TL;DR:

  • Gift card scams are a variant of CEO fraud where attackers impersonate a director and ask staff to buy gift cards and send the codes by email
  • The scam works because it feels urgent, personal, and the “director” gives a plausible reason for secrecy
  • Prevention is simple: a verbal verification rule for any financial request from a director, combined with brief staff training, stops this scam almost entirely

Gift card fraud does not require any technical sophistication. No malware, no hacking, no fake login pages. It is a social engineering attack built on a simple manipulation: a fake sense of authority, a request that feels slightly awkward to question, and urgency that prevents people from thinking it through.

UK small businesses lose millions to this scam annually. Action Fraud consistently lists it among the most reported fraud types affecting organisations. The losses are often not covered by business insurance because no system was breached — a member of staff was simply deceived.

How the Scam Works

The attack follows a predictable script.

Step 1: The initial message

A member of staff — usually someone in an admin, accounts, or office manager role — receives an email or text message that appears to be from the company director, MD, or owner. The sender’s display name matches the director, and the message is written in a plausible tone.

The message is always marked urgent. A typical opener:

“Hi Sarah, I’m in meetings all day and can’t speak. I need a favour urgently — completely confidential. Can you help me out?”

If Sarah replies yes, the next message arrives.

Step 2: The request

“I need you to buy some Amazon/iTunes/Google Play gift cards for me. I’ll explain later but it’s time-sensitive. Can you get £500 worth from a nearby shop and send me the card codes? I’ll pay you back this afternoon.”

The reasons given vary. A supplier needs paying immediately. It is a surprise for a client. The director’s corporate card is not working. The request for secrecy is always present — “don’t mention this to anyone, I’ll explain when I’m done with these meetings.”

Step 3: The extraction

If the staff member buys the cards and photographs the codes, they are sent to the attacker. Gift card codes are untraceable and instantly redeemable. The money is gone within minutes. When the real director eventually learns what happened, recovery is almost impossible.

Why It Works

Several psychological mechanisms make this scam effective, particularly in small businesses.

Authority. The message appears to come from the most senior person in the business. Most employees have been taught to respond promptly to directors’ requests.

Isolation. The request for secrecy prevents the employee from checking with colleagues, which would immediately reveal the fraud.

Urgency. The time pressure prevents the employee from pausing to think. “I need this in the next hour” is specifically designed to skip the part of your brain that asks whether this feels right.

Plausibility. Directors do sometimes ask unusual things. Small businesses do operate informally. It is entirely plausible that a director might need a favour and ask for discretion.

The gift card misdirection. Many people associate gift cards with normal retail purchases. They do not immediately register as a financial transfer. A request to “do a bank transfer” raises alarm; a request to “buy some gift cards” sounds less serious.

The Red Flags

Train your staff to recognise these warning signs:

  • Any request to buy gift cards on behalf of someone else, for any reason
  • Requests that emphasise urgency and confidentiality together
  • Messages from a director’s address that arrive via a slightly different email address (look at the actual sender address, not just the display name)
  • Requests to “not mention this to anyone” or to bypass normal procedures
  • Any financial request where the normal authorisation process is said to be impossible right now
  • Pressure to act before speaking to the person directly

The single most important signal: any request to not verify something verbally. Legitimate urgent business requests do not require you to avoid speaking to the person making them.

How to Stop It

The verbal verification rule

The most effective defence is a simple policy: any request for a financial payment, gift card purchase, or transfer of funds — regardless of who it appears to come from — requires verbal confirmation before acting on it.

Call the director back on a known number (not a number provided in the suspicious email). Text them on the number you already have saved. Walk to their office if they are in the building. Do not rely on email to verify an email.

This rule does not slow down legitimate business. Actual directors making actual requests can take a thirty-second phone call. Only fraudulent requests fall apart under verification.

Brief your staff clearly

A thirty-minute session covering gift card scams is enough to inoculate most staff. The key points:

  1. No legitimate business reason ever requires gift cards to be purchased on behalf of a senior person
  2. A request for secrecy is a scam indicator, not a reason to comply
  3. Checking with the apparent sender by phone is not rude — it is standard financial procedure
  4. You will never be blamed for following the verification rule; you may face consequences for not following it

Adjust your email display settings

Set your email client to show the full sender address rather than just the display name. Many gift card scams use a fake display name matching the director (Jane Smith) but send from an unrelated address (jane.smith.consultant@gmail.com). Making the actual address visible removes the impersonation.

In Microsoft 365, you can create mail flow rules that add a banner to any email claiming to be from a senior person but sent from an external domain. These are straightforward to configure in the Exchange admin centre.

Consider a financial controls policy

For businesses where gift card purchases do legitimately occur (retail, hospitality, events), a simple policy helps: gift cards above a set threshold require dual authorisation. This makes it structurally impossible for a single employee to act on a fraudulent request alone.

If You’ve Already Been Targeted

If a staff member has sent gift card codes to a fraudster:

  1. Report to Action Fraud immediately — call 0300 123 2040 or report at actionfraud.police.uk. Speed matters; law enforcement sometimes works with platforms to flag codes.
  2. Contact the gift card provider directly. Amazon, Apple, and Google all have fraud teams. If the codes have not yet been redeemed, there is a small chance they can be blocked. Act within the first hour.
  3. Document everything — the messages received, what was purchased, where and when, how the codes were sent.
  4. Do not blame the staff member. They were deceived by a sophisticated social engineering attack. Blame culture discourages future reporting of incidents and near-misses.

The financial loss from gift card fraud is rarely recoverable. The best response is prevention, and prevention costs almost nothing beyond a brief conversation with your team.