PROTECT · FRAUD & PAYMENT REQUESTS

Fraud & Payment Requests — Would Your Business Spot a Fake Request?

The most dangerous fraudulent request may not look suspicious. It may look exactly like the kind of request your business handles every day.

Fraud can exploit normal business behaviour

Businesses expect invoices, payment requests, bank-detail changes and urgent messages from colleagues and suppliers. Criminals can exploit those familiar processes by impersonating somebody trusted or taking over a genuine account.

The technology matters, but so does the decision process around moving money.

Urgency changes how people think

A request may claim that a payment is overdue, a deal will be lost or a senior person needs immediate action. Urgency can encourage people to skip the checks they would normally make.

A good process makes important verification normal even when somebody is in a hurry.

Bank-detail changes deserve an independent check

If a supplier appears to change payment details, verify the change using contact information the business already trusts. Do not rely solely on the email or document that requested the change.

The same principle applies to unusual payments, unexpected refunds and requests from senior staff that fall outside normal practice.

Separate request from approval where practical

For higher-value or unusual payments, a second person or approval step can prevent one compromised account or one moment of pressure becoming a financial loss.

The process should be proportionate to the size and nature of the business. The goal is not bureaucracy; it is making consequential decisions harder to manipulate.

BOI ACTION

Define your verification rule for changed bank details.

Write one sentence that everyone handling payments can follow, for example: “We independently verify any change to supplier payment details using contact information we already trust before making a payment.”

Then make sure the people who need the rule know it.

A useful question for the business

What is the largest payment one convincing email could cause us to make without an independent check?

Don’t assume. Check.

Familiar names, genuine-looking invoices and existing email conversations can all be manipulated. Verify the change or unusual request, not merely the appearance of the message.

NOT SURE WHERE TO START?

Take the 15-Minute Business Security Check

Ten straightforward questions will help you identify three priorities for sensible action.

Start the free Security Check →

Useful guidance

Final publication QA will verify current UK-first fraud, phishing and payment-security guidance and supporting authoritative sources.

Continue exploring

Even good controls sometimes fail. The next question is what the business does when something goes wrong.

Explore the Cyber Security Guides →


Found something that may be outdated or incorrect? Let us know.

Better Decisions. Stronger Organisations.

Understand what matters. Take sensible action. Check whether it worked.