Skip to main content

Independent UK reporting on scams, fraud and financial harm

Investigation

Sixty seconds: the anatomy of a bank impersonation call, line by line

We transcribed a real impersonation call reported to our tip line and annotated every sentence. Almost all of the persuasion happens in the first fifteen seconds — before the caller has asked for anything at all.

By Daniel Okoye, Senior reporter, fraud and payments · Updated

Two near-identical letterheads side by side under a magnifying glass
Illustrative picture. It does not depict any firm or individual named in this report.

Investigation

Scam types

Published
24 Aug 2026
Last revised
No revisions
Sources cited
3
Names named
None
Share thisWhatsAppXLinkedInFacebook Email

Impersonation calls are not won by the request. They are won by the opening, where the caller establishes three things at once: that they already know you, that something is already wrong, and that you are already being helped.

Below is a shortened transcript from a call reported to our tip line this month, published with the reader's consent and with identifying details removed.

Seconds 0-15: the borrowed authority

"This is the fraud team. I'm calling about a payment of £2,480 to an electronics retailer in Manchester — can you confirm that wasn't you?"

The caller opens with a denial you want to give. Saying "no, that wasn't me" is the first cooperative act, and every later instruction is framed as protecting a decision you have already made.

Seconds 15-30: the manufactured clock

"I can stop it, but the window closes when the batch settles."

A deadline you cannot verify does two things: it suppresses the instinct to hang up and check, and it makes a second opinion feel like a risk rather than a safeguard.

Seconds 30-45: the proof that proves nothing

"You'll see the number I'm calling from matches the back of your card."

Displayed numbers can be spoofed. This is the single most effective line in the script and the easiest to defeat: hang up, wait a minute, and dial the number on your card yourself.

Seconds 45-60: the redefinition

"We're moving your balance to a holding account in your own name."

No genuine bank asks a customer to move money to keep it safe. The phrase "in your own name" is doing the work of an entire fraud.

What defeats the whole script

  • End the call yourself. No legitimate process is damaged by a five-minute pause.
  • Call back on the number printed on your card or bank statement.
  • Treat any request to move money, read a code aloud, or install software as the end of the conversation.

If a payment has already left, contact your bank first — under the reimbursement rules banks must investigate authorised push payment fraud claims. If they reject it, the Financial Ombudsman Service is free. Report to Action Fraud, and use the FCA consumer helpline on 0800 111 6768 for questions about authorisation.

Firm warnings published each month

98 in this window · down 17 on the month before

  • 2Apr
  • 1May
  • 2Jun
  • 4Jul
  • 53Aug
  • 36Sept

Counted from the warning notices in our own archive. One notice can name several trading styles.

The wider record

Counts from our own archive, for context around this report. Not an estimate of fraud across the UK.

Clone firms as a share of our Warning List archive

Clone firms copy the name or details of a genuine authorised business.

106
  • Clone of an authorised firm17(16%)
  • Not recorded as a clone89(84%)

Contact details recorded against warned firms

One firm can appear in more than one row.

  • Website recorded76(35%)

    Website recorded: 76 entries
  • Phone recorded39(18%)

    Phone recorded: 39 entries
  • Email recorded85(39%)

    Email recorded: 85 entries
  • No contact details held16(7%)

    No contact details held: 16 entries

Open the data page to see how each figure is counted.

See all of our fraud data

How this report was made

Updated
Not revised since publication
Primary sources
3 sources
Following this subject
0 readers
Reader comments
0 comments

Checked against the published record

Sourcing. Every claim is tied to a published record — a regulator's notice, a court or ombudsman decision, or a document we hold. We quote a headline and a short summary and link the original.

Right of reply. Firms and people we criticise are put on notice before publication and their response is carried in the piece.

Independence. No affiliate links, no sponsored placements and no referrals to solicitors or claims firms. The only routes we point to are free. Read the full method · first published 24/08/2026

Trust and sourcing

  • Reported by

    Daniel Okoye

    Senior reporter, fraud and payments

    Bylined
  • Approved for publication by

    Helen Marsden

    Editor

    Editor approved
  • Legal review

    Not required

    No individual or firm is criticised, so no right of reply was required.

    Not flagged for review

Source URLs behind this report

What changed in each update

First published 24 August 2026 at 06:30 · last updated 25 August 2026 at 17:43

Nothing has changed since first publication.

How we source and correct our reporting

Updates and change log

First published
Last updated

No changes have been made since first publication.

Sources for this report

Sources for this report

  • Reader transcript, published with consent

    The Fraud Center tip line

    Identifying details removed at the reader's request.

  • National Cyber Security Centre logo

    Guidance on spoofed calls and messages

    National Cyber Security Centre

    Read the original source
  • Financial Ombudsman Service logo

    Free adjudication if a bank rejects a claim

    Financial Ombudsman Service

    Read the original source

We link directly to the original source wherever possible. A source may update its own page after we publish; we show the date we last recorded or updated the citation.

Readers can upvote helpful reporting.
Share thisWhatsAppXLinkedInFacebook Email

Share a quote card

Generate a branded image of the key line from this report, with the link on it, to post or send on.

  • Impersonation scams
  • Authorised push payment fraud
  • Scam types

Reader comments

0 published comments · moderated by the newsroom

House rules: comments are for readers' own experience and questions about the reporting. We remove spam, abuse and anything that names a private individual without cause. Comments containing links are held for an editor before they appear. We cannot tell you whether you have a claim, and we do not pass details to any solicitor, claims firm or representative.

  1. Loading comments…

About the author

Byline portrait of Daniel Okoye

Daniel Okoye Daniel covers authorised push payment fraud, payment systems and the reimbursement rules. He previously worked on a regional investigations desk.