An email lands on a Thursday afternoon. It’s from the accounts address at your groundworks subcontractor — the same address you’ve used for three years, sitting at the bottom of a thread you started yourself. Same signature. The invoice you were expecting is attached, for the sum you were expecting. One line has been added near the top: they’ve changed banks, and here are the new details.
Your payment run goes out on Friday.
What this actually is
The banks have a name for it: an invoice and mandate scam. A mandate, in this sense, is just the standing instruction about where a supplier’s money goes. The fraud is changing it. You haven’t been hacked. More often the subcontractor has — somebody gets into their email, reads a few months of it to learn who owes them what and when, and then sends one message that is entirely genuine apart from eight digits.
UK Finance, the trade body the banks report their fraud figures to, counted £41.3 million lost to invoice and mandate scams across the UK last year, across 2,305 cases. Two thousand cases sounds like somebody else’s problem until you look at where the money went missing from. £28 million of it left business accounts.
The part most people have wrong
Nearly everyone has absorbed, vaguely, that banks now have to refund people who get scammed. That did happen. In October 2024 the Payment Systems Regulator — the body that regulates the plumbing of UK payments — made reimbursement compulsory for what’s called authorised push payment fraud. “Authorised” is the load-bearing word. Nobody broke into your account; you pushed the money out yourself, because you were lied to. Up to £85,000 a claim, paid within five working days.
It does not cover your business.
The rules protect consumers, small charities and micro-enterprises. A micro-enterprise, under the definition being used, is a business with fewer than ten employees and turnover or a balance sheet under two million euros. Both conditions, not either. Turn over eight million with sixty on the books and you are outside the scheme completely. Whether you see that money again comes down to your bank’s goodwill and how quickly the receiving account was frozen.
The figures show what that gap is worth. Of the money individuals lost to this fraud last year, roughly seven pounds in every ten came back. Of the money businesses lost, under four.
Why construction is soft for this
Partly the sums. A fraudulent £60,000 payment doesn’t look odd leaving a contractor’s account, because £60,000 payments leave it every month. Partly the churn — you pay firms you’ve never paid before all the time, and a new supplier with unfamiliar details is the most ordinary thing in the world.
And partly because subbies genuinely do change bank accounts. A restructure into a new limited company. A move to invoice factoring, where a finance firm buys the unpaid invoice and wants paying direct. It happens often enough that the request doesn’t raise an eyebrow, which is precisely what the fraudster is counting on.
Then there’s the shape of the office. In most firms I audit, the supplier record sits in the accounts package, anyone with a login can edit the bank fields, and the software keeps no record of who changed what or when. The payment run is prepared by one person, against a deadline, on their own.
The name check that isn’t there
You may be leaning on Confirmation of Payee without having thought about it. That’s the check your banking screen does when you set up a new payee: it compares the name you’ve typed against the name actually registered on the account and tells you whether they match. It’s a good service and it has stopped a lot of money walking out of the door.
It has a gap that matters to you. It runs on the systems that move payments one at a time — Faster Payments, CHAPS, standing orders. Bacs, the batch system most firms use to pay everybody at once on the same day, isn’t part of the standard service. So the single payment you type in by hand gets a name check, and the file containing forty subcontractors doesn’t.
Which is the wrong way round, given where your money actually is.
What a fix looks like
Not a fraud platform. This is a process problem wearing a small software shape.
Treat a change of bank details as an event rather than an edit. The bank fields on a supplier record get locked. Anyone can request a change, but the request lands in a queue instead of the ledger. Somebody other than the person who received the email has to verify it — by ringing the supplier on a number already held on file, never the number in the email or printed on the new invoice — and record who they spoke to and when. Only then does the record move, and the old details stay visible underneath it. And the payment run refuses, without a second signature, to include any supplier whose details changed in the last fortnight.
That’s a few days of work sitting on top of whatever you already run. There’s nothing clever in it. The whole value is that it matches the way your office genuinely moves money, and that it can’t be quietly skipped at four o’clock on a Friday.
Where this doesn’t apply
If you pay a dozen suppliers a month and the MD looks at every one before it goes, you already have the control. Putting software around that would make it worse.
If you run a proper finance system with supplier approval built in — two people needed to change a bank account, every change logged — then you don’t need anything built either. You need it switched on, and you need to check nobody turned it off because it was holding up the payment run. That’s a half-day conversation with whoever supports the system, not a project.
And none of this makes you safe. Someone who has been reading your subcontractor’s email for two months will talk his way past a phone call, particularly if the number came from him. The aim is narrower than safety. Make the change slow, make it visible, and make sure the person who moves the money isn’t the same person who was asked to move it.
If you want a look at where your supplier details live and who can change them, get in touch.