TL;DR:

  • APP fraud (where you’re tricked into sending money yourself) is now the most common form of bank fraud for UK businesses — and harder to recover than unauthorised fraud
  • Since October 2023, UK banks must reimburse most APP fraud victims up to £85,000, but there are significant exceptions for business accounts
  • Confirmation of Payee (CoP) checks are your best free tool — always use them before any new payment
  • Account takeover usually starts with phishing or credential theft, not a direct bank hack
  • Most business banking security failures come down to weak access controls, not sophisticated attacks

If someone hacks into your bank account and moves money without your knowledge, UK law and your bank’s fraud team are usually on your side. But if a fraudster tricks you or one of your staff into authorising the payment yourselves — even under false pretences — the situation is much more complicated. That second scenario, called authorised push payment (APP) fraud, now accounts for the majority of bank fraud losses for UK small businesses. Understanding the difference is the starting point for protecting yourself.

What APP Fraud Actually Looks Like

APP fraud isn’t always an obvious scam. The most common forms that hit UK small businesses in 2026 include:

Invoice redirect fraud: A supplier’s email is compromised (or convincingly spoofed). You receive an email that looks like it’s from them saying their bank details have changed. You update your records and pay the next invoice to the new account. The money goes to fraudsters.

CEO or director impersonation: Someone emails your accounts team pretending to be a director or senior manager, requesting an urgent transfer. The email looks legitimate — sometimes because the director’s real email has been compromised.

Fake supplier or service scam: You’re contacted by someone posing as HMRC, a business rates authority, or a utility provider. There’s an urgent payment required to avoid a penalty or service interruption.

Investment fraud: A fraudster poses as a legitimate financial services firm, often with a convincing website and LinkedIn presence, and persuades you to transfer funds to an investment account.

What these have in common: you or a member of staff initiated and authorised the payment. The bank processed it as instructed. From a technical standpoint, the transaction looks completely legitimate.

What UK Banks Will and Won’t Reimburse

The Payment Systems Regulator’s reimbursement rules came into force in October 2023. For most APP fraud cases, your bank is required to reimburse you — split equally between the sending and receiving bank. The limit is £85,000 per claim.

However, there are important exceptions that catch many small businesses out:

Gross negligence exclusion: If the bank can show you ignored explicit warnings during the payment journey — for example, you confirmed a payment despite a fraud warning pop-up, or you shared your banking credentials with someone — they can refuse to reimburse.

Business account nuances: The rules apply to personal and small business accounts, but “small business” has a specific definition under the scheme. Larger businesses may have different protections negotiated through their banking terms.

International transfers: The reimbursement scheme covers Faster Payments and CHAPS. International SWIFT payments operate under different rules and often have weaker protections.

Cryptocurrency and non-bank transfers: If you were tricked into buying cryptocurrency or using a payment service outside the banking system, the rules don’t apply.

This is not a reason to be complacent — reimbursement being available doesn’t mean recovery is quick or guaranteed. Prevention is still far better than the claims process.

Confirmation of Payee: Use It Every Time

Confirmation of Payee (CoP) is a free service your bank provides that checks whether the name you’ve entered matches the account holder at the receiving bank before you complete a transfer. It’s available on most UK business banking platforms and all major banks are required to support it.

Before making any payment to a new payee — or to a payee whose details have supposedly changed — run a CoP check. If the check returns a mismatch or “name not found,” stop and verify through a different channel. Call the supplier or contact on a number you already have on record, not one from the email you just received.

CoP doesn’t catch every fraud (fraudsters sometimes open accounts in names that closely match legitimate businesses) but it stops the simplest cases dead and demonstrates due diligence if you later need to make a claim.

Account Takeover: How It Actually Happens

Account takeover — where fraudsters gain access to your banking credentials and make unauthorised transactions themselves — is the other major threat. Despite what people imagine, this rarely involves sophisticated hacking of bank systems. The most common routes are:

Phishing emails or texts that direct you to a fake banking login page. You enter your credentials, fraudsters capture them and log in with them.

Malware on a business device that captures keystrokes or screenshots, or intercepts your session while you’re logged into genuine banking sites.

SIM swapping — fraudsters convince your mobile provider to transfer your number to a SIM they control, giving them access to one-time passwords sent by SMS.

Credential reuse — your email or another service gets breached, and you use the same password for banking.

Most account takeover attacks on small businesses start outside the bank, with a compromised email account or device. Securing your banking login is only part of the picture.

Steps That Actually Reduce Your Risk

Use your banking app rather than a browser where possible. Apps are harder to spoof with fake login pages and are less exposed to browser-based malware. On a desktop, bookmark your bank’s genuine URL and access it only from that bookmark.

Enable all available multi-factor authentication on your banking accounts. Prefer authenticator apps (Google Authenticator, Microsoft Authenticator) over SMS-based codes where your bank offers the choice, since SMS is vulnerable to SIM swapping.

Separate your banking device from general business use. Ideally, access business banking from a dedicated device that isn’t used for email, browsing, or software installation. If that’s not practical, at minimum don’t access banking from shared or public computers.

Set up payment approval limits that require dual authorisation. Most business banking platforms let you require a second approver for payments above a threshold. This alone stops a significant proportion of fraud, including CEO impersonation scams, since the fraudster would need to compromise two people rather than one.

Train anyone who handles payments to verify bank detail changes by phone. This is the single highest-impact practice for preventing invoice redirect fraud. Make it a written policy: any change to a supplier’s bank details requires a phone verification call to a number that was already in your records before the change request arrived.

Review your online banking users and their permissions quarterly. Former employees with banking access, and staff with higher permissions than their role requires, are a consistent source of both fraud and error.

Banking security for small businesses is mostly about process and access control, not technology. The fraudsters targeting UK SMEs in 2026 are primarily exploiting human factors — urgency, authority, and trust — not technical vulnerabilities in banking systems.