Invoice fraud losses in the UK are falling. UK Finance recorded £41.3m across 2,305 cases in 2025, down 4%, and called it the lowest loss total ever reported. What hasn't improved is who carries it: business accounts took 68% of those losses, and 48% of the money came back.
In this article
The short version
- Invoice and mandate scams cost £41.3m across 2,305 cases in 2025, down 4% and the lowest total UK Finance has reported.
- Reimbursement reaches individuals, micro-enterprises and charities: fewer than ten staff, and turnover or a balance sheet total no higher than €2 million, with both limbs required.
- Above either limb you're outside the regime entirely, and you have no negligence claim against your bank for a payment you authorised, which Philipp v Barclays settled.
- Gross negligence here means "a significant degree of carelessness" against four procedural standards, and the bank has to prove it.
- Two official datasets put the average loss 2.6 times apart, so any average needs its source beside it.
What the 2026 data says
Most guidance on this subject opens by telling you invoice fraud is surging, and on the primary data for 2025 it isn't.
UK Finance's Annual Fraud Report 2026 puts invoice and mandate scams at £41.3m across 2,305 cases, down 4% and 2%, and calls that the "Lowest loss total ever reported". Authorised push payment fraud overall went the other way, up 19% to £576.4m, with personal losses up 26% and non-personal losses down 11%. So the category aimed at your accounts payable function shrank in a year when the fraud around it grew.
Your position still isn't comfortable. Business accounts carried £28.0m of that £41.3m, and only 48% came back. UK Finance on why business victims are harder to protect: "Typically, businesses make genuine higher-value payments more regularly, making it harder to spot and stop a fraudulent one."
Two official datasets then disagree about a typical loss by a factor of 2.6.
| Source | What it says |
|---|---|
| UK Finance, full year 2025, bank-reported | £41.3m across 2,305 cases, about £17,900 a case. Our arithmetic from their two figures |
| Action Fraud data cited by the NCA, September 2025 | £3,908,086 across 83 reported cases in that month, "averaging more than £47,000 per case" |
They count different things. UK Finance aggregates what banks report; Action Fraud counts what victims choose to report, and that population skews to larger losses. One month isn't a year either, so name whichever figure you use.
One gap as you go looking for material: Take Five, the UK's flagship fraud awareness campaign, lists eleven scam types and invoice fraud isn't among them.
How the fraud works, under four official names
Criminals are "impersonating others, creating or amending invoices and diverting payments to bank accounts under their own control", in the National Crime Agency's words.
One crime, four official names: payment diversion fraud to the NCA, mandate fraud to Action Fraud, business email compromise to the NCSC, and an invoice or mandate scam to UK Finance. Search one term and you'll miss the guidance filed under the other three.
Its four warning indicators are the closest thing to a checklist any official body publishes. Have you been asked to "urgently process a payment that is large or unusual"? To "change the bank details of an existing supplier or to set up a new supplier"? Is "the language used in the email inconsistent with that of the genuine sender"? Does the email or address "contain spelling mistakes"?
Note the second, because setting up a new supplier is on that list beside amending an existing one, so your controls need to reach both.
Whether you'd be reimbursed, and the test that decides it
For payments made on or after 7 October 2024, UK transfers over Faster Payments and CHAPS carry a reimbursement right for payers the regime covers, and it covers fewer businesses than most summaries suggest. The Payment Systems Regulator states that "The protections apply to individuals, microenterprises and charities", and doesn't define microenterprise on that page. The binding direction does: an enterprise that "employs fewer than ten persons and that has either an annual turnover or annual balance sheet total that does not exceed €2 million". Both limbs have to be met.
Inside that scope, the right is capped at £85,000, with an optional £100 excess and a 13 month claim window. A charity qualifies separately, where annual income is under £1 million and it's registered under the relevant Charities Act.
| Your business | Reimbursement right | Ombudsman complaint |
|---|---|---|
| Six staff, £400,000 turnover | Yes, inside the regime | Yes |
| Eleven staff, £50,000 turnover | No, over the headcount limb | Yes, as a small business |
| Nine staff, €5 million turnover | No, over the financial limb | Yes, as a small business |
| Nine staff, majority-owned by a large group | Aggregated with the group, so usually no | Worth advice on your own group |
| Sixty staff, £10 million turnover | No | No, above both ombudsman limbs |
Two details make the test harder to apply than it looks. The currency isn't consistent inside the regulator's own paperwork: Specific Direction 21 says €2 million, and a draft of the scheme rules numbered v0.7 says £2 million. SD21 is the finalised, signed direction, so work from €2 million.
Group structure counts too. The FCA's glossary adds that "articles 3 to 6 of the Annex to the Micro-enterprise Recommendation" apply when you test the criteria, and those articles aggregate partner and linked enterprises.
Above either limb there's no reimbursement right, and no fallback claim against your bank. In Philipp v Barclays the Supreme Court kept the Quincecare duty alive but held that "These principles have no application to a situation where, as in the present case, the customer is a victim of APP fraud." A payment you authorised is a payment your bank was obliged to carry out.
What's left is an attempt at recovery. Faster Payments, "once sent, cannot be cancelled", and your bank has to act within a maximum of two working days of being told. Then the sentence that decides most cases: "No funds would be removed without the consent of the receiving customer." That page describes recovering a misdirected payment, and we couldn't verify that it formally covers a payment induced by fraud. Either way recovery needs the recipient to agree, and a fraudster doesn't.
One clause to carry through all of this: the government intends to consolidate the PSR's functions entirely within the FCA and transfer the reimbursement requirements across, with no date announced.
What gross negligence means here
Plenty of articles imply that failing to check a bank-detail change makes you grossly negligent and costs you your claim. In this regime it doesn't work that way, and the exception attaches to four procedural standards in the PSR's consumer standard of caution, SR1: have regard to any intervention by your bank or a competent national authority; report promptly once you learn or suspect a scam, and within 13 months in any event; answer reasonable and proportionate requests for information; and consent to your bank reporting to the police, or report it yourself.
The bar is high and the burden isn't yours. The PSR's guidance calls gross negligence "a higher standard than the standard of negligence under common law", needing "a significant degree of carelessness", and says "The burden of proof falls exclusively upon the PSP".
Eligible at the ombudsman, with no reimbursement right
The Financial Ombudsman Service will look at a complaint from a small business, meaning one that "is not a micro-enterprise, has an annual turnover of less than £6.5 million and has a balance sheet total of less than £5 million, or employs fewer than 50 people".
Set that beside the reimbursement threshold and a band opens up: a twelve-person business turning over £3m can bring a complaint, and has no reimbursement right to complain about. FOS decides what's fair and reasonable and isn't confined to the PSR's rules, and complaints referred on or after 1 April 2026 carry an award limit of £455,000. How it treats cases outside the regime we couldn't establish, so read this as eligibility and not entitlement.
The controls, and which ones are official
Competitor pages give you one undifferentiated list. The split below matters if you document your controls for an insurer or an auditor, because much of what circulates as official guidance isn't.
| Control | Where it comes from |
|---|---|
| Call the supplier back on a number you already held | Sourced. NCA and NatWest: "Call the genuine supplier on a previously used phone number before you transfer money, as emails can be intercepted or diverted" |
| Verify important email requests through a second channel | Sourced. NCSC: "verified using a second type of communication (such as SMS message, a phone call, logging into an account, or confirmation by post or in-person)" |
| Treat a change of bank details as suspicious by default | Sourced. Take Five: "Companies rarely change their bank details" |
| Tell your customers your own details will not change | Sourced. NCSC: "our bank details will not change at any point" |
| Check at every stage of the payment run, not only at approval | Sourced. Take Five: "staff members at every stage of the payment process" |
| Limit what you publish about your business and finance staff | Sourced. Take Five on information shared online, NCSC on privacy settings |
| Read the Confirmation of Payee response properly | Sourced, with a caveat: it checks the account name only, never the sort code and account number, and a business account can legitimately return a close match on a trading name |
| Dual authorisation above a value you set | Ours. No official page we fetched recommends it by name |
| Purchase order matching before a payment is released | Ours |
| A verification step when you onboard a supplier | Partly ours. The NCA names new supplier setup as a red flag, so the risk is sourced and the control is ours |
| Payment limits, out-of-hours rules, escalation thresholds | Ours |
The callback is the control that catches a changed bank detail, and one thing decides whether it works: the number has to be one you already held, since a number on the invoice or in the email footer came from whoever sent it.
The first hour after you've paid one
No official body publishes an hour-by-hour checklist, so here is one, with the first four steps drawn from primary sources and the last from us.
| Step | What to do, and where it comes from |
|---|---|
| 1. Your bank | Ring it on its official website number, never a number from the email. The NCA's wording is to "act fast!" |
| 2. Whoever runs your IT | The compromised mailbox may still be live, so the same fraud can run on your next invoice. NCSC: "the sooner they know, the sooner they can help" |
| 3. Action Fraud | Report through actionfraud.police.uk. Two official pages give phone numbers a digit apart, so use the website rather than a printed number. In Scotland the NCA's guidance is to call 101 and your bank |
| 4. gov.uk/report-cyber | Where your own systems were compromised, report the cyber incident separately |
| 5. Ours, not official guidance | Tell the genuine supplier, whose mailbox may be the compromised one; preserve the email headers; check whether other invoices that period went to the same account |
Also ours: as a general rule of contract, paying a fraudster doesn't discharge what you owe, so the loss can land on you twice. No official source we fetched says so, so take advice on your own facts.
Your own invoices are somebody else's exposure
Everything above treats you as the payer. Turn it round, because the invoices you send are raw material for the same attack on your customers.
The official material stops just short of the argument. The NCA says "emails can be intercepted or diverted" and describes the mechanism as "creating or amending invoices". The NCSC's suggested line to customers is that "our bank details will not change at any point", and Take Five tells payers that "Companies rarely change their bank details". All of it assumes a document carrying your account number, travelling by email, for your customer to retype.
Our reading, and it needs the label because no regulator, Pay.UK, UK Finance or NCSC source we fetched makes the point: if your customer never retypes your bank details, the attack the NCA describes has nothing to act on. A mandate authorised once, or a payment link approved inside their own banking app, leaves no digits on the invoice for anybody to alter.
Three hedges belong with it. This attack goes and fraud generally doesn't, a fraudulent payment link being a live risk of its own. Direct debit moves control of the collection to you, bringing mandate misuse and indemnity claims. And no official source compares invoice-redirection risk across methods, so nobody can size the difference.
So the practical change is to stop treating the emailed PDF as your payment instruction: collect by mandate where the relationship recurs, and send a payment link where it doesn't. Adfin does both from one invoice, though the argument holds whoever you collect through.
Common questions
Is invoice fraud against UK businesses getting worse? Not on the primary data. UK Finance recorded £41.3m of losses across 2,305 cases in 2025, down 4% and the lowest total ever reported. Non-personal losses across all authorised push payment fraud fell 11% that year, while personal losses rose 26%.
Will my bank refund my business if we pay a fraudulent invoice? Only if you're covered: the regime reaches individuals, micro-enterprises and charities. A micro-enterprise employs fewer than ten people and has turnover or a balance sheet total no higher than €2 million. Above either one there's no reimbursement right, and no claim against your bank for a payment you authorised.
What counts as a micro-enterprise for APP fraud reimbursement? Specific Direction 21 defines it as an enterprise that "employs fewer than ten persons and that has either an annual turnover or annual balance sheet total that does not exceed €2 million". One PSR document gives it in euros and a draft of the scheme rules gives £2 million. Partner and linked enterprises are aggregated, so a small subsidiary of a large group won't qualify.
Does gross negligence mean we failed to check the bank details? No. It attaches to four procedural standards: heeding your bank's interventions, reporting promptly and within 13 months, answering reasonable information requests, and consenting to a police report. The PSR calls the standard "a significant degree of carelessness" and puts the burden of proof "exclusively upon the PSP".
Can we complain to the Financial Ombudsman if we're too big to be reimbursed? You may be able to. Its small business test is much wider, reaching businesses under £6.5 million of turnover or fewer than 50 staff, and it decides on what's fair and reasonable. Eligibility to complain isn't an entitlement to money, and we couldn't verify how it treats these cases.
What should we do in the first hour after paying a fraudulent invoice? Ring your bank on a number from its official website, tell whoever runs your IT because the mailbox may still be compromised, and report to Action Fraud, plus gov.uk/report-cyber if your systems were involved. Then tell the genuine supplier and preserve the email headers.
Sources
- Philipp v Barclays Bank UK PLC [2023] UKSC 25 (accurate as of August 2026)
- Action Fraud — A to Z of fraud, mandate fraud (accurate as of August 2026)
- Action Fraud — reporting a fraud (accurate as of August 2026)
- FCA Handbook — glossary, micro-enterprise (accurate as of August 2026)
- Financial Ombudsman Service — compensation limits (accurate as of August 2026)
- Financial Ombudsman Service — can we help your business (accurate as of August 2026)
- GOV.UK — report a cyber incident (accurate as of August 2026)
- HM Treasury — a streamlined approach to payment systems regulation, consultation response (accurate as of August 2026)
- National Crime Agency — payment diversion fraud (accurate as of August 2026)
- NCSC — business email compromise and payment diversion fraud (accurate as of August 2026)
- NCSC — respond and recover, business payment fraud (accurate as of August 2026)
- Payment Systems Regulator — APP fraud reimbursement protections (accurate as of August 2026)
- Payment Systems Regulator — APP reimbursement scheme rules for FPS, schedule 4 draft v0.7 (accurate as of August 2026)
- Payment Systems Regulator — SR1 consumer standard of caution exception (accurate as of August 2026)
- Payment Systems Regulator — SR1 consumer standard of caution guidance (accurate as of August 2026)
- Payment Systems Regulator — Specific Direction 21, CHAPS reimbursement (accurate as of August 2026)
- Faster Payments — what happens if I have sent a payment to the wrong place (accurate as of August 2026)
- Take Five — protect your business (accurate as of August 2026)
- UK Finance — Annual Fraud Report 2026 (accurate as of August 2026)
This article is information about UK fraud reporting, the APP reimbursement rules and the case law around them, and it isn't legal advice. Whether you meet the micro-enterprise test decides whether you have a reimbursement right at all, the regulator's own documents give that threshold in two currencies, and group structure can change the answer, so take your position to a solicitor before relying on it. Last updated August 2026.
