The Email That Could Cost You £10,000
| In short: The most expensive cyber-attacks on small businesses often involve no “hacking” at all — just a convincing email that tricks someone into paying the wrong person. Here are the four scams aimed squarely at businesses, and the one simple habit that stops nearly all of them. |
Picture this. It’s Friday afternoon, you’re halfway out the door, and an email lands from a supplier you deal with all the time. Same logo, same friendly sign-off, an invoice attached just like always. The only difference is a polite little note saying they’ve changed banks, with shiny new account details. You pay it. And the money sails straight into a criminal’s account, never to be seen again.
No alarms went off. Nobody “broke in.” That’s exactly why this kind of scam works — and why it quietly costs UK businesses a fortune every year. The good news? Once you know the tricks, they’re surprisingly easy to spot.
Scam 1: The Fake Invoice (“We’ve Changed Banks”)
A criminal poses as a genuine supplier and sends an invoice with new payment details. The cheeky ones have been quietly lurking in an email chain for weeks, waiting for a real invoice so they can swoop in and “update” where the money goes. It’s convincing precisely because everything else looks completely normal — because, until that one detail, it was.
Scam 2: The Urgent Boss (CEO Fraud)
An email or text arrives, apparently from the boss: “Are you at your desk? I need you to make a payment urgently — I’m stuck in a meeting and can’t talk.” The authority and the time pressure are the trick. A helpful member of staff, keen to impress, pays up before it occurs to them to double-check.
Its close cousin is the gift-card con: “Quick favour — can you nip out and grab £500 of gift cards for a client and send me the codes? I’ll explain later.” Spoiler: your director did not text you that. They never do. Nobody settles genuine business expenses in Amazon vouchers.
Scam 3: The Dodgy Link (Password Phishing)
A fake email from “Microsoft,” your bank, or a parcel company, designed to panic you into clicking and typing your password into a lookalike login page. Hand it over and the criminals now have the keys to your email — and from there, they can run Scams 1 and 2 on your own customers, from your own address. That’s how the cycle keeps spinning.
The Red Flags to Watch For
- Urgency or secrecy: “act now,” “keep this between us,” “don’t mention it to anyone yet.”
- Any change to bank details or payment process — treat this as a red flag every single time, no exceptions.
- A sender address that’s almost right but not quite: micros0ft.com, yoursupplier-ltd.net.
- A request that conveniently skips your usual process.
- That niggling feeling that something is just… off. Trust it.
The One Habit That Stops Nearly All of It
Verify independently. If an email asks you to pay something, change bank details, or do anything urgent, pick up the phone and confirm — using a number you already have on file, never the one printed in the email (that one rings the criminal, who will happily reassure you). Thirty seconds on the phone beats £10,000 down the drain. Better still, make it a firm company rule: no change to bank details is ever actioned on the strength of an email alone.
If It’s Already Happened
Don’t panic, and please don’t stay quiet out of embarrassment — it happens to switched-on people every day. Contact your bank straight away, because speed genuinely matters and funds can sometimes be stopped or recalled if you’re quick. Then change your passwords and tell your IT support so they can check nothing else has been tampered with. The faster you move, the better the odds.
The Bottom Line
The uncomfortable truth is that the humble inbox is now the front door criminals knock on most often — simply because it’s easier than picking a digital lock. But a team that knows the warning signs, backed by the right protections quietly working in the background, is a genuinely hard target.
| Not sure about an email? Ask us first. If something looks off, or you’d like a hand making sure your team can spot these scams, get in touch — we’re always happy to take a look or talk it through. A quick call now beats an expensive mistake later. Call 0118 976 7111 · hello@vcisystems.co.uk · www.vcisystems.co.uk |
