If your business is being impersonated right now, act in this order: freeze outgoing payments to any recently changed bank details, lock and re-credential the affected accounts, preserve every message as evidence, then report the fraud to your bank and Action Fraud the same day. Speed matters more than certainty: Faster Payments settle in seconds, so the recall window is measured in hours, not days.
A company impersonation scam is when criminals pose as your business — or as one of your suppliers, directors, or banks — to extract payments, credentials, or credit in your name. The exposure is substantial and growing. UK Finance reports that criminals stole £1.28 billion through fraud in 2025, with authorised push payment (APP) losses reaching £576.4 million across 248,070 cases. The Home Office puts the cost of fraud to UK businesses at £5.2 billion in the year ending March 2024, and fraud now accounts for 45% of all recorded crime in England and Wales.
Impersonation only works when nobody verifies who actually owns the bank account receiving the money. That verification gap is exactly what automated vendor identity verification closes, by confirming account ownership and legal entity before a payment leaves your systems rather than after. This guide covers the first 24 hours, the reporting channels that matter in the UK, and the controls that stop the next attempt.
Key Takeaways
- Contain first, investigate second: stop pending payments, lock compromised accounts, enable MFA, and appoint one incident owner before you start diagnosing.
- Report to your bank, Action Fraud (0300 123 2040) and Companies House — and to the FCA if the impersonator is posing as an authorised firm. In Scotland, report to Police Scotland on 101.
- The PSR’s APP reimbursement rules do not protect most corporates. Mandatory reimbursement up to £85,000 covers consumers, micro-enterprises and small charities only, so a mid-sized or large business carries the loss itself.
- The highest-yield red flag is any request to change supplier or payroll bank details — what Action Fraud classifies as mandate fraud, which hit 7% of UK businesses in a single year.
- The failure to prevent fraud offence under ECCTA has been in force since 1 September 2025. Large organisations need demonstrable, reasonable fraud prevention procedures as a statutory defence — manual controls alone are hard to evidence.
What Should You Do First If Your Company Is Being Impersonated?
Contain the damage in the first hour, then build the evidence file. Work through these seven steps in sequence — resist the urge to investigate before you’ve stopped the bleeding.
- Freeze every payment tied to changed details. Halt outgoing CHAPS, Faster Payments and Bacs runs, plus any scheduled payments, to accounts whose details were modified in the last 90 days. If a payment has already left, telephone your bank immediately and ask them to attempt recall and contact the beneficiary bank.
- Isolate the affected accounts. Disconnect compromised mailboxes, ERP logins and accounts payable sessions. Don’t delete anything — isolate it.
- Reset credentials and enforce MFA. Rotate passwords for every account the attacker could have touched, revoke active sessions and app tokens, and switch on multi-factor authentication across finance, email and administrator accounts.
- Appoint a single incident owner. One named person coordinates the response and owns all external communication. Parallel, uncoordinated outreach is how organisations contradict themselves in front of customers and regulators.
- Build a timestamped evidence file. Export original emails with full headers, screenshots of spoofed domains or social profiles, invoice copies, payment confirmations and a chronological timeline. Save messages as .eml or .msg files — forwarding destroys the headers investigators need.
- Notify your bank through a verified channel. Ring the number printed on your bank statement or in your corporate banking portal, never a number supplied in the suspicious message. Ask them to flag the beneficiary account, apply enhanced monitoring, and confirm whether any other payment instructions were altered.
- Warn the people who could be defrauded next. Alert customers, suppliers and partners that your identity is being misused, and tell them precisely which channels are legitimate.
Steps 5 to 7 run in parallel once containment is complete. If the impersonation involved a compromised mailbox rather than a lookalike domain, treat it as a full security incident — attackers frequently sit inside an inbox for weeks, studying invoice formats and payment cycles, before they act. If personal data was accessed, remember the UK GDPR clock: reportable breaches must reach the ICO within 72 hours.
The First 24 Hours: Company Impersonation Response Timeline
| Window | Phase | Actions |
|---|---|---|
| Hour 0–1 | Contain | Freeze CHAPS, Faster Payments and Bacs runs; halt payments to changed details; isolate affected accounts |
| Hour 1–4 | Secure | Rotate credentials; enforce MFA everywhere; name one incident owner |
| Hour 4–24 | Report | Bank fraud team on a verified line; Action Fraud (0300 123 2040) or Police Scotland (101); ICO if personal data is involved |
| Day 2+ | Notify and monitor | Warn suppliers and customers; check Companies House filings; check business credit files; consider Cifas Protective Registration |
Recovery window: Faster Payments settle in seconds and funds are typically dispersed within hours, so recall odds fall sharply after the first 24–72 hours.
Where Do You Report a Company Impersonation Scam in the UK?
Report to your bank first, then Action Fraud, then Companies House if your filings have been touched. Each channel serves a different purpose, and filing with all of them strengthens both recovery odds and any future insurance claim.
| Channel | What it’s for | Where |
|---|---|---|
| Your bank’s fraud team | Payment recall, beneficiary account freeze | Number on your statement or corporate banking portal |
| Action Fraud | National fraud and cybercrime reporting for England, Wales and Northern Ireland | actionfraud.police.uk · 0300 123 2040 |
| Police Scotland | Fraud reporting in Scotland (Action Fraud does not cover Scotland) | 101 |
| Companies House | Fraudulent filings, unauthorised director, address or registered office changes | Companies House online reporting |
| FCA | Someone impersonating an FCA-authorised firm (a “clone firm”) | fca.org.uk |
| NCSC Suspicious Email Reporting Service | Phishing and spoofed-site takedowns | report@phishing.gov.uk |
| ICO | Notifiable personal data breach, within 72 hours | ico.org.uk |
| Cifas | Protective Registration against further applications in your name | cifas.org.uk |
| Credit reference agencies | Dispute fraudulent applications, accounts or searches | Experian, Equifax, TransUnion, Creditsafe, Dun & Bradstreet UK |
Three practical notes. First, an Action Fraud report generates a crime reference number, which your insurer and often your bank will ask for — file it even when recovery looks unlikely. Second, if fraudulent documents have been filed at Companies House, report the specific filings rather than the company in general, and download copies of the filed forms as evidence before anything is amended. Third, notify your insurer early: most crime and cyber policies impose reporting deadlines and require a crime reference number before they will open a claim.
The Scale of the Problem in the UK
| Measure | Figure | Source |
|---|---|---|
| Total fraud losses, 2025 | £1.28 billion | UK Finance |
| APP fraud losses, 2025 | £576.4 million across 248,070 cases | UK Finance |
| Cost of fraud to UK businesses (year ending March 2024) | £5.2 billion | Home Office |
| UK businesses experiencing fraud in 12 months | 27% | Economic Crime Survey 2024 |
| Businesses hit by fake invoice fraud | 11% | Economic Crime Survey 2024 |
| Businesses hit by mandate fraud | 7% | Economic Crime Survey 2024 |
| Fraud as a share of all crime in England and Wales | 45% | ONS, year ending September 2025 |
What Is a Business Impersonation Scam?
A business impersonation scam is any fraud in which criminals adopt a company’s identity — its name, domain, branding, directors or banking relationship — to deceive a third party into sending money or data. The impersonated business may be the victim, the vehicle, or both.
Business impersonation scams pursue one of four objectives:
- Redirected payments: invoices or bank-detail change requests that route funds to the fraudster’s account. This is the dominant motive — Action Fraud calls it mandate fraud — and it maps directly onto the top vendor fraud schemes targeting UK finance teams.
- Credential theft: harvesting logins to email, banking portals or ERP systems for a larger follow-up attack.
- Credit and account fraud: opening trade accounts, credit facilities, leases or business bank accounts in the company’s name.
- Data extraction: stealing sensitive company information — payroll records, customer lists, supplier master files — to sell or reuse in a later attack.
Typical outcomes include irrecoverable payment losses, chargeback and refund liability, damaged commercial credit, and regulatory scrutiny. The hidden cost is operational: after an incident, organisations spend weeks of senior finance and IT capacity on forensics, bank correspondence and filing corrections.
Small and mid-sized businesses are disproportionately targeted for structural reasons, not because criminals prefer them: they publish the same Companies House data as large firms but have fewer approval layers, rarely have a dedicated fraud function, often run a single shared accounts payable inbox, and are more likely to have one person able to both change a supplier record and release a payment.
How Is Business Identity Theft Different From Personal Identity Theft?
Business identity theft targets an entity’s commercial identity and credit, and it unwinds far more slowly than personal identity theft — not least because the UK’s mandatory reimbursement regime largely excludes corporates.
| Dimension | Personal identity theft | Business identity theft |
|---|---|---|
| Identifiers abused | National Insurance number, date of birth, driving licence | Company registration number, UTR, VAT number, director and PSC details |
| Public exposure | Mostly private data | Companies House registration, officers and registered office are public by design |
| Reimbursement rights | APP reimbursement up to £85,000 for consumers | Available only to micro-enterprises and small charities; larger businesses are out of scope |
| Typical loss size | Hundreds to thousands | Tens of thousands to millions |
| Recovery path | Bank claim, CRA dispute, Financial Ombudsman Service | Bank claim, litigation, Companies House filing corrections |
| Collateral damage | Personal credit file | Credit facilities, supplier terms, tender eligibility, brand trust |
The two crimes increasingly overlap. Criminals combine a director’s personal information — home address, date of birth, National Insurance number — with public Companies House filings to pass verification at banks and lenders, because the pairing looks far more convincing than either data set alone.
The reimbursement asymmetry is the point most finance teams miss. Since 7 October 2024, payment service providers must reimburse in-scope APP fraud victims up to £85,000, but that protection stops at consumers, micro-enterprises and small charities. If a £400,000 payment leaves a mid-sized manufacturer on fraudulent instructions, there is no statutory right to reimbursement. The loss is commercial, and the only reliable defence is preventing the payment in the first place.
Businesses also get less procedural help on the credit side. You must find the fraudulent entry yourself, dispute it in writing with the relevant credit reference agency, and prove it — optionally adding a notice of correction to the file. The consequences that hurt most are second-order: a fraudulent trade line can raise borrowing costs, shorten supplier terms, or disqualify you from a tender, often months later, when nobody connects the dots.
There is also a hybrid threat sitting between the two categories. Criminals build fabricated entities from a mix of real and fake identifiers, then cultivate them for months until they resemble established suppliers. This is synthetic identity fraud, and it is especially dangerous in procurement because roughly 95% of synthetic identities pass standard verification checks (Thomson Reuters). A supplier that clears your onboarding process is not necessarily a supplier that exists.
How Do Scammers Impersonate Your Business Identity?
Criminals impersonate businesses across every channel where trust is assumed rather than verified. Most attacks combine two or three of them.
Which Channels Do Impersonators Use?
- Email: lookalike domains, display-name spoofing and reply-chain hijacking. This is the dominant vector, and it is worth understanding exactly how email spoofing works before you design controls around it.
- Telephone and SMS: caller ID spoofing and smishing, often used to “confirm” a bank-detail change already sent by email.
- AI-generated audio and video: synthetic voice or video of a named director, used to authorise urgent transfers. Deepfake authorisation requests are now credible enough that “I heard the CFO say it” is no longer a control.
- Fake websites and portals: cloned checkout, careers or supplier onboarding pages built to capture credentials and sensitive company information.
- Social and marketplace profiles: counterfeit company pages and paid ads using your logo.
- Post and paper: forged letterhead for Companies House filings or credit applications.
How Do They Abuse Your Branding?
Spoofing methods are cheap and effective: registering a domain that swaps one character or changes the TLD, registering a company name that closely mimics yours, copying your email signature and logo lockup verbatim, cloning genuine invoice templates including PO number formats, and reusing real employee names and job titles scraped from LinkedIn. Without SPF, DKIM and DMARC enforcement on your domain, attackers can also send mail that appears to originate from your actual address.
Which Data Points Do Criminals Exploit?
- Your company registration number, VAT number and registered office, all publicly retrievable
- Director, PSC and registered office details from Companies House
- Supplier and customer names from press releases, case studies and job adverts
- Invoice numbering conventions and payment terms
- Approval thresholds and finance team structure inferred from org charts
Because Companies House data is public by design, reconnaissance requires no hacking at all. Note the inverse signal too: fake and synthetic entities are frequently registered to virtual mailboxes or serviced offices, so a registered office that resolves to a mail-forwarding service deserves closer scrutiny during supplier onboarding — especially for a company claiming years of trading history.
What Does the Scam Flow Look Like, Step by Step?
- Reconnaissance: the attacker maps your suppliers, finance staff and approval chain from public sources.
- Infrastructure: they register a lookalike domain or compromise a mailbox — yours or a supplier’s.
- Insertion: they join or replicate a live email thread, often after weeks of silent observation.
- The ask: a bank-detail change, an urgent overdue invoice, or a transfer “authorised” by a director whose voice or writing style has been cloned.
- The payment: funds land in a mule account and are dispersed within hours.
- The exit: the account closes before your reconciliation cycle surfaces the discrepancy.
The gap between step 5 and step 6 is why detection-based controls underperform. By the time a month-end reconciliation flags the anomaly, recovery is largely theoretical.
Why Detection-Based Controls Lose the Race
| Timeline | What the fraudster does | What an unprotected finance team sees |
|---|---|---|
| Weeks before | Reconnaissance, mailbox access, invoice pattern study | Nothing |
| Day 0 | Bank-detail change accepted, Faster Payment released | A routine payment run |
| Day 0–1 | Funds dispersed through mule accounts, account closed | Nothing |
| Day 1–3 | Already gone | Recovery window closing (24–72 hours) |
| Day 30 | Untraceable | Month-end reconciliation finally flags the discrepancy |
Detection gap: 27 days between the fraudster’s exit and the finance team’s discovery.
What Are the Red Flags in Your Records and Communications?
The single highest-value red flag is any inbound request to change bank details. Treat every one as a mandate fraud attempt until independently verified.
Invoice and payment discrepancies to flag:
- New or changed bank details, especially a sort code from a different bank or a switch to an overseas IBAN
- Invoice amounts just below an approval threshold
- Duplicate invoice numbers, or numbering that breaks the supplier’s usual sequence
- A supplier’s payment terms suddenly shortening, or “urgent overdue” framing on a current account
- A mismatch between the supplier’s registered name and the account holder name
- Free email domains replacing a corporate domain on correspondence
Unexpected changes at Companies House:
- A director appointment or termination you didn’t authorise
- Registered office or trading address changes you didn’t make
- New company names closely resembling yours
- Reinstatement of a dissolved company
- Unexplained searches or applications showing on your business credit file
Instruct staff to preserve evidence. Anyone receiving a suspicious message should save it as an attachment with full headers, screenshot the sender details, and forward it to the incident owner — without replying, clicking or deleting. Nine times out of ten, the quality of the evidence file determines whether the bank engages seriously. For the underlying patterns, learn how to detect and prevent invoice fraud, since most impersonation attempts arrive as a document your team already expects to receive.
How Should You Monitor Companies House and Credit Information?
Monitor quarterly at minimum, and treat monitoring as an early-warning system rather than a compliance chore. Fraudulent filings and credit applications typically precede the payment attack — catching them early is the difference between a nuisance and a loss.
How Do You Check Your Companies House Records?
Search the Companies House register by exact company name, then by director name to catch companies registered in your officers’ names. Set up free “follow this company” email alerts so every filing against your entity lands in an inbox you actually read. Register your company’s email address with Companies House, and ask about protected online filing options that block paper submission of key forms. Download copies of any filing you didn’t authorise before requesting a correction — once amended, the original is harder to produce as evidence.
Identity verification is now part of this picture. Since 18 November 2025, new directors and people with significant control must verify their identity with Companies House, and existing directors must complete verification by 18 November 2026. Treat the deadline as a control, not just an admin task: verified officer records make it materially harder for someone to appoint a fictitious director to your company.
Which Credit Reference Agencies Should You Monitor?
- Experian Business
- Equifax Business
- TransUnion
- Creditsafe
- Dun & Bradstreet UK
Pull your business credit report from each agency at least quarterly and review it line by line against your own records. Paid monitoring is worth the cost for one reason: it alerts you to new trade lines and searches in near real time, which is the only way to catch credit fraud before it matures. When an unexpected entry appears, record the date discovered, the reporting creditor, the amount and the account number; dispute it in writing; consider a notice of correction; and escalate to the incident owner so it is linked to any open case. Cifas Protective Registration adds a flag that requires extra checks on future applications made in your name.
What Should Long-Term Monitoring Look Like?
Maintain a standing incident log covering every impersonation attempt, successful or not — date, channel, target, amount at risk, outcome and controls changed as a result. It serves three purposes: it evidences reasonable procedures under the failure to prevent fraud offence, it reveals which suppliers or entities are repeatedly targeted, and it justifies control investment to your board and audit committee.
Business Impersonation Monitoring Cadence
| Frequency | Check | What it catches |
|---|---|---|
| Weekly (52× a year) | Payment file review | Bank-detail changes made in the last 7 days |
| Monthly (12× a year) | Supplier master audit | New suppliers, duplicate records, reactivated dormant accounts |
| Quarterly (4× a year) | Business credit files: Experian, Equifax, TransUnion, Creditsafe, D&B | New trade lines, unexplained searches, score movements |
| Continuous plus annual review | Companies House alerts and full register check | Director, registered office and company name changes |
Frequency reflects how fast each signal decays: payment data ages in days, register filings in months.
Which Preventive Controls Actually Stop Company Impersonation?
The controls that work remove the fraudster’s opportunity rather than trying to spot their message. Prioritise in this order:
- Verify bank details out of band, every time. Ring the supplier on a number from your own supplier master file — never from the request — and confirm changes with a known contact. This one control blocks the majority of mandate fraud attempts.
- Don’t mistake Confirmation of Payee for verification. CoP checks whether the name you type matches the name on the account for Faster Payments and CHAPS. It does not confirm that the account belongs to your genuine supplier, that the company behind it is real, or that the instruction to change details was authentic. A fraudster who names their mule account correctly passes CoP cleanly.
- Automate account validation. Manual callbacks don’t scale past a few dozen suppliers and fail silently under volume. Automated validation checks that the sort code and account number, the legal entity and the bank actually correspond, continuously across the supplier lifecycle. This is Trustpair’s core function: validating supplier account ownership at onboarding, on every data change, and before each payment run, so a redirected payment is blocked rather than reported. If you are building a shortlist, compare identity verification solutions on the features and false-positive benchmarks that matter during an RFP.
- Evidence reasonable procedures under ECCTA. The failure to prevent fraud offence has applied to large organisations since 1 September 2025. Automated, logged, pre-payment verification is far easier to evidence to a prosecutor or auditor than a spreadsheet and a second signature.
- Enforce MFA everywhere, with phishing-resistant factors on finance, email and administrator accounts.
- Lock down your Companies House footprint. Limit filing authority to two named officers, secure the WebFiling account with MFA, switch on filing alerts, and complete director identity verification ahead of the November 2026 deadline.
- Harden and monitor your domain estate. Deploy SPF, DKIM and DMARC at enforcement, register obvious lookalike domains defensively, and monitor for new registrations and fake social handles.
- Segregate duties and train on the real scenario. Nobody who can modify a supplier record should be able to release a payment to it. Then run simulations of bank-detail change requests and director urgency — walking teams through how third-party fraud plays out inside a finance team makes useful training material, because it shows how ordinary the attack looks from the inside.
Your Next Steps
If you are in an active incident, work the seven steps above and file your reports today. If you are reading this to prepare, do three things this week: audit who in your organisation can change a supplier’s bank details, check your Companies House filings and business credit reports, and pressure-test what would actually happen if a convincing bank-detail change request landed in your accounts payable inbox tomorrow.
Then close the verification gap for good. Trustpair validates supplier and third-party account ownership automatically across 170+ countries — at onboarding, on every data change, and before each payment run — so impersonation attempts are blocked at the payment stage instead of discovered at reconciliation. Book a demo with a fraud expert to see how it fits your existing ERP and P2P workflows.