Taking payments
13 min read
October 4, 2026

How to spot and prevent invoice fraud

Adfin team

Invoice fraud losses in the UK are falling. UK Finance recorded £41.3m across 2,305 cases in 2025, down 4%, and called it the lowest loss total ever reported. What hasn't improved is who carries it: business accounts took 68% of those losses, and 48% of the money came back.

In this article

The short version

  • Invoice and mandate scams cost £41.3m across 2,305 cases in 2025, down 4% and the lowest total UK Finance has reported.
  • Reimbursement reaches individuals, micro-enterprises and charities: fewer than ten staff, and turnover or a balance sheet total no higher than €2 million, with both limbs required.
  • Above either limb you're outside the regime entirely, and you have no negligence claim against your bank for a payment you authorised, which Philipp v Barclays settled.
  • Gross negligence here means "a significant degree of carelessness" against four procedural standards, and the bank has to prove it.
  • Two official datasets put the average loss 2.6 times apart, so any average needs its source beside it.

What the 2026 data says

Most guidance on this subject opens by telling you invoice fraud is surging, and on the primary data for 2025 it isn't.

UK Finance's Annual Fraud Report 2026 puts invoice and mandate scams at £41.3m across 2,305 cases, down 4% and 2%, and calls that the "Lowest loss total ever reported". Authorised push payment fraud overall went the other way, up 19% to £576.4m, with personal losses up 26% and non-personal losses down 11%. So the category aimed at your accounts payable function shrank in a year when the fraud around it grew.

Your position still isn't comfortable. Business accounts carried £28.0m of that £41.3m, and only 48% came back. UK Finance on why business victims are harder to protect: "Typically, businesses make genuine higher-value payments more regularly, making it harder to spot and stop a fraudulent one."

Two official datasets then disagree about a typical loss by a factor of 2.6.

They count different things. UK Finance aggregates what banks report; Action Fraud counts what victims choose to report, and that population skews to larger losses. One month isn't a year either, so name whichever figure you use.

One gap as you go looking for material: Take Five, the UK's flagship fraud awareness campaign, lists eleven scam types and invoice fraud isn't among them.

How the fraud works, under four official names

Criminals are "impersonating others, creating or amending invoices and diverting payments to bank accounts under their own control", in the National Crime Agency's words.

One crime, four official names: payment diversion fraud to the NCA, mandate fraud to Action Fraud, business email compromise to the NCSC, and an invoice or mandate scam to UK Finance. Search one term and you'll miss the guidance filed under the other three.

Its four warning indicators are the closest thing to a checklist any official body publishes. Have you been asked to "urgently process a payment that is large or unusual"? To "change the bank details of an existing supplier or to set up a new supplier"? Is "the language used in the email inconsistent with that of the genuine sender"? Does the email or address "contain spelling mistakes"?

Note the second, because setting up a new supplier is on that list beside amending an existing one, so your controls need to reach both.

Whether you'd be reimbursed, and the test that decides it

For payments made on or after 7 October 2024, UK transfers over Faster Payments and CHAPS carry a reimbursement right for payers the regime covers, and it covers fewer businesses than most summaries suggest. The Payment Systems Regulator states that "The protections apply to individuals, microenterprises and charities", and doesn't define microenterprise on that page. The binding direction does: an enterprise that "employs fewer than ten persons and that has either an annual turnover or annual balance sheet total that does not exceed €2 million". Both limbs have to be met.

Inside that scope, the right is capped at £85,000, with an optional £100 excess and a 13 month claim window. A charity qualifies separately, where annual income is under £1 million and it's registered under the relevant Charities Act.

Two details make the test harder to apply than it looks. The currency isn't consistent inside the regulator's own paperwork: Specific Direction 21 says €2 million, and a draft of the scheme rules numbered v0.7 says £2 million. SD21 is the finalised, signed direction, so work from €2 million.

Group structure counts too. The FCA's glossary adds that "articles 3 to 6 of the Annex to the Micro-enterprise Recommendation" apply when you test the criteria, and those articles aggregate partner and linked enterprises.

Above either limb there's no reimbursement right, and no fallback claim against your bank. In Philipp v Barclays the Supreme Court kept the Quincecare duty alive but held that "These principles have no application to a situation where, as in the present case, the customer is a victim of APP fraud." A payment you authorised is a payment your bank was obliged to carry out.

What's left is an attempt at recovery. Faster Payments, "once sent, cannot be cancelled", and your bank has to act within a maximum of two working days of being told. Then the sentence that decides most cases: "No funds would be removed without the consent of the receiving customer." That page describes recovering a misdirected payment, and we couldn't verify that it formally covers a payment induced by fraud. Either way recovery needs the recipient to agree, and a fraudster doesn't.

One clause to carry through all of this: the government intends to consolidate the PSR's functions entirely within the FCA and transfer the reimbursement requirements across, with no date announced.

What gross negligence means here

Plenty of articles imply that failing to check a bank-detail change makes you grossly negligent and costs you your claim. In this regime it doesn't work that way, and the exception attaches to four procedural standards in the PSR's consumer standard of caution, SR1: have regard to any intervention by your bank or a competent national authority; report promptly once you learn or suspect a scam, and within 13 months in any event; answer reasonable and proportionate requests for information; and consent to your bank reporting to the police, or report it yourself.

The bar is high and the burden isn't yours. The PSR's guidance calls gross negligence "a higher standard than the standard of negligence under common law", needing "a significant degree of carelessness", and says "The burden of proof falls exclusively upon the PSP".

Eligible at the ombudsman, with no reimbursement right

The Financial Ombudsman Service will look at a complaint from a small business, meaning one that "is not a micro-enterprise, has an annual turnover of less than £6.5 million and has a balance sheet total of less than £5 million, or employs fewer than 50 people".

Set that beside the reimbursement threshold and a band opens up: a twelve-person business turning over £3m can bring a complaint, and has no reimbursement right to complain about. FOS decides what's fair and reasonable and isn't confined to the PSR's rules, and complaints referred on or after 1 April 2026 carry an award limit of £455,000. How it treats cases outside the regime we couldn't establish, so read this as eligibility and not entitlement.

The controls, and which ones are official

Competitor pages give you one undifferentiated list. The split below matters if you document your controls for an insurer or an auditor, because much of what circulates as official guidance isn't.

The callback is the control that catches a changed bank detail, and one thing decides whether it works: the number has to be one you already held, since a number on the invoice or in the email footer came from whoever sent it.

The first hour after you've paid one

No official body publishes an hour-by-hour checklist, so here is one, with the first four steps drawn from primary sources and the last from us.

Also ours: as a general rule of contract, paying a fraudster doesn't discharge what you owe, so the loss can land on you twice. No official source we fetched says so, so take advice on your own facts.

Your own invoices are somebody else's exposure

Everything above treats you as the payer. Turn it round, because the invoices you send are raw material for the same attack on your customers.

The official material stops just short of the argument. The NCA says "emails can be intercepted or diverted" and describes the mechanism as "creating or amending invoices". The NCSC's suggested line to customers is that "our bank details will not change at any point", and Take Five tells payers that "Companies rarely change their bank details". All of it assumes a document carrying your account number, travelling by email, for your customer to retype.

Our reading, and it needs the label because no regulator, Pay.UK, UK Finance or NCSC source we fetched makes the point: if your customer never retypes your bank details, the attack the NCA describes has nothing to act on. A mandate authorised once, or a payment link approved inside their own banking app, leaves no digits on the invoice for anybody to alter.

Three hedges belong with it. This attack goes and fraud generally doesn't, a fraudulent payment link being a live risk of its own. Direct debit moves control of the collection to you, bringing mandate misuse and indemnity claims. And no official source compares invoice-redirection risk across methods, so nobody can size the difference.

So the practical change is to stop treating the emailed PDF as your payment instruction: collect by mandate where the relationship recurs, and send a payment link where it doesn't. Adfin does both from one invoice, though the argument holds whoever you collect through.

Common questions

Is invoice fraud against UK businesses getting worse? Not on the primary data. UK Finance recorded £41.3m of losses across 2,305 cases in 2025, down 4% and the lowest total ever reported. Non-personal losses across all authorised push payment fraud fell 11% that year, while personal losses rose 26%.

Will my bank refund my business if we pay a fraudulent invoice? Only if you're covered: the regime reaches individuals, micro-enterprises and charities. A micro-enterprise employs fewer than ten people and has turnover or a balance sheet total no higher than €2 million. Above either one there's no reimbursement right, and no claim against your bank for a payment you authorised.

What counts as a micro-enterprise for APP fraud reimbursement? Specific Direction 21 defines it as an enterprise that "employs fewer than ten persons and that has either an annual turnover or annual balance sheet total that does not exceed €2 million". One PSR document gives it in euros and a draft of the scheme rules gives £2 million. Partner and linked enterprises are aggregated, so a small subsidiary of a large group won't qualify.

Does gross negligence mean we failed to check the bank details? No. It attaches to four procedural standards: heeding your bank's interventions, reporting promptly and within 13 months, answering reasonable information requests, and consenting to a police report. The PSR calls the standard "a significant degree of carelessness" and puts the burden of proof "exclusively upon the PSP".

Can we complain to the Financial Ombudsman if we're too big to be reimbursed? You may be able to. Its small business test is much wider, reaching businesses under £6.5 million of turnover or fewer than 50 staff, and it decides on what's fair and reasonable. Eligibility to complain isn't an entitlement to money, and we couldn't verify how it treats these cases.

What should we do in the first hour after paying a fraudulent invoice? Ring your bank on a number from its official website, tell whoever runs your IT because the mailbox may still be compromised, and report to Action Fraud, plus gov.uk/report-cyber if your systems were involved. Then tell the genuine supplier and preserve the email headers.

Sources

This article is information about UK fraud reporting, the APP reimbursement rules and the case law around them, and it isn't legal advice. Whether you meet the micro-enterprise test decides whether you have a reimbursement right at all, the regulator's own documents give that threshold in two currencies, and group structure can change the answer, so take your position to a solicitor before relying on it. Last updated August 2026.

Adfin team