Skip to main content

Independent UK reporting on scams, fraud and financial harm

News

NCSC and partners expose "zero-click" phishing campaign aimed at Western organisations

The National Cyber Security Centre and international partners have attributed a phishing campaign requiring no user interaction to Russian state-supported actors. Consumer accounts are not the stated target.

By Daniel Okoye, Senior reporter, fraud and payments · Updated

A dim server room aisle with blue status lights and a technician silhouette
Illustrative picture. It does not depict any firm or individual named in this report.

News

Scam types

Published
23 Aug 2026
Last revised
26 Aug 2026
Sources cited
6
Names named
3 on file
Share thisWhatsAppXLinkedInFacebook Email

The National Cyber Security Centre has repeated its warning about a credential-harvesting campaign that needs no click to begin working: the preview itself renders a convincing login prompt, and the target is finance and payroll staff at small firms.

What the campaign does

The message arrives as a shared-document or voicemail notification from an address inside a supplier's real thread. The harvested credentials are used to read mail rather than to move money directly. That reading stage is the point: the operator learns invoice cycles, tone of voice and who signs off payments, then waits for a genuine invoice to change the bank details on it.

  • Targets are chosen for access to payment approvals, not seniority.
  • Mailbox rules are added to hide replies from the real supplier.
  • The fraudulent payment request arrives inside an existing, genuine thread.

Why consumers should care

Households meet the same operation at the other end. A conveyancing payment, a builder's final invoice or a school trip payment arrives with new account details from an address that has been correct for months. The loss lands on the payer, and the claim is made to the payer's bank under the reimbursement rules.

Practical steps

  1. Turn on multi-factor authentication on email before anything else.
  2. Never accept changed bank details by email; ring the number you already have.
  3. Check mailbox rules and forwarding settings for entries you did not create.
  4. Report suspicious emails to the national suspicious email service; texts go to 7726.

If a payment has gone, call your bank, report to Action Fraud, and if the bank refuses, take it to the Financial Ombudsman Service. The FCA consumer helpline is 0800 111 6768. Source: NCSC news; headline, summary and link only.

Named in this report

Each file gathers every warning, published contact detail and update we hold on that name.

Firm warnings published each month

98 in this window · down 17 on the month before

  • 2Apr
  • 1May
  • 2Jun
  • 4Jul
  • 53Aug
  • 36Sept

Counted from the warning notices in our own archive. One notice can name several trading styles.

The wider record

Counts from our own archive, for context around this report. Not an estimate of fraud across the UK.

Clone firms as a share of our Warning List archive

Clone firms copy the name or details of a genuine authorised business.

106
  • Clone of an authorised firm17(16%)
  • Not recorded as a clone89(84%)

Contact details recorded against warned firms

One firm can appear in more than one row.

  • Website recorded76(35%)

    Website recorded: 76 entries
  • Phone recorded39(18%)

    Phone recorded: 39 entries
  • Email recorded85(39%)

    Email recorded: 85 entries
  • No contact details held16(7%)

    No contact details held: 16 entries

Open the data page to see how each figure is counted.

See all of our fraud data

How this report was made

Updated
3 times
Primary sources
6 sources
Following this subject
0 readers
Reader comments
0 comments

Checked against the published record

Sourcing. Every claim is tied to a published record — a regulator's notice, a court or ombudsman decision, or a document we hold. We quote a headline and a short summary and link the original.

Right of reply. Firms and people we criticise are put on notice before publication and their response is carried in the piece.

Independence. No affiliate links, no sponsored placements and no referrals to solicitors or claims firms. The only routes we point to are free. Read the full method · first published 23/08/2026

Trust and sourcing

  • Reported by

    Daniel Okoye

    Senior reporter, fraud and payments

    Bylined
  • Approved for publication by

    Helen Marsden

    Editor

    Editor approved
  • Legal review

    Not required

    No individual or firm is criticised, so no right of reply was required.

    Not flagged for review

Source URLs behind this report

What changed in each update

First published 23 August 2026 at 09:30 · last updated 26 August 2026 at 11:30

  1. Added the current free reporting routes and clarified what the reimbursement rules do and do not cover.

    Payment Systems Regulator
  2. Checked against the source record and refreshed the figures and dates in the panels. No findings changed.

    FCA Financial Services Register
  3. First published.

    FCA Warning List
How we source and correct our reporting

Updates and change log

First published
Last updated
  1. Added the current free reporting routes and clarified what the reimbursement rules do and do not cover.

    Payment Systems Regulator
  2. Checked against the source record and refreshed the figures and dates in the panels. No findings changed.

    FCA Financial Services Register
  3. First published.

    FCA Warning List

Sources for this report

Sources for this report

  • NCSC logo

    National Cyber Security Centre advisories

    NCSC

    The advisory this report summarises.

    Read the original source
  • FCA logo

    Financial Conduct Authority Warning List

    FCA

    Primary record of firms the FCA says may be operating without authorisation.

    Read the original source
  • FCA logo

    FCA Financial Services Register

    FCA

    Authoritative check on whether a firm is authorised and for what.

    Read the original source
  • PSR logo

    Payment Systems Regulator — APP fraud reimbursement

    PSR

    The reimbursement requirement for authorised push payment fraud.

    Read the original source
  • FOS logo

    Financial Ombudsman Service

    FOS

    Free, independent adjudication and published decision data.

    Read the original source
  • Action Fraud logo

    Action Fraud reporting service

    Action Fraud

    The UK national reporting centre for fraud and cybercrime.

    Read the original source

We link directly to the original source wherever possible. A source may update its own page after we publish; we show the date we last recorded or updated the citation.

Readers can upvote helpful reporting.
Share thisWhatsAppXLinkedInFacebook Email

Share a quote card

Generate a branded image of the key line from this report, with the link on it, to post or send on.

  • Phishing

Reader comments

0 published comments · moderated by the newsroom

House rules: comments are for readers' own experience and questions about the reporting. We remove spam, abuse and anything that names a private individual without cause. Comments containing links are held for an editor before they appear. We cannot tell you whether you have a claim, and we do not pass details to any solicitor, claims firm or representative.

  1. Loading comments…

About the author

Byline portrait of Daniel Okoye

Daniel Okoye Daniel covers authorised push payment fraud, payment systems and the reimbursement rules. He previously worked on a regional investigations desk.