Security

Your supplier's bank details have changed. The call nobody makes

Outline icons of a paper invoice, two envelopes with one tilted open and a sheet emerging from it, an old desk telephone and an open padlock on the left, leading to a cable-stayed bridge.

A supplier you have used for six years emails to say their bank details have changed. Same signature, same tone, same person who rang you about a delivery in March. The invoice is for the amount you were expecting. Your bookkeeper pays it on the Friday.

That is the scam that empties small business accounts in this country. No voice clone, no deepfake video call, no artificial intelligence in the part that matters. Just a compromised mailbox and a bank detail nobody rang to check.

The rule that stops it

Here is the whole defence. Copy it, put your business name on it, give it to whoever pays your bills.

No change to any supplier's bank details is paid until someone has rung the number we already hold on file and spoken to a person they can name. This applies to requests that appear to come from me.

That last sentence is the one that matters. The version of this scam that works best is the one where the owner appears to be demanding an urgent payment, so a rule the owner is exempt from is not a rule. It also protects your staff, because it removes any need for them to be brave with someone impatient on the phone.

The rest of this article is why that paragraph is worth more than anything you could buy.

What the numbers actually say

UK Finance publishes an annual fraud report built from data submitted by the firms listed as contributing to it. The 2026 edition covers calendar year 2025. It is the closest thing this country has to a scoreboard.

In 2025, £1.28 billion was stolen through payment fraud. Of that, £576.4 million came from people being tricked into sending money themselves.

Now the part nobody quotes. CEO fraud, the scam a voice clone is built for, accounted for 197 confirmed cases in the entire United Kingdom. That is 197 out of 248,070 authorised push payment cases of every kind, so one in roughly twelve hundred. UK Finance records 197 as the lowest case total it has ever published, though its comparable data only begins in 2020, so read "ever" as "in six years". Losses came to £5.6 million, which is the lowest since 2020 rather than the lowest outright, because 2020 itself was lower at £4.8 million. Invoice and mandate fraud, the supplier scam I opened with, also fell, to its own lowest recorded level on both measures.

What rose were the ordinary scams. Purchase fraud, where you pay for goods that never arrive, hit its highest recorded level. So did investment fraud, advance fee fraud and romance fraud. None of those needs a convincing clone of anybody. They need a plausible advert and a payment made in a hurry.

The one figure aimed squarely at you: 68 percent of invoice and mandate losses, about £28 million, landed on business accounts rather than personal ones. UK Finance's explanation is short and correct. Businesses make genuine high value payments regularly, which makes a fraudulent one harder to spot.

The bit the vendors leave out

Artificial intelligence appears in that report almost nowhere. Where it does appear, it is inside a guest foreword written by people who sell fraud detection software. UK Finance's own data chapters, the scam by scam breakdown, the methodology, do not discuss it.

I want to be careful about what that proves, because it is easy to overreach here and I nearly did. It does not prove AI fraud is not happening. The report's eight scam categories have no box for it. A voice cloned supplier call gets recorded as invoice and mandate fraud. A cloned boss gets recorded as CEO fraud. The dataset cannot separate the two by design. The absence tells you about the reporting template, not about prevalence.

What it does tell you is that nobody is currently counting it. So when you see a figure claiming AI scams rose by some enormous percentage last year, ask who counted, over what period, against what baseline. In the cases I chased for this article, the number came from a company selling detection software. That does not make it wrong. It does mean a supplier of umbrellas is not a neutral source on rainfall.

Voice cloning is rare, which is not the same as ignorable

Cloning a voice convincingly no longer needs a studio or hours of recording. The raw material is already public, in a video on your website or a voicemail greeting.

The honest framing is rare but catastrophic. CEO fraud carries the highest average loss of all eight scam types, just over £28,000 per confirmed case. Only 20 percent of those losses were returned to victims. For a firm turning over £150,000, one hit like that is not a bad quarter, it is the business.

You do not rebuild around a risk like that. You put in the one control that neutralises it. A cloned voice defeats your ear. It does not defeat a call back to a number the criminal did not supply.

The newer trick and what stands up

In December 2025 an AI security firm, Aurascape, published research on criminals poisoning what chatbots say. The method is to seed content across sites an assistant trusts, compromised university and government pages, YouTube descriptions, review sites, formatted in the question and answer shape these systems like to quote. Ask a chatbot for a company's support number and the poisoned entry is what comes back. Gizmodo reported that Google's AI Overviews returned fraudulent numbers presented as official airline support.

Three caveats I would want if I were reading this. Aurascape sells security software. The documented campaign was about airline and travel bookings, with American phone numbers, not British suppliers or bank details. And the model itself is not corrupted, the poisoned page is simply retrieved and repeated.

The practical lesson survives all three. A phone number or a bank detail that reaches you through a chatbot has exactly the standing of one in a search advert, which is none. Go to the company's own site.

Two more habits, then stop

Use the number you already have, never the one in the message. Every version of this, the cloned voice, the spoofed email, the poisoned chatbot answer, depends on you using contact details the criminal chose. Keep supplier bank details and phone numbers in one place that is not your inbox. A spreadsheet, the supplier record in your accounts software, a card index if you like. It matters only that there is one of them and everyone knows which.

Let somebody watch a payment go out. The National Cyber Security Centre makes this point in its guidance for small organisations, that staff should know the normal way key tasks are done so an unusual request stands out. Someone who has never seen a supplier payment processed has no baseline to be suspicious against. Next time one goes through, have the person who does not usually do it stand there. It takes ten minutes and it is the cheapest training in this article.

If it happens anyway, claim

Do not write the money off on your own authority, which is advice I nearly got wrong.

Since October 2024 there has been mandatory reimbursement for this type of fraud. It covers personal, micro business and charity accounts. If you employ fewer than ten people you are very likely inside it. It applies to payments authorised and received in the UK, up to £85,000. You have thirteen months to claim. For invoice and mandate fraud specifically, 48 percent of losses were returned to victims in 2025. Across authorised push payment fraud of every kind it was £354.3 million out of £576.4 million.

So roughly half of it comes back, which is better than the horror stories suggest. None of it comes back if you do not ask. Report it to your bank immediately, then to Action Fraud. Then claim. The thirteen months is the number to write down.

What I would not spend money on

There is a market forming in deepfake detection aimed at small businesses. I would leave it for now. You should know I have an interest in saying so, because the work I sell sits in the same budget.

The reason is proportion. You would be buying a screening layer for the rarest attack while the common one stays open. A burglar alarm in the loft while the back door stands unlocked.

The thing underneath is usually duller. Supplier records living in six places with nobody certain which is current. That is not a security problem, it is a process problem. It is the same one costing you hours every month in ordinary admin. The method for finding it is in the bottleneck audit. Getting your team confident about what normal looks like is what AI training for your team is for.

Where to start this week

Pick your three largest suppliers by value. Find the bank details you currently pay. Confirm each one by ringing the number you have held longest, not the number on the most recent invoice.

Then write the rule at the top of this page into a document and send it to whoever pays your bills.

If you want a second pair of eyes on where your business is actually exposed, rather than where a vendor says it is, the automation side of what we do tends to start in the same place, with the admin nobody has examined in years. The first conversation is free and there is no pitch attached to it.

The three calls will take an hour. All three will feel unnecessary, right up until the day one of them is not.

The first conversation is free.

No pitch, no obligation. We will look at where your hours actually go, then tell you honestly what is worth automating and what is not. If you do not need us, you will hear that too.

Book a consultation