A supplier calls your office phone. It sounds exactly like the person you’ve dealt with for three years, right down to the slight cough halfway through the sentence. They say the bank details have changed and could the next invoice go to the new account. You say yes, because why wouldn’t you. The voice on the line was never a person at all.
The number that should worry every trades business
UK Finance’s Annual Fraud Report 2026 puts total payment fraud losses at £1.28 billion in 2025, up 4% on the year before. The sharpest rise was in authorised push payment fraud, the kind built on impersonation rather than hacking, which climbed 19% to £576.4 million. UK Finance names the cause directly: organised criminal groups are increasingly using AI tools, including deepfakes, cloned voices and synthetic identities, to impersonate people you already trust and bypass the checks banks have spent years building.
Inside that total sits a figure that hits trades and small firms hardest. Invoice and mandate fraud, the “your supplier’s bank details have changed” scam, accounted for 2,305 reported cases and £41.3 million lost, an average of almost £18,000 a hit, with roughly two thirds of that coming out of business accounts rather than personal ones. For a plumbing firm, an electrical contractor or a small building company, £18,000 is not a rounding error. It is a month’s margin, sometimes a year’s.
What this actually looks like on a job
We’re not talking about a badly spelled email any more. Banks are warning that AI-driven fraud is now genuinely hard to spot, and the mechanics explain why. Cloning a voice convincingly takes a few seconds of someone talking, pulled from a voicemail greeting, a video call recording or a clip posted online. From there a fraudster can ring a bookkeeper sounding exactly like the boss, or ring a site manager sounding exactly like a regular supplier, and ask for a payment or a bank detail change that seems completely routine. The bank-detail switch is the classic version: a fake message, call or email claims a supplier has moved banks, the next invoice goes to the new account, and the money is gone by the time anyone checks.
Why trades and small firms are the easy targets
Deepfake fraud does not exploit a software flaw. It exploits trust and speed, and small trades businesses run on both. Approvals often sit with one or two people who know each supplier personally and want to keep a job moving, not stop it for a paperwork check. There is rarely a finance team to slow a payment down, and the person answering the phone is usually the same person who has the authority to send money. That combination, fast decisions plus informal verification, is exactly what this kind of fraud is built to exploit. It is also worth naming honestly: the UK’s own fraud reporting shows victims of this type of scam are not careless people. The calls and messages are built specifically to sound unremarkable.
The other reason trades firms get hit is exposure. A working website, a company Facebook page, and a director who appears in a five-minute local news clip or a supplier’s promotional video is all a fraudster needs. Voice cloning tools that were research demos two years ago are now consumer products, and a few seconds of clean audio is enough to build a convincing sample. None of that means going quiet online is the answer. It means treating every unexpected payment request the same way regardless of how it reaches you, because a phone call is no longer proof of who is on the other end of it.
The one habit that stops nearly all of it
There is a single control that blocks almost every version of this scam, and it costs nothing to put in place. Never action a payment or a bank detail change on the strength of an inbound call, voicemail or message alone, however convincing it sounds. Hang up, and call the supplier or colleague back using a number you already have on file, not one given to you in the same call or message. Security guidance built around AI-era fraud keeps landing on the same answer: verification has to happen on a separate, pre-established channel every single time, with no exceptions made for how urgent or ordinary the request sounds. Agree this rule with everyone who can approve a payment, in writing, before you ever need it.
What we build for clients
We build small, boring automations on purpose, because boring is what stops this. For clients handling supplier payments, we set up a simple check step: any change to bank details or payment instructions triggers an internal alert and a callback requirement before the change takes effect, logged automatically so nobody has to remember to do it under pressure. It is not glamorous AI. It is the kind of workflow that turns a moment of “that sounded fine” into a moment of “let me just confirm that first,” which is the entire difference between a normal Tuesday and an £18,000 loss.
If a scam does get through, speed matters more than anything else. Call your bank straight away and ask for a payment recall. Some transfers can still be pulled back within the first 24 to 72 hours, but the window closes fast, so the first phone call after the payment is as important as the verification step that should have stopped it.
AI has made impersonation cheap and convincing, and the fraud figures show criminals already know it. The businesses that stay safe will not be the ones that avoid AI. They will be the ones that build one deliberate pause into how money moves, and stick to it every time, no exceptions.
Report it too, even if the payment was recovered. Suspicious calls and messages can be reported to Action Fraud, and any successful loss should be reported to your bank and to Action Fraud on the same day. The reports feed the same fraud data that produced the £1.28 billion figure above, and the sooner a pattern is logged, the sooner banks and telecoms providers can block the numbers and accounts behind it for the next business down the road.