TL;DR:
- Fraud against UK small businesses spikes in Q4, when businesses are processing higher volumes of transactions, staff are distracted, and criminals target the chaos.
- The most damaging attacks — invoice redirect fraud, CEO impersonation, and credential phishing — all exploit distraction and time pressure. Setting up processes now, before the rush, makes you significantly harder to hit.
- Three actions make the biggest difference: multi-factor authentication on all email and financial accounts, a written procedure for verifying bank account changes, and a backup point-of-contact for financial decisions when key people are on leave.
Ask any accountant which time of year they see the most fraud incidents and the answer is consistent: Q4. The weeks running up to Christmas, the end of the financial year (April in the UK, but many businesses align planning with December), and the period between Christmas and New Year when skeleton staff are covering for absent colleagues.
The reasons are straightforward. Transaction volumes are higher — which means more invoices to process and more opportunities to slip a fraudulent one through. Staff are distracted, rushing to close things out before the holiday. Key decision-makers are often on annual leave. And criminals know all of this.
August is the best time to prepare. The pressure is off, you can think clearly, and the changes you make now will be embedded by the time the rush starts.
The Three Attacks Most Likely to Hit You
1. Invoice Redirect Fraud
A supplier’s email account gets compromised (or spoofed convincingly). You receive what looks like a legitimate email from your supplier saying their bank account has changed and asking you to update your records. The email looks right, the branding looks right, maybe it arrives mid-thread. You update the bank details and pay the next invoice to the fraudster’s account.
The reason this works is simple: you’re busy, you trust the email because it looks like the supplier you deal with, and there’s no existing process that requires you to verify bank account changes before updating them.
The fix: Implement a policy today that any bank account change request — from any supplier — requires a phone call to a number you already have on file (not a number in the email) before the change is made. Put this in writing. Tell your finance staff. Remind them in September and October.
This single procedural change makes invoice redirect fraud dramatically harder. The NCSC recommends exactly this, and it works.
2. CEO Impersonation (Business Email Compromise)
An email arrives in accounts payable or finance, seemingly from the CEO or managing director, asking for an urgent payment — often to a new payee, often with a reason for urgency (“I’m in a meeting and can’t be reached, please process this immediately”). The email may come from a spoofed address that looks like the CEO’s email, or in some cases from a compromised email account.
The urgency is deliberate. It’s designed to prevent staff from doing what they should do, which is check with the person before authorising an unusual payment.
The fix: Establish a clear rule that no payment above a threshold (£500, £1,000 — whatever makes sense for your business) to a new payee is processed without voice confirmation from the authorising person. Train your team that they should never feel uncomfortable asking to verify, even if the request seems to come from a senior person. Real managers understand why the check is needed.
If you have a maximum payment authority structure (the finance manager can authorise up to £X, the director above that), make sure it’s documented and followed consistently — not bypassed because a senior person “said it was urgent.”
3. Credential Phishing During Busy Periods
Phishing emails are sent year-round, but click rates go up when people are rushing. An email claiming to be from HMRC about an urgent tax matter, from a parcel carrier about a failed delivery, from Microsoft about a security alert on your account — all of these are designed to create enough anxiety that you click before you think.
During Q4, the volume of legitimate urgent emails increases (tax deadlines, supplier statements, courier tracking). This makes the fraudulent ones harder to distinguish from the real ones.
The fix: Multi-factor authentication on every account that matters. Email (Microsoft 365, Google Workspace). Online banking. Your accounting software (Xero, QuickBooks, Sage). Your payment processor. Company social media accounts. VAT and HMRC Online. Companies House.
If an attacker phishes a password, MFA means they still can’t access the account. For phishing-specific attacks, use hardware keys (YubiKey) or passkeys where available — these are phishing-resistant in a way that SMS or authenticator app codes are not. For most small businesses, any MFA is dramatically better than no MFA, even if it’s SMS.
Practical Preparation Checklist
Do before September:
- Enable MFA on all email accounts for all staff — no exceptions
- Enable MFA on your accounting software and online banking
- Write a one-page “bank account change verification procedure” and share it with anyone who processes payments
- Check that your DMARC record is set to
p=quarantineorp=reject(this prevents criminals from sending emails that appear to come from your domain — check with MXToolbox) - Review who has access to your company email admin console. Remove former employees if any still have access.
In September:
- Brief your team on the three fraud types above. Spend 20 minutes in a team meeting. The NCSC’s Cyber Aware programme has free, plain-English resources you can use.
- Designate a backup authoriser for financial decisions when key people are on leave. Document who it is.
- Check that your cyber insurance policy (if you have one) covers social engineering and invoice fraud. Many policies have exclusions worth understanding before you need to claim.
- Make sure your bank has up-to-date contact numbers for you. If you spot a suspicious transaction, you need to call immediately — make sure you know who to call.
October/November:
- Send a reminder to staff about the verification procedure for bank account changes
- Check that your email security settings (SPF, DKIM, DMARC) are still correctly configured — especially if you’ve changed email providers or added a mailing list service during the year
- If you’re expecting high-value supplier payments in Q4, call your key suppliers now to confirm their bank details. File the confirmed details. When an invoice arrives, you have something to check against.
The Staffing Gap Problem
The period between Christmas and New Year creates a specific vulnerability: reduced staff, unfamiliar people covering roles, and a backlog of things to process quickly in the new year. Criminals know this and sometimes time operations around it.
Two practical steps:
- Set financial transaction limits for holiday cover. Anyone covering finance during that period should have a lower unilateral payment authority than usual — a £200 limit rather than £2,000, with anything above requiring a call to someone specific.
- Communicate the cover arrangements to key suppliers in advance. If your main supplier knows that James is covering accounts payable from 24 December to 3 January and any queries should go to james@yourcompany.com, they’re less likely to be surprised by unusual behaviour from their end that could be exploited.
The Mindset Shift That Makes the Difference
Most of these frauds work because there’s social pressure to be helpful, responsive, and not to slow things down. An email from the CEO says urgent. A supplier email says please update our bank details. Staff don’t want to be the person who caused a problem by being difficult.
Explicitly give your team permission to pause and verify. Make it clear that calling to confirm a bank change or a payment request is not obstructive — it’s exactly what you want them to do. Criminals rely on the social norm of not wanting to seem unhelpful or slow. Breaking that norm, with explicit team backing, is the cultural change that makes the procedural controls actually stick.
The fraud that costs a small business £10,000 or £50,000 is rarely technically sophisticated. It’s operationally simple and socially engineered. The defences are also simple — they just need to be established before the moment when someone is busy, stressed, and under time pressure to click or pay.
Do it now.
Free resources: NCSC’s Small Business Cyber Security Guide (ncsc.gov.uk/collection/small-business-guide), Action Fraud reporting (actionfraud.police.uk), Cyber Essentials certification (cyberessentials.ncsc.gov.uk).