TL;DR:

  • Mandate fraud happens when a criminal contacts your business — by phone, email, or letter — impersonating a supplier, landlord, or utility company to get you to update their bank payment details to a fraudulent account
  • Unlike invoice fraud (which intercepts a specific payment), mandate fraud hijacks a recurring payment relationship — rent, subscriptions, supplier standing orders — that then bleeds funds for weeks or months before detection
  • The defence is a call-back verification using a number from your own records, not the one provided in the change request

Mandate fraud doesn’t require any hacking. There are no malware infections, no data breaches, no sophisticated technical attacks. The criminal calls, emails, or sends a letter claiming to be your landlord, utility provider, or a long-standing supplier. They have one request: “We’ve updated our banking details — please use the new account for future payments.”

If you update the details without verifying, the next payment goes to the criminal. Then the one after that. Depending on how frequently you pay and how long it takes to notice, the losses can be significant. The NCSC estimates that mandate fraud costs UK businesses tens of millions of pounds annually, and most cases involve the loss of multiple payments before detection.

How Mandate Fraud Works

The typical attack has three elements: a plausible cover story, some basic research, and a sense of urgency.

The call or email arrives from a contact claiming to be from an organisation you already pay. The fraudster will have done basic research — your landlord’s company name, your utility provider, or a supplier you’ve been using for years are all findable from a company website, Companies House filings, or even your own social media presence. They don’t need to know your current bank details; they just need to know who you pay.

The instruction is to update payment details. Sometimes this comes with a plausible business reason: “We’ve changed banks,” “We’re migrating to a new payment system,” or “Our old account is closing.” The new details provided belong to a mule account the criminal controls.

The delay is what makes it damaging. Because it’s a standing payment rather than a one-off invoice, you may not notice anything is wrong until you receive a chaser from the real supplier asking where their payments are. By that point, multiple payments may have gone to the fraudulent account, and recovering them is difficult even if you report promptly.

Who Gets Targeted

Mandate fraud targets businesses of all sizes, but small businesses are disproportionately affected because:

  • Fewer controls: in a small team, the person who receives the change request often has the authority to action it without a separate approval step
  • Familiarity: in a small team, the same person might know the supplier and the bank details and handle the update themselves, compressing the verification gap
  • Regular payments at predictable amounts: rent, software subscriptions, and supplier standing orders are predictable targets because the payment amounts are stable and the timing is known

Sectors with high volumes of regular supplier payments — construction (subcontractors), hospitality (regular deliveries), professional services (software and subscriptions) — are particularly targeted.

The Warning Signs

A bank detail change request should always trigger scrutiny. Specific warning signs include:

  • Urgency language: “Please update this by end of week or your account will be suspended”
  • Contact from a new email address: the request comes from a slightly different domain (supplier.co.uk instead of supplier.com), or a personal Gmail/Outlook account rather than a business address
  • New phone number: the email provides a phone number “to confirm the change” — this routes to the fraudster, not the real supplier
  • Letter or fax: paper mandate change requests are not inherently more trustworthy; fraudsters send physical letters too, sometimes using a PO Box as the return address

The One Defence That Works

Call back using a number you already hold. This is the NCSC’s core recommendation and it’s the only reliable check.

When you receive any request to change payment details:

  1. Do not use the phone number or email in the change request
  2. Look up the supplier’s number in your own records, your accounting software, or their official website independently navigated (not linked from the email)
  3. Call and speak to someone you know, or ask to be transferred to accounts
  4. Ask them to confirm the change was intentional and confirm the new account details match

This takes two minutes and stops mandate fraud entirely.

What to Do If You’ve Been Hit

If you discover that payments have been redirected to a fraudulent account:

  1. Call your bank immediately — banks have 24/7 fraud lines and can sometimes recall payments if acted on quickly. Under the Confirmation of Payee system, same-day or next-day payments may be partially recoverable.

  2. Report to Action Fraud at actionfraud.police.uk or by calling 0300 123 2040. A police report creates the record needed for insurance claims and any bank recovery process.

  3. Contact the real supplier — they need to know their details have been impersonated and may have other customers at risk from the same campaign.

  4. Report to your bank’s fraud team — your bank is required under the APP (Authorised Push Payment) fraud code to assess your case and consider reimbursement. Since the Payment Systems Regulator’s mandatory reimbursement rules came into force in 2024, UK banks must reimburse most APP fraud victims up to £85,000, unless gross negligence can be demonstrated. A verbal check-back is enough to show you took reasonable precautions.

Building a Payment Change Process

If your business handles multiple supplier relationships, a simple process reduces risk significantly:

  • Designate one person (or two for dual-authorisation) to process payment detail changes
  • Require a call-back confirmation before any change is actioned, and document it — who called, who confirmed, when
  • In accounting software like Xero or QuickBooks, flag accounts with recent payment detail changes and review them at the next reconciliation
  • Add payment changes to your regular bank reconciliation check so anomalies surface quickly

You don’t need an expensive tool to do any of this. A single row in a shared spreadsheet — supplier, old sort code, new sort code, confirmation call made by, date — creates an audit trail and forces a moment of deliberate verification.

References