How to Respond to a Company Impersonation Scam: A 7-Step Playbook

IN THIS ARTICLE
Table of Contents
Like it? Share it

If your business is being impersonated right now, act in this order: freeze outgoing payments to any recently changed bank details, lock and re-credential the affected accounts, preserve every message as evidence, then report the fraud to your bank and Action Fraud the same day. Speed matters more than certainty: Faster Payments settle in seconds, so the recall window is measured in hours, not days.

A company impersonation scam is when criminals pose as your business — or as one of your suppliers, directors, or banks — to extract payments, credentials, or credit in your name. The exposure is substantial and growing. UK Finance reports that criminals stole £1.28 billion through fraud in 2025, with authorised push payment (APP) losses reaching £576.4 million across 248,070 cases. The Home Office puts the cost of fraud to UK businesses at £5.2 billion in the year ending March 2024, and fraud now accounts for 45% of all recorded crime in England and Wales.

Impersonation only works when nobody verifies who actually owns the bank account receiving the money. That verification gap is exactly what automated vendor identity verification closes, by confirming account ownership and legal entity before a payment leaves your systems rather than after. This guide covers the first 24 hours, the reporting channels that matter in the UK, and the controls that stop the next attempt.

Key Takeaways

  • Contain first, investigate second: stop pending payments, lock compromised accounts, enable MFA, and appoint one incident owner before you start diagnosing.
  • Report to your bank, Action Fraud (0300 123 2040) and Companies House — and to the FCA if the impersonator is posing as an authorised firm. In Scotland, report to Police Scotland on 101.
  • The PSR’s APP reimbursement rules do not protect most corporates. Mandatory reimbursement up to £85,000 covers consumers, micro-enterprises and small charities only, so a mid-sized or large business carries the loss itself.
  • The highest-yield red flag is any request to change supplier or payroll bank details — what Action Fraud classifies as mandate fraud, which hit 7% of UK businesses in a single year.
  • The failure to prevent fraud offence under ECCTA has been in force since 1 September 2025. Large organisations need demonstrable, reasonable fraud prevention procedures as a statutory defence — manual controls alone are hard to evidence.

What Should You Do First If Your Company Is Being Impersonated?

Contain the damage in the first hour, then build the evidence file. Work through these seven steps in sequence — resist the urge to investigate before you’ve stopped the bleeding.

  1. Freeze every payment tied to changed details. Halt outgoing CHAPS, Faster Payments and Bacs runs, plus any scheduled payments, to accounts whose details were modified in the last 90 days. If a payment has already left, telephone your bank immediately and ask them to attempt recall and contact the beneficiary bank.
  2. Isolate the affected accounts. Disconnect compromised mailboxes, ERP logins and accounts payable sessions. Don’t delete anything — isolate it.
  3. Reset credentials and enforce MFA. Rotate passwords for every account the attacker could have touched, revoke active sessions and app tokens, and switch on multi-factor authentication across finance, email and administrator accounts.
  4. Appoint a single incident owner. One named person coordinates the response and owns all external communication. Parallel, uncoordinated outreach is how organisations contradict themselves in front of customers and regulators.
  5. Build a timestamped evidence file. Export original emails with full headers, screenshots of spoofed domains or social profiles, invoice copies, payment confirmations and a chronological timeline. Save messages as .eml or .msg files — forwarding destroys the headers investigators need.
  6. Notify your bank through a verified channel. Ring the number printed on your bank statement or in your corporate banking portal, never a number supplied in the suspicious message. Ask them to flag the beneficiary account, apply enhanced monitoring, and confirm whether any other payment instructions were altered.
  7. Warn the people who could be defrauded next. Alert customers, suppliers and partners that your identity is being misused, and tell them precisely which channels are legitimate.

Steps 5 to 7 run in parallel once containment is complete. If the impersonation involved a compromised mailbox rather than a lookalike domain, treat it as a full security incident — attackers frequently sit inside an inbox for weeks, studying invoice formats and payment cycles, before they act. If personal data was accessed, remember the UK GDPR clock: reportable breaches must reach the ICO within 72 hours.

The First 24 Hours: Company Impersonation Response Timeline

WindowPhaseActions
Hour 0–1ContainFreeze CHAPS, Faster Payments and Bacs runs; halt payments to changed details; isolate affected accounts
Hour 1–4SecureRotate credentials; enforce MFA everywhere; name one incident owner
Hour 4–24ReportBank fraud team on a verified line; Action Fraud (0300 123 2040) or Police Scotland (101); ICO if personal data is involved
Day 2+Notify and monitorWarn suppliers and customers; check Companies House filings; check business credit files; consider Cifas Protective Registration

Recovery window: Faster Payments settle in seconds and funds are typically dispersed within hours, so recall odds fall sharply after the first 24–72 hours.

Where Do You Report a Company Impersonation Scam in the UK?

Report to your bank first, then Action Fraud, then Companies House if your filings have been touched. Each channel serves a different purpose, and filing with all of them strengthens both recovery odds and any future insurance claim.

ChannelWhat it’s forWhere
Your bank’s fraud teamPayment recall, beneficiary account freezeNumber on your statement or corporate banking portal
Action FraudNational fraud and cybercrime reporting for England, Wales and Northern Irelandactionfraud.police.uk · 0300 123 2040
Police ScotlandFraud reporting in Scotland (Action Fraud does not cover Scotland)101
Companies HouseFraudulent filings, unauthorised director, address or registered office changesCompanies House online reporting
FCASomeone impersonating an FCA-authorised firm (a “clone firm”)fca.org.uk
NCSC Suspicious Email Reporting ServicePhishing and spoofed-site takedownsreport@phishing.gov.uk
ICONotifiable personal data breach, within 72 hoursico.org.uk
CifasProtective Registration against further applications in your namecifas.org.uk
Credit reference agenciesDispute fraudulent applications, accounts or searchesExperian, Equifax, TransUnion, Creditsafe, Dun & Bradstreet UK

Three practical notes. First, an Action Fraud report generates a crime reference number, which your insurer and often your bank will ask for — file it even when recovery looks unlikely. Second, if fraudulent documents have been filed at Companies House, report the specific filings rather than the company in general, and download copies of the filed forms as evidence before anything is amended. Third, notify your insurer early: most crime and cyber policies impose reporting deadlines and require a crime reference number before they will open a claim.

The Scale of the Problem in the UK

MeasureFigureSource
Total fraud losses, 2025£1.28 billionUK Finance
APP fraud losses, 2025£576.4 million across 248,070 casesUK Finance
Cost of fraud to UK businesses (year ending March 2024)£5.2 billionHome Office
UK businesses experiencing fraud in 12 months27%Economic Crime Survey 2024
Businesses hit by fake invoice fraud11%Economic Crime Survey 2024
Businesses hit by mandate fraud7%Economic Crime Survey 2024
Fraud as a share of all crime in England and Wales45%ONS, year ending September 2025

What Is a Business Impersonation Scam?

A business impersonation scam is any fraud in which criminals adopt a company’s identity — its name, domain, branding, directors or banking relationship — to deceive a third party into sending money or data. The impersonated business may be the victim, the vehicle, or both.

Business impersonation scams pursue one of four objectives:

  • Redirected payments: invoices or bank-detail change requests that route funds to the fraudster’s account. This is the dominant motive — Action Fraud calls it mandate fraud — and it maps directly onto the top vendor fraud schemes targeting UK finance teams.
  • Credential theft: harvesting logins to email, banking portals or ERP systems for a larger follow-up attack.
  • Credit and account fraud: opening trade accounts, credit facilities, leases or business bank accounts in the company’s name.
  • Data extraction: stealing sensitive company information — payroll records, customer lists, supplier master files — to sell or reuse in a later attack.

Typical outcomes include irrecoverable payment losses, chargeback and refund liability, damaged commercial credit, and regulatory scrutiny. The hidden cost is operational: after an incident, organisations spend weeks of senior finance and IT capacity on forensics, bank correspondence and filing corrections.

Small and mid-sized businesses are disproportionately targeted for structural reasons, not because criminals prefer them: they publish the same Companies House data as large firms but have fewer approval layers, rarely have a dedicated fraud function, often run a single shared accounts payable inbox, and are more likely to have one person able to both change a supplier record and release a payment.

How Is Business Identity Theft Different From Personal Identity Theft?

Business identity theft targets an entity’s commercial identity and credit, and it unwinds far more slowly than personal identity theft — not least because the UK’s mandatory reimbursement regime largely excludes corporates.

DimensionPersonal identity theftBusiness identity theft
Identifiers abusedNational Insurance number, date of birth, driving licenceCompany registration number, UTR, VAT number, director and PSC details
Public exposureMostly private dataCompanies House registration, officers and registered office are public by design
Reimbursement rightsAPP reimbursement up to £85,000 for consumersAvailable only to micro-enterprises and small charities; larger businesses are out of scope
Typical loss sizeHundreds to thousandsTens of thousands to millions
Recovery pathBank claim, CRA dispute, Financial Ombudsman ServiceBank claim, litigation, Companies House filing corrections
Collateral damagePersonal credit fileCredit facilities, supplier terms, tender eligibility, brand trust

The two crimes increasingly overlap. Criminals combine a director’s personal information — home address, date of birth, National Insurance number — with public Companies House filings to pass verification at banks and lenders, because the pairing looks far more convincing than either data set alone.

The reimbursement asymmetry is the point most finance teams miss. Since 7 October 2024, payment service providers must reimburse in-scope APP fraud victims up to £85,000, but that protection stops at consumers, micro-enterprises and small charities. If a £400,000 payment leaves a mid-sized manufacturer on fraudulent instructions, there is no statutory right to reimbursement. The loss is commercial, and the only reliable defence is preventing the payment in the first place.

Businesses also get less procedural help on the credit side. You must find the fraudulent entry yourself, dispute it in writing with the relevant credit reference agency, and prove it — optionally adding a notice of correction to the file. The consequences that hurt most are second-order: a fraudulent trade line can raise borrowing costs, shorten supplier terms, or disqualify you from a tender, often months later, when nobody connects the dots.

There is also a hybrid threat sitting between the two categories. Criminals build fabricated entities from a mix of real and fake identifiers, then cultivate them for months until they resemble established suppliers. This is synthetic identity fraud, and it is especially dangerous in procurement because roughly 95% of synthetic identities pass standard verification checks (Thomson Reuters). A supplier that clears your onboarding process is not necessarily a supplier that exists.

How Do Scammers Impersonate Your Business Identity?

Criminals impersonate businesses across every channel where trust is assumed rather than verified. Most attacks combine two or three of them.

Which Channels Do Impersonators Use?

  • Email: lookalike domains, display-name spoofing and reply-chain hijacking. This is the dominant vector, and it is worth understanding exactly how email spoofing works before you design controls around it.
  • Telephone and SMS: caller ID spoofing and smishing, often used to “confirm” a bank-detail change already sent by email.
  • AI-generated audio and video: synthetic voice or video of a named director, used to authorise urgent transfers. Deepfake authorisation requests are now credible enough that “I heard the CFO say it” is no longer a control.
  • Fake websites and portals: cloned checkout, careers or supplier onboarding pages built to capture credentials and sensitive company information.
  • Social and marketplace profiles: counterfeit company pages and paid ads using your logo.
  • Post and paper: forged letterhead for Companies House filings or credit applications.

How Do They Abuse Your Branding?

Spoofing methods are cheap and effective: registering a domain that swaps one character or changes the TLD, registering a company name that closely mimics yours, copying your email signature and logo lockup verbatim, cloning genuine invoice templates including PO number formats, and reusing real employee names and job titles scraped from LinkedIn. Without SPF, DKIM and DMARC enforcement on your domain, attackers can also send mail that appears to originate from your actual address.

Which Data Points Do Criminals Exploit?

  • Your company registration number, VAT number and registered office, all publicly retrievable
  • Director, PSC and registered office details from Companies House
  • Supplier and customer names from press releases, case studies and job adverts
  • Invoice numbering conventions and payment terms
  • Approval thresholds and finance team structure inferred from org charts

Because Companies House data is public by design, reconnaissance requires no hacking at all. Note the inverse signal too: fake and synthetic entities are frequently registered to virtual mailboxes or serviced offices, so a registered office that resolves to a mail-forwarding service deserves closer scrutiny during supplier onboarding — especially for a company claiming years of trading history.

What Does the Scam Flow Look Like, Step by Step?

  1. Reconnaissance: the attacker maps your suppliers, finance staff and approval chain from public sources.
  2. Infrastructure: they register a lookalike domain or compromise a mailbox — yours or a supplier’s.
  3. Insertion: they join or replicate a live email thread, often after weeks of silent observation.
  4. The ask: a bank-detail change, an urgent overdue invoice, or a transfer “authorised” by a director whose voice or writing style has been cloned.
  5. The payment: funds land in a mule account and are dispersed within hours.
  6. The exit: the account closes before your reconciliation cycle surfaces the discrepancy.

The gap between step 5 and step 6 is why detection-based controls underperform. By the time a month-end reconciliation flags the anomaly, recovery is largely theoretical.

Why Detection-Based Controls Lose the Race

TimelineWhat the fraudster doesWhat an unprotected finance team sees
Weeks beforeReconnaissance, mailbox access, invoice pattern studyNothing
Day 0Bank-detail change accepted, Faster Payment releasedA routine payment run
Day 0–1Funds dispersed through mule accounts, account closedNothing
Day 1–3Already goneRecovery window closing (24–72 hours)
Day 30UntraceableMonth-end reconciliation finally flags the discrepancy

Detection gap: 27 days between the fraudster’s exit and the finance team’s discovery.

What Are the Red Flags in Your Records and Communications?

The single highest-value red flag is any inbound request to change bank details. Treat every one as a mandate fraud attempt until independently verified.

Invoice and payment discrepancies to flag:

  • New or changed bank details, especially a sort code from a different bank or a switch to an overseas IBAN
  • Invoice amounts just below an approval threshold
  • Duplicate invoice numbers, or numbering that breaks the supplier’s usual sequence
  • A supplier’s payment terms suddenly shortening, or “urgent overdue” framing on a current account
  • A mismatch between the supplier’s registered name and the account holder name
  • Free email domains replacing a corporate domain on correspondence

Unexpected changes at Companies House:

  • A director appointment or termination you didn’t authorise
  • Registered office or trading address changes you didn’t make
  • New company names closely resembling yours
  • Reinstatement of a dissolved company
  • Unexplained searches or applications showing on your business credit file

Instruct staff to preserve evidence. Anyone receiving a suspicious message should save it as an attachment with full headers, screenshot the sender details, and forward it to the incident owner — without replying, clicking or deleting. Nine times out of ten, the quality of the evidence file determines whether the bank engages seriously. For the underlying patterns, learn how to detect and prevent invoice fraud, since most impersonation attempts arrive as a document your team already expects to receive.

How Should You Monitor Companies House and Credit Information?

Monitor quarterly at minimum, and treat monitoring as an early-warning system rather than a compliance chore. Fraudulent filings and credit applications typically precede the payment attack — catching them early is the difference between a nuisance and a loss.

How Do You Check Your Companies House Records?

Search the Companies House register by exact company name, then by director name to catch companies registered in your officers’ names. Set up free “follow this company” email alerts so every filing against your entity lands in an inbox you actually read. Register your company’s email address with Companies House, and ask about protected online filing options that block paper submission of key forms. Download copies of any filing you didn’t authorise before requesting a correction — once amended, the original is harder to produce as evidence.

Identity verification is now part of this picture. Since 18 November 2025, new directors and people with significant control must verify their identity with Companies House, and existing directors must complete verification by 18 November 2026. Treat the deadline as a control, not just an admin task: verified officer records make it materially harder for someone to appoint a fictitious director to your company.

Which Credit Reference Agencies Should You Monitor?

  • Experian Business
  • Equifax Business
  • TransUnion
  • Creditsafe
  • Dun & Bradstreet UK

Pull your business credit report from each agency at least quarterly and review it line by line against your own records. Paid monitoring is worth the cost for one reason: it alerts you to new trade lines and searches in near real time, which is the only way to catch credit fraud before it matures. When an unexpected entry appears, record the date discovered, the reporting creditor, the amount and the account number; dispute it in writing; consider a notice of correction; and escalate to the incident owner so it is linked to any open case. Cifas Protective Registration adds a flag that requires extra checks on future applications made in your name.

What Should Long-Term Monitoring Look Like?

Maintain a standing incident log covering every impersonation attempt, successful or not — date, channel, target, amount at risk, outcome and controls changed as a result. It serves three purposes: it evidences reasonable procedures under the failure to prevent fraud offence, it reveals which suppliers or entities are repeatedly targeted, and it justifies control investment to your board and audit committee.

Business Impersonation Monitoring Cadence

FrequencyCheckWhat it catches
Weekly (52× a year)Payment file reviewBank-detail changes made in the last 7 days
Monthly (12× a year)Supplier master auditNew suppliers, duplicate records, reactivated dormant accounts
Quarterly (4× a year)Business credit files: Experian, Equifax, TransUnion, Creditsafe, D&BNew trade lines, unexplained searches, score movements
Continuous plus annual reviewCompanies House alerts and full register checkDirector, registered office and company name changes

Frequency reflects how fast each signal decays: payment data ages in days, register filings in months.

Which Preventive Controls Actually Stop Company Impersonation?

The controls that work remove the fraudster’s opportunity rather than trying to spot their message. Prioritise in this order:

  1. Verify bank details out of band, every time. Ring the supplier on a number from your own supplier master file — never from the request — and confirm changes with a known contact. This one control blocks the majority of mandate fraud attempts.
  2. Don’t mistake Confirmation of Payee for verification. CoP checks whether the name you type matches the name on the account for Faster Payments and CHAPS. It does not confirm that the account belongs to your genuine supplier, that the company behind it is real, or that the instruction to change details was authentic. A fraudster who names their mule account correctly passes CoP cleanly.
  3. Automate account validation. Manual callbacks don’t scale past a few dozen suppliers and fail silently under volume. Automated validation checks that the sort code and account number, the legal entity and the bank actually correspond, continuously across the supplier lifecycle. This is Trustpair’s core function: validating supplier account ownership at onboarding, on every data change, and before each payment run, so a redirected payment is blocked rather than reported. If you are building a shortlist, compare identity verification solutions on the features and false-positive benchmarks that matter during an RFP.
  4. Evidence reasonable procedures under ECCTA. The failure to prevent fraud offence has applied to large organisations since 1 September 2025. Automated, logged, pre-payment verification is far easier to evidence to a prosecutor or auditor than a spreadsheet and a second signature.
  5. Enforce MFA everywhere, with phishing-resistant factors on finance, email and administrator accounts.
  6. Lock down your Companies House footprint. Limit filing authority to two named officers, secure the WebFiling account with MFA, switch on filing alerts, and complete director identity verification ahead of the November 2026 deadline.
  7. Harden and monitor your domain estate. Deploy SPF, DKIM and DMARC at enforcement, register obvious lookalike domains defensively, and monitor for new registrations and fake social handles.
  8. Segregate duties and train on the real scenario. Nobody who can modify a supplier record should be able to release a payment to it. Then run simulations of bank-detail change requests and director urgency — walking teams through how third-party fraud plays out inside a finance team makes useful training material, because it shows how ordinary the attack looks from the inside.

Your Next Steps

If you are in an active incident, work the seven steps above and file your reports today. If you are reading this to prepare, do three things this week: audit who in your organisation can change a supplier’s bank details, check your Companies House filings and business credit reports, and pressure-test what would actually happen if a convincing bank-detail change request landed in your accounts payable inbox tomorrow.

Then close the verification gap for good. Trustpair validates supplier and third-party account ownership automatically across 170+ countries — at onboarding, on every data change, and before each payment run — so impersonation attempts are blocked at the payment stage instead of discovered at reconciliation. Book a demo with a fraud expert to see how it fits your existing ERP and P2P workflows.

FAQ
Frequently asked questions
Browse through our different sections and find the answer to your question.

Sometimes, but only if you act within hours. Telephone your bank’s fraud team immediately to request recall and ask them to contact the beneficiary bank, then report to Action Fraud the same day. Be realistic about reimbursement: the PSR’s mandatory APP reimbursement regime covers consumers, micro-enterprises and small charities up to £85,000, so most mid-sized and large businesses have no statutory right to be repaid and must rely on recall, insurance or civil recovery.

Report to your bank, then Action Fraud on 0300 123 2040 (or Police Scotland on 101 if you are in Scotland). Add Companies House if fraudulent filings were made, the FCA if someone is impersonating an authorised firm, the NCSC at report@phishing.gov.uk for phishing takedowns, and the ICO within 72 hours if personal data was compromised.

Yes. Impersonating a company to obtain money or data is prosecuted as fraud by false representation under the Fraud Act 2006, alongside offences for false Companies House filings and, where relevant, money laundering offences. Since September 2025, the Economic Crime and Corporate Transparency Act also creates a failure to prevent fraud offence for large organisations whose associates commit fraud for their benefit.

Verify it out of band before you pay: ring a known contact at the supplier using a number from your own records, not from the request. Confirm the account holder name matches the supplier’s registered company name, and treat urgency or secrecy as a red flag. Remember that Confirmation of Payee only matches a name to an account — it does not prove the account belongs to your genuine supplier. Automated account validation performs that check systematically on every change.

Small businesses combine public visibility with thin controls: their Companies House data is public, approval chains are short, one person often controls both supplier records and payments, and few have a dedicated fraud function. The attack is identical to the one used on large enterprises; only the defences differ.

You’d like these articles

Ready to beat the fraudsters? Try our 2-minute game

Ready to beat the fraudsters? Try our 2-minute game