type of fraud so effective is timing. Criminals increasingly watch for the moments when a genuine payment is already expected, such as around a known invoice date, the end of a project, or shortly after a real email thread about an upcoming payment. The fraudulent message doesn’t have to invent a reason to pay. It just has to slot into a conversation that was already happening, which is exactly why a message that would look obviously wrong on any other day can sail straight through on the right one.

How to make this harder to pull off

Never change payment details on a phone call or email alone. Any request to update a supplier’s bank account, however official it looks, should trigger a callback to a number you already have on file, not one provided in the message. This single habit stops the majority of mandate fraud cold.

Separate who can request a change from who can approve a payment. If the same person can both action a bank detail change and release the payment, you have no check in the system at all. Even a small business can split this across two people.

Put it in writing, not just in your head. A short internal policy that says “we always verify bank detail changes by phone before paying” gives your team permission to slow down and check, even when the email creates pressure to move fast. Smallprint has plain-English templates that can help you formalise supplier verification and payment procedures without needing to draft them from scratch.

Know what to do if it happens anyway. If you do pay a fraudulent invoice, speed matters. Contact your bank immediately to attempt a recall, and report it to Action Fraud. If the fraud came through a compromised supplier account rather than your own systems, understanding your own notification obligations matters too, particularly if any personal data was involved.

Train the team who actually process payments, not just the leadership. Whoever reads incoming invoices and approves changes day to day is your real front line here, and they’re often the least likely to have had any specific training on what to look for. A short, practical briefing on these three fraud types, refreshed periodically, costs almost nothing next to the average loss.

The takeaway

This is one of the least technical frauds out there, and one of the most expensive. A single phone call to a known number, before you act on any changed bank details, is the cheapest insurance policy your accounts team will ever use.