{"id":52589,"date":"2026-09-16T11:58:00","date_gmt":"2026-09-16T09:58:00","guid":{"rendered":"https:\/\/trustpair.com\/?p=52589"},"modified":"2026-09-16T12:11:57","modified_gmt":"2026-09-16T10:11:57","slug":"gb-blog-how-to-respond-to-a-company-impersonation-scam","status":"publish","type":"post","link":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/","title":{"rendered":"How to Respond to a Company Impersonation Scam: A 7-Step Playbook"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\" id=\"speakable\">If your business is being impersonated right now, act in this order: <strong>freeze outgoing payments to any recently changed bank details, lock and re-credential the affected accounts, preserve every message as evidence, then report the fraud to your bank and Action Fraud the same day.<\/strong> Speed matters more than certainty: Faster Payments settle in seconds, so the recall window is measured in hours, not days.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A company impersonation scam is when criminals pose as your business \u2014 or as one of your suppliers, directors, or banks \u2014 to extract payments, credentials, or credit in your name. The exposure is substantial and growing. UK Finance reports that criminals stole \u00a31.28 billion through fraud in 2025, with authorised push payment (APP) losses reaching \u00a3576.4 million across 248,070 cases. The Home Office puts the cost of fraud to UK businesses at \u00a35.2 billion in the year ending March 2024, and fraud now accounts for 45% of all recorded crime in England and Wales.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Impersonation only works when nobody verifies who actually owns the bank account receiving the money. That verification gap is exactly what <a href=\"https:\/\/trustpair.com\/vendor-identity-verification\/\" target=\"_blank\" rel=\"noopener\">automated vendor identity verification<\/a> closes, by confirming account ownership and legal entity before a payment leaves your systems rather than after. This guide covers the first 24 hours, the reporting channels that matter in the UK, and the controls that stop the next attempt.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"key-takeaways\">Key Takeaways<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Contain first, investigate second:<\/strong>\u00a0stop pending payments, lock compromised accounts, enable MFA, and appoint one incident owner before you start diagnosing.<\/li>\n\n\n\n<li><strong>Report to your bank, Action Fraud (0300 123 2040) and Companies House<\/strong>\u00a0\u2014 and to the FCA if the impersonator is posing as an authorised firm. In Scotland, report to Police Scotland on 101.<\/li>\n\n\n\n<li><strong>The PSR&#8217;s APP reimbursement rules do not protect most corporates.<\/strong>\u00a0Mandatory reimbursement up to \u00a385,000 covers consumers, micro-enterprises and small charities only, so a mid-sized or large business carries the loss itself.<\/li>\n\n\n\n<li><strong>The highest-yield red flag is any request to change supplier or payroll bank details<\/strong>\u00a0\u2014 what Action Fraud classifies as mandate fraud, which hit 7% of UK businesses in a single year.<\/li>\n\n\n\n<li><strong>The failure to prevent fraud offence under ECCTA has been in force since 1 September 2025.<\/strong>\u00a0Large organisations need demonstrable, reasonable fraud prevention procedures as a statutory defence \u2014 manual controls alone are hard to evidence.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-should-you-do-first-if-your-company-is-being-impersonated\">What Should You Do First If Your Company Is Being Impersonated?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Contain the damage in the first hour, then build the evidence file.<\/strong> Work through these seven steps in sequence \u2014 resist the urge to investigate before you&#8217;ve stopped the bleeding.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Freeze every payment tied to changed details.<\/strong>\u00a0Halt outgoing CHAPS, Faster Payments and Bacs runs, plus any scheduled payments, to accounts whose details were modified in the last 90 days. If a payment has already left, telephone your bank immediately and ask them to attempt recall and contact the beneficiary bank.<\/li>\n\n\n\n<li><strong>Isolate the affected accounts.<\/strong>\u00a0Disconnect compromised mailboxes, ERP logins and accounts payable sessions. Don&#8217;t delete anything \u2014 isolate it.<\/li>\n\n\n\n<li><strong>Reset credentials and enforce MFA.<\/strong>\u00a0Rotate passwords for every account the attacker could have touched, revoke active sessions and app tokens, and switch on multi-factor authentication across finance, email and administrator accounts.<\/li>\n\n\n\n<li><strong>Appoint a single incident owner.<\/strong>\u00a0One named person coordinates the response and owns all external communication. Parallel, uncoordinated outreach is how organisations contradict themselves in front of customers and regulators.<\/li>\n\n\n\n<li><strong>Build a timestamped evidence file.<\/strong>\u00a0Export original emails with full headers, screenshots of spoofed domains or social profiles, invoice copies, payment confirmations and a chronological timeline. Save messages as .eml or .msg files \u2014 forwarding destroys the headers investigators need.<\/li>\n\n\n\n<li><strong>Notify your bank through a verified channel.<\/strong>\u00a0Ring the number printed on your bank statement or in your corporate banking portal, never a number supplied in the suspicious message. Ask them to flag the beneficiary account, apply enhanced monitoring, and confirm whether any other payment instructions were altered.<\/li>\n\n\n\n<li><strong>Warn the people who could be defrauded next.<\/strong>\u00a0Alert customers, suppliers and partners that your identity is being misused, and tell them precisely which channels are legitimate.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Steps 5 to 7 run in parallel once containment is complete. If the impersonation involved a compromised mailbox rather than a lookalike domain, treat it as a full security incident \u2014 attackers frequently sit inside an inbox for weeks, studying invoice formats and payment cycles, before they act. If personal data was accessed, remember the UK GDPR clock: reportable breaches must reach the ICO within 72 hours.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"the-first-24-hours-company-impersonation-response-timeline\">The First 24 Hours: Company Impersonation Response Timeline<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Window<\/th><th class=\"has-text-align-left\" data-align=\"left\">Phase<\/th><th class=\"has-text-align-left\" data-align=\"left\">Actions<\/th><\/tr><\/thead><tbody><tr><td>Hour 0\u20131<\/td><td>Contain<\/td><td>Freeze CHAPS, Faster Payments and Bacs runs; halt payments to changed details; isolate affected accounts<\/td><\/tr><tr><td>Hour 1\u20134<\/td><td>Secure<\/td><td>Rotate credentials; enforce MFA everywhere; name one incident owner<\/td><\/tr><tr><td>Hour 4\u201324<\/td><td>Report<\/td><td>Bank fraud team on a verified line; Action Fraud (0300 123 2040) or Police Scotland (101); ICO if personal data is involved<\/td><\/tr><tr><td>Day 2+<\/td><td>Notify and monitor<\/td><td>Warn suppliers and customers; check Companies House filings; check business credit files; consider Cifas Protective Registration<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Recovery window: Faster Payments settle in seconds and funds are typically dispersed within hours, so recall odds fall sharply after the first 24\u201372 hours.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"where-do-you-report-a-company-impersonation-scam-in-the-uk\">Where Do You Report a Company Impersonation Scam in the UK?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Report to your bank first, then Action Fraud, then Companies House if your filings have been touched.<\/strong> Each channel serves a different purpose, and filing with all of them strengthens both recovery odds and any future insurance claim.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Channel<\/th><th class=\"has-text-align-left\" data-align=\"left\">What it&#8217;s for<\/th><th class=\"has-text-align-left\" data-align=\"left\">Where<\/th><\/tr><\/thead><tbody><tr><td>Your bank&#8217;s fraud team<\/td><td>Payment recall, beneficiary account freeze<\/td><td>Number on your statement or corporate banking portal<\/td><\/tr><tr><td>Action Fraud<\/td><td>National fraud and cybercrime reporting for England, Wales and Northern Ireland<\/td><td>actionfraud.police.uk \u00b7 0300 123 2040<\/td><\/tr><tr><td>Police Scotland<\/td><td>Fraud reporting in Scotland (Action Fraud does not cover Scotland)<\/td><td>101<\/td><\/tr><tr><td>Companies House<\/td><td>Fraudulent filings, unauthorised director, address or registered office changes<\/td><td>Companies House online reporting<\/td><\/tr><tr><td>FCA<\/td><td>Someone impersonating an FCA-authorised firm (a &#8220;clone firm&#8221;)<\/td><td>fca.org.uk<\/td><\/tr><tr><td>NCSC Suspicious Email Reporting Service<\/td><td>Phishing and spoofed-site takedowns<\/td><td><a href=\"mailto:report@phishing.gov.uk\" target=\"_blank\" rel=\"noopener\">report@phishing.gov.uk<\/a><\/td><\/tr><tr><td>ICO<\/td><td>Notifiable personal data breach, within 72 hours<\/td><td>ico.org.uk<\/td><\/tr><tr><td>Cifas<\/td><td>Protective Registration against further applications in your name<\/td><td>cifas.org.uk<\/td><\/tr><tr><td>Credit reference agencies<\/td><td>Dispute fraudulent applications, accounts or searches<\/td><td>Experian, Equifax, TransUnion, Creditsafe, Dun &amp; Bradstreet UK<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Three practical notes. First, an Action Fraud report generates a crime reference number, which your insurer and often your bank will ask for \u2014 file it even when recovery looks unlikely. Second, if fraudulent documents have been filed at Companies House, report the specific filings rather than the company in general, and download copies of the filed forms as evidence before anything is amended. Third, notify your insurer early: most crime and cyber policies impose reporting deadlines and require a crime reference number before they will open a claim.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"the-scale-of-the-problem-in-the-uk\">The Scale of the Problem in the UK<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Measure<\/th><th class=\"has-text-align-left\" data-align=\"left\">Figure<\/th><th class=\"has-text-align-left\" data-align=\"left\">Source<\/th><\/tr><\/thead><tbody><tr><td>Total fraud losses, 2025<\/td><td>\u00a31.28 billion<\/td><td>UK Finance<\/td><\/tr><tr><td>APP fraud losses, 2025<\/td><td>\u00a3576.4 million across 248,070 cases<\/td><td>UK Finance<\/td><\/tr><tr><td>Cost of fraud to UK businesses (year ending March 2024)<\/td><td>\u00a35.2 billion<\/td><td>Home Office<\/td><\/tr><tr><td>UK businesses experiencing fraud in 12 months<\/td><td>27%<\/td><td>Economic Crime Survey 2024<\/td><\/tr><tr><td>Businesses hit by fake invoice fraud<\/td><td>11%<\/td><td>Economic Crime Survey 2024<\/td><\/tr><tr><td>Businesses hit by mandate fraud<\/td><td>7%<\/td><td>Economic Crime Survey 2024<\/td><\/tr><tr><td>Fraud as a share of all crime in England and Wales<\/td><td>45%<\/td><td>ONS, year ending September 2025<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-is-a-business-impersonation-scam\">What Is a Business Impersonation Scam?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A business impersonation scam is any fraud in which criminals adopt a company&#8217;s identity \u2014 its name, domain, branding, directors or banking relationship \u2014 to deceive a third party into sending money or data.<\/strong> The impersonated business may be the victim, the vehicle, or both.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Business impersonation scams pursue one of four objectives:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Redirected payments:<\/strong>\u00a0invoices or bank-detail change requests that route funds to the fraudster&#8217;s account. This is the dominant motive \u2014 Action Fraud calls it mandate fraud \u2014 and it maps directly onto\u00a0<a href=\"https:\/\/trustpair.com\/gb\/blog\/the-top-3-vendor-fraud-schemes\/\" target=\"_blank\" rel=\"noopener\">the top vendor fraud schemes targeting UK finance teams<\/a>.<\/li>\n\n\n\n<li><strong>Credential theft:<\/strong>\u00a0harvesting logins to email, banking portals or ERP systems for a larger follow-up attack.<\/li>\n\n\n\n<li><strong>Credit and account fraud:<\/strong>\u00a0opening trade accounts, credit facilities, leases or business bank accounts in the company&#8217;s name.<\/li>\n\n\n\n<li><strong>Data extraction:<\/strong>\u00a0stealing sensitive company information \u2014 payroll records, customer lists, supplier master files \u2014 to sell or reuse in a later attack.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Typical outcomes include irrecoverable payment losses, chargeback and refund liability, damaged commercial credit, and regulatory scrutiny. The hidden cost is operational: after an incident, organisations spend weeks of senior finance and IT capacity on forensics, bank correspondence and filing corrections.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Small and mid-sized businesses are disproportionately targeted for structural reasons, not because criminals prefer them: they publish the same Companies House data as large firms but have fewer approval layers, rarely have a dedicated fraud function, often run a single shared accounts payable inbox, and are more likely to have one person able to both change a supplier record and release a payment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"how-is-business-identity-theft-different-from-personal-identity-theft\">How Is Business Identity Theft Different From Personal Identity Theft?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business identity theft targets an entity&#8217;s commercial identity and credit, and it unwinds far more slowly than personal identity theft \u2014 not least because the UK&#8217;s mandatory reimbursement regime largely excludes corporates.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Dimension<\/th><th class=\"has-text-align-left\" data-align=\"left\">Personal identity theft<\/th><th class=\"has-text-align-left\" data-align=\"left\">Business identity theft<\/th><\/tr><\/thead><tbody><tr><td>Identifiers abused<\/td><td>National Insurance number, date of birth, driving licence<\/td><td>Company registration number, UTR, VAT number, director and PSC details<\/td><\/tr><tr><td>Public exposure<\/td><td>Mostly private data<\/td><td>Companies House registration, officers and registered office are public by design<\/td><\/tr><tr><td>Reimbursement rights<\/td><td>APP reimbursement up to \u00a385,000 for consumers<\/td><td>Available only to micro-enterprises and small charities; larger businesses are out of scope<\/td><\/tr><tr><td>Typical loss size<\/td><td>Hundreds to thousands<\/td><td>Tens of thousands to millions<\/td><\/tr><tr><td>Recovery path<\/td><td>Bank claim, CRA dispute, Financial Ombudsman Service<\/td><td>Bank claim, litigation, Companies House filing corrections<\/td><\/tr><tr><td>Collateral damage<\/td><td>Personal credit file<\/td><td>Credit facilities, supplier terms, tender eligibility, brand trust<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The two crimes increasingly overlap. Criminals combine a director&#8217;s personal information \u2014 home address, date of birth, National Insurance number \u2014 with public Companies House filings to pass verification at banks and lenders, because the pairing looks far more convincing than either data set alone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reimbursement asymmetry is the point most finance teams miss. Since 7 October 2024, payment service providers must reimburse in-scope APP fraud victims up to \u00a385,000, but that protection stops at consumers, micro-enterprises and small charities. If a \u00a3400,000 payment leaves a mid-sized manufacturer on fraudulent instructions, there is no statutory right to reimbursement. The loss is commercial, and the only reliable defence is preventing the payment in the first place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Businesses also get less procedural help on the credit side. You must find the fraudulent entry yourself, dispute it in writing with the relevant credit reference agency, and prove it \u2014 optionally adding a notice of correction to the file. The consequences that hurt most are second-order: a fraudulent trade line can raise borrowing costs, shorten supplier terms, or disqualify you from a tender, often months later, when nobody connects the dots.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is also a hybrid threat sitting between the two categories. Criminals build fabricated entities from a mix of real and fake identifiers, then cultivate them for months until they resemble established suppliers. This is <a href=\"https:\/\/trustpair.com\/gb\/blog\/understanding-and-combating-synthetic-identity-fraud-in-business\/\" target=\"_blank\" rel=\"noopener\">synthetic identity fraud<\/a>, and it is especially dangerous in procurement because roughly 95% of synthetic identities pass standard verification checks (Thomson Reuters). A supplier that clears your onboarding process is not necessarily a supplier that exists.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"how-do-scammers-impersonate-your-business-identity\">How Do Scammers Impersonate Your Business Identity?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Criminals impersonate businesses across every channel where trust is assumed rather than verified.<\/strong> Most attacks combine two or three of them.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"which-channels-do-impersonators-use\">Which Channels Do Impersonators Use?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Email:<\/strong>\u00a0lookalike domains, display-name spoofing and reply-chain hijacking. This is the dominant vector, and it is worth understanding exactly\u00a0<a href=\"https:\/\/trustpair.com\/gb\/blog\/spoofing-an-open-door-to-corporate-fraud\/\" target=\"_blank\" rel=\"noopener\">how email spoofing works<\/a>\u00a0before you design controls around it.<\/li>\n\n\n\n<li><strong>Telephone and SMS:<\/strong>\u00a0caller ID spoofing and smishing, often used to &#8220;confirm&#8221; a bank-detail change already sent by email.<\/li>\n\n\n\n<li><strong>AI-generated audio and video:<\/strong>\u00a0synthetic voice or video of a named director, used to authorise urgent transfers. Deepfake authorisation requests are now credible enough that &#8220;I heard the CFO say it&#8221; is no longer a control.<\/li>\n\n\n\n<li><strong>Fake websites and portals:<\/strong>\u00a0cloned checkout, careers or supplier onboarding pages built to capture credentials and sensitive company information.<\/li>\n\n\n\n<li><strong>Social and marketplace profiles:<\/strong>\u00a0counterfeit company pages and paid ads using your logo.<\/li>\n\n\n\n<li><strong>Post and paper:<\/strong>\u00a0forged letterhead for Companies House filings or credit applications.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"how-do-they-abuse-your-branding\">How Do They Abuse Your Branding?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Spoofing methods are cheap and effective: registering a domain that swaps one character or changes the TLD, registering a company name that closely mimics yours, copying your email signature and logo lockup verbatim, cloning genuine invoice templates including PO number formats, and reusing real employee names and job titles scraped from LinkedIn. Without SPF, DKIM and DMARC enforcement on your domain, attackers can also send mail that appears to originate from your actual address.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"which-data-points-do-criminals-exploit\">Which Data Points Do Criminals Exploit?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your company registration number, VAT number and registered office, all publicly retrievable<\/li>\n\n\n\n<li>Director, PSC and registered office details from Companies House<\/li>\n\n\n\n<li>Supplier and customer names from press releases, case studies and job adverts<\/li>\n\n\n\n<li>Invoice numbering conventions and payment terms<\/li>\n\n\n\n<li>Approval thresholds and finance team structure inferred from org charts<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Because Companies House data is public by design, reconnaissance requires no hacking at all. Note the inverse signal too: fake and synthetic entities are frequently registered to virtual mailboxes or serviced offices, so a registered office that resolves to a mail-forwarding service deserves closer scrutiny during supplier onboarding \u2014 especially for a company claiming years of trading history.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-does-the-scam-flow-look-like-step-by-step\">What Does the Scam Flow Look Like, Step by Step?<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Reconnaissance:<\/strong>\u00a0the attacker maps your suppliers, finance staff and approval chain from public sources.<\/li>\n\n\n\n<li><strong>Infrastructure:<\/strong>\u00a0they register a lookalike domain or compromise a mailbox \u2014 yours or a supplier&#8217;s.<\/li>\n\n\n\n<li><strong>Insertion:<\/strong>\u00a0they join or replicate a live email thread, often after weeks of silent observation.<\/li>\n\n\n\n<li><strong>The ask:<\/strong>\u00a0a bank-detail change, an urgent overdue invoice, or a transfer &#8220;authorised&#8221; by a director whose voice or writing style has been cloned.<\/li>\n\n\n\n<li><strong>The payment:<\/strong>\u00a0funds land in a mule account and are dispersed within hours.<\/li>\n\n\n\n<li><strong>The exit:<\/strong>\u00a0the account closes before your reconciliation cycle surfaces the discrepancy.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The gap between step 5 and step 6 is why detection-based controls underperform. By the time a month-end reconciliation flags the anomaly, recovery is largely theoretical.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"why-detection-based-controls-lose-the-race\">Why Detection-Based Controls Lose the Race<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Timeline<\/th><th class=\"has-text-align-left\" data-align=\"left\">What the fraudster does<\/th><th class=\"has-text-align-left\" data-align=\"left\">What an unprotected finance team sees<\/th><\/tr><\/thead><tbody><tr><td>Weeks before<\/td><td>Reconnaissance, mailbox access, invoice pattern study<\/td><td>Nothing<\/td><\/tr><tr><td>Day 0<\/td><td>Bank-detail change accepted, Faster Payment released<\/td><td>A routine payment run<\/td><\/tr><tr><td>Day 0\u20131<\/td><td>Funds dispersed through mule accounts, account closed<\/td><td>Nothing<\/td><\/tr><tr><td>Day 1\u20133<\/td><td>Already gone<\/td><td>Recovery window closing (24\u201372 hours)<\/td><\/tr><tr><td>Day 30<\/td><td>Untraceable<\/td><td>Month-end reconciliation finally flags the discrepancy<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Detection gap: 27 days between the fraudster&#8217;s exit and the finance team&#8217;s discovery.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-are-the-red-flags-in-your-records-and-communications\">What Are the Red Flags in Your Records and Communications?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The single highest-value red flag is any inbound request to change bank details.<\/strong> Treat every one as a mandate fraud attempt until independently verified.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Invoice and payment discrepancies to flag:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>New or changed bank details, especially a sort code from a different bank or a switch to an overseas IBAN<\/li>\n\n\n\n<li>Invoice amounts just below an approval threshold<\/li>\n\n\n\n<li>Duplicate invoice numbers, or numbering that breaks the supplier&#8217;s usual sequence<\/li>\n\n\n\n<li>A supplier&#8217;s payment terms suddenly shortening, or &#8220;urgent overdue&#8221; framing on a current account<\/li>\n\n\n\n<li>A mismatch between the supplier&#8217;s registered name and the account holder name<\/li>\n\n\n\n<li>Free email domains replacing a corporate domain on correspondence<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Unexpected changes at Companies House:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A director appointment or termination you didn&#8217;t authorise<\/li>\n\n\n\n<li>Registered office or trading address changes you didn&#8217;t make<\/li>\n\n\n\n<li>New company names closely resembling yours<\/li>\n\n\n\n<li>Reinstatement of a dissolved company<\/li>\n\n\n\n<li>Unexplained searches or applications showing on your business credit file<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Instruct staff to preserve evidence. Anyone receiving a suspicious message should save it as an attachment with full headers, screenshot the sender details, and forward it to the incident owner \u2014 without replying, clicking or deleting. Nine times out of ten, the quality of the evidence file determines whether the bank engages seriously. For the underlying patterns, learn how to <a href=\"https:\/\/trustpair.com\/gb\/blog\/how-to-detect-and-prevent-invoice-fraud\/\" target=\"_blank\" rel=\"noopener\">detect and prevent invoice fraud<\/a>, since most impersonation attempts arrive as a document your team already expects to receive.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"how-should-you-monitor-companies-house-and-credit-information\">How Should You Monitor Companies House and Credit Information?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Monitor quarterly at minimum, and treat monitoring as an early-warning system rather than a compliance chore.<\/strong> Fraudulent filings and credit applications typically precede the payment attack \u2014 catching them early is the difference between a nuisance and a loss.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"how-do-you-check-your-companies-house-records\">How Do You Check Your Companies House Records?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Search the Companies House register by exact company name, then by director name to catch companies registered in your officers&#8217; names. Set up free &#8220;follow this company&#8221; email alerts so every filing against your entity lands in an inbox you actually read. Register your company&#8217;s email address with Companies House, and ask about protected online filing options that block paper submission of key forms. Download copies of any filing you didn&#8217;t authorise before requesting a correction \u2014 once amended, the original is harder to produce as evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Identity verification is now part of this picture. Since 18 November 2025, new directors and people with significant control must verify their identity with Companies House, and existing directors must complete verification by 18 November 2026. Treat the deadline as a control, not just an admin task: verified officer records make it materially harder for someone to appoint a fictitious director to your company.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"which-credit-reference-agencies-should-you-monitor\">Which Credit Reference Agencies Should You Monitor?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Experian Business<\/li>\n\n\n\n<li>Equifax Business<\/li>\n\n\n\n<li>TransUnion<\/li>\n\n\n\n<li>Creditsafe<\/li>\n\n\n\n<li>Dun &amp; Bradstreet UK<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Pull your business credit report from each agency at least quarterly and review it line by line against your own records. Paid monitoring is worth the cost for one reason: it alerts you to new trade lines and searches in near real time, which is the only way to catch credit fraud before it matures. When an unexpected entry appears, record the date discovered, the reporting creditor, the amount and the account number; dispute it in writing; consider a notice of correction; and escalate to the incident owner so it is linked to any open case. Cifas Protective Registration adds a flag that requires extra checks on future applications made in your name.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-should-long-term-monitoring-look-like\">What Should Long-Term Monitoring Look Like?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Maintain a standing incident log covering every impersonation attempt, successful or not \u2014 date, channel, target, amount at risk, outcome and controls changed as a result. It serves three purposes: it evidences reasonable procedures under the failure to prevent fraud offence, it reveals which suppliers or entities are repeatedly targeted, and it justifies control investment to your board and audit committee.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"business-impersonation-monitoring-cadence\">Business Impersonation Monitoring Cadence<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Frequency<\/th><th class=\"has-text-align-left\" data-align=\"left\">Check<\/th><th class=\"has-text-align-left\" data-align=\"left\">What it catches<\/th><\/tr><\/thead><tbody><tr><td>Weekly (52\u00d7 a year)<\/td><td>Payment file review<\/td><td>Bank-detail changes made in the last 7 days<\/td><\/tr><tr><td>Monthly (12\u00d7 a year)<\/td><td>Supplier master audit<\/td><td>New suppliers, duplicate records, reactivated dormant accounts<\/td><\/tr><tr><td>Quarterly (4\u00d7 a year)<\/td><td>Business credit files: Experian, Equifax, TransUnion, Creditsafe, D&amp;B<\/td><td>New trade lines, unexplained searches, score movements<\/td><\/tr><tr><td>Continuous plus annual review<\/td><td>Companies House alerts and full register check<\/td><td>Director, registered office and company name changes<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Frequency reflects how fast each signal decays: payment data ages in days, register filings in months.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"which-preventive-controls-actually-stop-company-impersonation\">Which Preventive Controls Actually Stop Company Impersonation?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The controls that work remove the fraudster&#8217;s opportunity rather than trying to spot their message.<\/strong> Prioritise in this order:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Verify bank details out of band, every time.<\/strong>\u00a0Ring the supplier on a number from your own supplier master file \u2014 never from the request \u2014 and confirm changes with a known contact. This one control blocks the majority of mandate fraud attempts.<\/li>\n\n\n\n<li><strong>Don&#8217;t mistake Confirmation of Payee for verification.<\/strong>\u00a0CoP checks whether the name you type matches the name on the account for Faster Payments and CHAPS. It does not confirm that the account belongs to your genuine supplier, that the company behind it is real, or that the instruction to change details was authentic. A fraudster who names their mule account correctly passes CoP cleanly.<\/li>\n\n\n\n<li><strong>Automate account validation.<\/strong>\u00a0Manual callbacks don&#8217;t scale past a few dozen suppliers and fail silently under volume. Automated validation checks that the sort code and account number, the legal entity and the bank actually correspond, continuously across the supplier lifecycle. This is Trustpair&#8217;s core function: validating supplier account ownership at onboarding, on every data change, and before each payment run, so a redirected payment is blocked rather than reported. If you are building a shortlist,\u00a0<a href=\"https:\/\/trustpair.com\/gb\/blog\/best-identity-verification-solutions-selection-guide-and-provider-comparison\/\" target=\"_blank\" rel=\"noopener\">compare identity verification solutions<\/a>\u00a0on the features and false-positive benchmarks that matter during an RFP.<\/li>\n\n\n\n<li><strong>Evidence reasonable procedures under ECCTA.<\/strong>\u00a0The failure to prevent fraud offence has applied to large organisations since 1 September 2025. Automated, logged, pre-payment verification is far easier to evidence to a prosecutor or auditor than a spreadsheet and a second signature.<\/li>\n\n\n\n<li><strong>Enforce MFA everywhere,<\/strong>\u00a0with phishing-resistant factors on finance, email and administrator accounts.<\/li>\n\n\n\n<li><strong>Lock down your Companies House footprint.<\/strong>\u00a0Limit filing authority to two named officers, secure the WebFiling account with MFA, switch on filing alerts, and complete director identity verification ahead of the November 2026 deadline.<\/li>\n\n\n\n<li><strong>Harden and monitor your domain estate.<\/strong>\u00a0Deploy SPF, DKIM and DMARC at enforcement, register obvious lookalike domains defensively, and monitor for new registrations and fake social handles.<\/li>\n\n\n\n<li><strong>Segregate duties and train on the real scenario.<\/strong>\u00a0Nobody who can modify a supplier record should be able to release a payment to it. Then run simulations of bank-detail change requests and director urgency \u2014 walking teams through\u00a0<a href=\"https:\/\/trustpair.com\/gb\/blog\/third-party-fraud-how-to-fight-back-in-your-business\/\" target=\"_blank\" rel=\"noopener\">how third-party fraud plays out inside a finance team<\/a>\u00a0makes useful training material, because it shows how ordinary the attack looks from the inside.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"your-next-steps\">Your Next Steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you are in an active incident, work the seven steps above and file your reports today. If you are reading this to prepare, do three things this week: audit who in your organisation can change a supplier&#8217;s bank details, check your Companies House filings and business credit reports, and pressure-test what would actually happen if a convincing bank-detail change request landed in your accounts payable inbox tomorrow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then close the verification gap for good. Trustpair validates supplier and third-party account ownership automatically across 170+ countries \u2014 at onboarding, on every data change, and before each payment run \u2014 so impersonation attempts are blocked at the payment stage instead of discovered at reconciliation. <a href=\"https:\/\/trustpair.com\/gb\/demo-5\/\" target=\"_blank\" rel=\"noopener\">Book a demo with a fraud expert<\/a> to see how it fits your existing ERP and P2P workflows.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If your business is being impersonated right now, act in this order: freeze outgoing payments to any recently changed bank details, lock and re-credential the affected accounts, preserve every message as evidence, then report the fraud to your bank and Action Fraud the same day. Speed matters more than certainty: Faster Payments settle in seconds, [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":21844,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,78],"tags":[],"class_list":["post-52589","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fraud-protection","category-risk-management-2"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to Respond to a Company Impersonation Scam: A 7-Step Playbook - Trustpair<\/title>\n<meta name=\"description\" content=\"Being impersonated? Respond to a company impersonation scam in 7 steps: freeze payments, report to Action Fraud and Companies House, and block the next attempt.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Respond to a Company Impersonation Scam: A 7-Step Playbook - Trustpair\" \/>\n<meta property=\"og:description\" content=\"Being impersonated? Respond to a company impersonation scam in 7 steps: freeze payments, report to Action Fraud and Companies House, and block the next attempt.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/\" \/>\n<meta property=\"og:site_name\" content=\"Trustpair\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-16T09:58:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-16T10:11:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trustpair.com\/wp-content\/uploads\/Deepfake-Scam.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1008\" \/>\n\t<meta property=\"og:image:height\" content=\"688\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Julia Suarez\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Julia Suarez\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/\"},\"author\":{\"name\":\"Julia Suarez\",\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/#\\\/schema\\\/person\\\/f5876cae04765e0f672445de6e8b156e\"},\"headline\":\"How to Respond to a Company Impersonation Scam: A 7-Step Playbook\",\"datePublished\":\"2026-09-16T09:58:00+00:00\",\"dateModified\":\"2026-09-16T10:11:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/\"},\"wordCount\":3637,\"publisher\":{\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustpair.com\\\/wp-content\\\/uploads\\\/Deepfake-Scam.png\",\"articleSection\":[\"Fraud protection\",\"Risk Management\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/\",\"url\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/\",\"name\":\"How to Respond to a Company Impersonation Scam: A 7-Step Playbook - Trustpair\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustpair.com\\\/wp-content\\\/uploads\\\/Deepfake-Scam.png\",\"datePublished\":\"2026-09-16T09:58:00+00:00\",\"dateModified\":\"2026-09-16T10:11:57+00:00\",\"description\":\"Being impersonated? Respond to a company impersonation scam in 7 steps: freeze payments, report to Action Fraud and Companies House, and block the next attempt.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustpair.com\\\/wp-content\\\/uploads\\\/Deepfake-Scam.png\",\"contentUrl\":\"https:\\\/\\\/trustpair.com\\\/wp-content\\\/uploads\\\/Deepfake-Scam.png\",\"width\":1008,\"height\":688},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/blog\\\/gb-blog-how-to-respond-to-a-company-impersonation-scam\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Respond to a Company Impersonation Scam: A 7-Step Playbook\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/#website\",\"url\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/\",\"name\":\"Trustpair\",\"description\":\"Leading Payment Fraud Prevention Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/#organization\",\"name\":\"Trustpair\",\"url\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/trustpair.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Logo-trustpair.svg\",\"contentUrl\":\"https:\\\/\\\/trustpair.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Logo-trustpair.svg\",\"width\":304,\"height\":73,\"caption\":\"Trustpair\"},\"image\":{\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/trustpair.com\\\/gb\\\/#\\\/schema\\\/person\\\/f5876cae04765e0f672445de6e8b156e\",\"name\":\"Julia Suarez\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fd9f3c948b449649167e4d1747849d71f61c74c1e83ac31ea56617e64a9aec5b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fd9f3c948b449649167e4d1747849d71f61c74c1e83ac31ea56617e64a9aec5b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fd9f3c948b449649167e4d1747849d71f61c74c1e83ac31ea56617e64a9aec5b?s=96&d=mm&r=g\",\"caption\":\"Julia Suarez\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Respond to a Company Impersonation Scam: A 7-Step Playbook - Trustpair","description":"Being impersonated? Respond to a company impersonation scam in 7 steps: freeze payments, report to Action Fraud and Companies House, and block the next attempt.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/","og_locale":"en_GB","og_type":"article","og_title":"How to Respond to a Company Impersonation Scam: A 7-Step Playbook - Trustpair","og_description":"Being impersonated? Respond to a company impersonation scam in 7 steps: freeze payments, report to Action Fraud and Companies House, and block the next attempt.","og_url":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/","og_site_name":"Trustpair","article_published_time":"2026-09-16T09:58:00+00:00","article_modified_time":"2026-09-16T10:11:57+00:00","og_image":[{"width":1008,"height":688,"url":"https:\/\/trustpair.com\/wp-content\/uploads\/Deepfake-Scam.png","type":"image\/png"}],"author":"Julia Suarez","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Julia Suarez","Estimated reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/#article","isPartOf":{"@id":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/"},"author":{"name":"Julia Suarez","@id":"https:\/\/trustpair.com\/gb\/#\/schema\/person\/f5876cae04765e0f672445de6e8b156e"},"headline":"How to Respond to a Company Impersonation Scam: A 7-Step Playbook","datePublished":"2026-09-16T09:58:00+00:00","dateModified":"2026-09-16T10:11:57+00:00","mainEntityOfPage":{"@id":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/"},"wordCount":3637,"publisher":{"@id":"https:\/\/trustpair.com\/gb\/#organization"},"image":{"@id":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/#primaryimage"},"thumbnailUrl":"https:\/\/trustpair.com\/wp-content\/uploads\/Deepfake-Scam.png","articleSection":["Fraud protection","Risk Management"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/","url":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/","name":"How to Respond to a Company Impersonation Scam: A 7-Step Playbook - Trustpair","isPartOf":{"@id":"https:\/\/trustpair.com\/gb\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/#primaryimage"},"image":{"@id":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/#primaryimage"},"thumbnailUrl":"https:\/\/trustpair.com\/wp-content\/uploads\/Deepfake-Scam.png","datePublished":"2026-09-16T09:58:00+00:00","dateModified":"2026-09-16T10:11:57+00:00","description":"Being impersonated? Respond to a company impersonation scam in 7 steps: freeze payments, report to Action Fraud and Companies House, and block the next attempt.","breadcrumb":{"@id":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/#primaryimage","url":"https:\/\/trustpair.com\/wp-content\/uploads\/Deepfake-Scam.png","contentUrl":"https:\/\/trustpair.com\/wp-content\/uploads\/Deepfake-Scam.png","width":1008,"height":688},{"@type":"BreadcrumbList","@id":"https:\/\/trustpair.com\/gb\/blog\/gb-blog-how-to-respond-to-a-company-impersonation-scam\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/trustpair.com\/gb\/"},{"@type":"ListItem","position":2,"name":"How to Respond to a Company Impersonation Scam: A 7-Step Playbook"}]},{"@type":"WebSite","@id":"https:\/\/trustpair.com\/gb\/#website","url":"https:\/\/trustpair.com\/gb\/","name":"Trustpair","description":"Leading Payment Fraud Prevention Platform","publisher":{"@id":"https:\/\/trustpair.com\/gb\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustpair.com\/gb\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/trustpair.com\/gb\/#organization","name":"Trustpair","url":"https:\/\/trustpair.com\/gb\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/trustpair.com\/gb\/#\/schema\/logo\/image\/","url":"https:\/\/trustpair.com\/wp-content\/uploads\/2024\/07\/Logo-trustpair.svg","contentUrl":"https:\/\/trustpair.com\/wp-content\/uploads\/2024\/07\/Logo-trustpair.svg","width":304,"height":73,"caption":"Trustpair"},"image":{"@id":"https:\/\/trustpair.com\/gb\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/trustpair.com\/gb\/#\/schema\/person\/f5876cae04765e0f672445de6e8b156e","name":"Julia Suarez","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/secure.gravatar.com\/avatar\/fd9f3c948b449649167e4d1747849d71f61c74c1e83ac31ea56617e64a9aec5b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/fd9f3c948b449649167e4d1747849d71f61c74c1e83ac31ea56617e64a9aec5b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fd9f3c948b449649167e4d1747849d71f61c74c1e83ac31ea56617e64a9aec5b?s=96&d=mm&r=g","caption":"Julia Suarez"}}]}},"_links":{"self":[{"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/posts\/52589","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/comments?post=52589"}],"version-history":[{"count":8,"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/posts\/52589\/revisions"}],"predecessor-version":[{"id":52654,"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/posts\/52589\/revisions\/52654"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/media\/21844"}],"wp:attachment":[{"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/media?parent=52589"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/categories?post=52589"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trustpair.com\/gb\/wp-json\/wp\/v2\/tags?post=52589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}