Cyber security

Business Email Compromise and Payment Diversion Fraud: A UK Guide

All business email compromise (BEC) needs is one email account a criminal can use, or one that looks enough like a real one, and someone busy enough to act on a convincing message without checking.

The goal is almost always money. A supplier’s invoice arrives with “updated” bank details. A client is told, the day before completion, that the account for their deposit has changed. Someone in finance gets an urgent request from the managing director, who is apparently in a meeting and can’t talk.

How business email compromise works

There are three common ways in.

A real mailbox, taken over. Often, someone signs in to a fake Microsoft 365 page and the criminal takes over their mailbox. They read quietly for days or weeks, learning who pays whom and when, and set up rules that hide replies from the real owner. Then they send the payment request from the genuine address, often in reply to a real conversation. Our post on fake Microsoft 365 sign-in pages explains how that first step happens.

A lookalike address. The criminal registers a domain one letter different from your supplier’s, or uses a free email account with the right display name, and sends the request from that.

Your own domain, spoofed. If your domain doesn’t have SPF, DKIM and DMARC set up and enforced, criminals can send email that appears to come from your address, to your clients and suppliers. Our free email security check shows what your SPF and DMARC records say.

What it costs UK businesses

UK Finance’s Annual Fraud Report 2026 recorded £41.3 million lost to invoice and mandate fraud in 2025, across 2,305 cases, with 68% of the losses (£28 million) from business accounts. CEO fraud, where the criminal poses as a senior manager, accounted for a further £5.6 million across 197 cases.

Those figures only count cases reported through the banks. In the government’s Cyber Security Breaches Survey 2025/2026, 12% of businesses said someone had impersonated their organisation by email or online in the previous year.

Payment diversion on property completions

Solicitors are a natural target, because a completion is a large, time-critical payment arranged by email. The criminal watches a compromised mailbox, the solicitor’s or the client’s, and at the right moment sends the buyer new bank details.

The Law Society’s advice, written with the SRA and the National Crime Agency, is to check by calling before you transfer money, on the firm’s published number rather than one in an email. It points out that law firms rarely change their bank details, and suggests sending a small test sum first. Firms should tell clients at the start of every matter that they will never change bank details by email. Until 14 January 2027, the Law Society is also consulting on an updated Conveyancing Protocol with stronger guidance on cyber security and fraud, and the SRA publishes scam alerts about firms being impersonated.

Our page on IT support for solicitors covers the controls we put in place for law firms.

How to stop it

Start with process:

  • One rule for bank details. Nobody changes a supplier’s or client’s bank details, or makes an unusual payment, because an email says so. The NCSC recommends verifying important email requests using a second type of communication.
  • Call back on a number you already hold, from your records or the company’s website, never one in the message.
  • Two people for payments: one sets up or changes a payee, another approves it.
  • Tell your clients and suppliers how you’ll contact them about payments, and that you’ll never change your bank details by email.

Then the technology:

  • Protect your domain with SPF, DKIM and DMARC. Bulk senders already have to publish these for Google and Yahoo, and Microsoft has rejected non-compliant mail to Outlook.com from high-volume senders since May 2025. Setting DMARC to enforce goes further and stops criminals sending as your domain.
  • Protect every mailbox with multi-factor authentication, ideally passkeys or another phishing-resistant method.
  • Watch for the signs of a takeover: new forwarding or deletion rules, sign-ins from unusual places, and sent messages the owner didn’t write.
  • Train your team to treat any request involving money and urgency as a reason to slow down. Our guide to phishing and email scams has five checks to run on any email asking for money.

If it happens

The NCSC’s advice on business payment fraud is to act immediately:

  1. Call your bank on the number on its website or your card, and ask it to stop or recover the payment. Time matters.
  2. Tell whoever runs your IT. If the request came from a real mailbox, that account needs securing, and other contacts may have been sent the same message.
  3. Report it to Report Fraud (reportfraud.police.uk or 0300 123 2040), or Police Scotland on 101 in Scotland.
  4. Warn the people affected: the supplier or client being impersonated, and anyone else who may have received the same request.

If your business is a micro-enterprise, the mandatory reimbursement rules for authorised push payment fraud may cover you, up to £85,000. Larger businesses aren’t covered, although banks can still try to get money back: UK Finance says 48% of invoice and mandate fraud losses were returned to victims in 2025. If a compromised mailbox held personal data, you may also need to report a data breach within 72 hours; our guide to UK GDPR explains when.

Questions people ask

What is business email compromise?

A fraud where criminals use a compromised or lookalike email account to impersonate someone you trust, such as a supplier, a client or your managing director, and persuade you to pay money or send information. Payment diversion and CEO fraud are the most common forms.

What is payment diversion fraud?

Where a criminal persuades you, or your client, to pay into their bank account instead of the right one, usually with an email saying the bank details have changed. UK Finance calls it invoice and mandate fraud.

How do we stop payment diversion fraud?

Make it a rule that bank details are never changed on the strength of an email. Confirm any change by phone, on a number you already hold rather than one in the message, and have a second person approve it. Protect your own domain with SPF, DKIM and DMARC, and every mailbox with multi-factor authentication.

What should we do if we’ve paid a fraudster?

Call your bank straight away, on the number on its website or your card, and ask it to try to stop or recover the payment. Tell whoever runs your IT, because a mailbox may have been compromised. Then report it to Report Fraud, or Police Scotland on 101 in Scotland.

Will the bank refund a business that pays a fraudster?

Micro-enterprises, charities and individuals are covered by the mandatory reimbursement rules for authorised push payment fraud, up to £85,000. Larger businesses aren’t, though banks can still try to recover the money; UK Finance says 48% of invoice and mandate fraud losses were returned to victims in 2025.

Sources

More on cyber security

All cyber security articles