The National Cyber Security Centre has repeated its warning about a credential-harvesting campaign that needs no click to begin working: the preview itself renders a convincing login prompt, and the target is finance and payroll staff at small firms.
What the campaign does
The message arrives as a shared-document or voicemail notification from an address inside a supplier's real thread. The harvested credentials are used to read mail rather than to move money directly. That reading stage is the point: the operator learns invoice cycles, tone of voice and who signs off payments, then waits for a genuine invoice to change the bank details on it.
- Targets are chosen for access to payment approvals, not seniority.
- Mailbox rules are added to hide replies from the real supplier.
- The fraudulent payment request arrives inside an existing, genuine thread.
Why consumers should care
Households meet the same operation at the other end. A conveyancing payment, a builder's final invoice or a school trip payment arrives with new account details from an address that has been correct for months. The loss lands on the payer, and the claim is made to the payer's bank under the reimbursement rules.
Practical steps
- Turn on multi-factor authentication on email before anything else.
- Never accept changed bank details by email; ring the number you already have.
- Check mailbox rules and forwarding settings for entries you did not create.
- Report suspicious emails to the national suspicious email service; texts go to 7726.
If a payment has gone, call your bank, report to Action Fraud, and if the bank refuses, take it to the Financial Ombudsman Service. The FCA consumer helpline is 0800 111 6768. Source: NCSC news; headline, summary and link only.
Named in this report
Each file gathers every warning, published contact detail and update we hold on that name.
Firm warnings published each month
98 in this window · down 17 on the month before
- 2Apr
- 1May
- 2Jun
- 4Jul
- 53Aug
- 36Sept
Counted from the warning notices in our own archive. One notice can name several trading styles.
The wider record
Counts from our own archive, for context around this report. Not an estimate of fraud across the UK.
Clone firms as a share of our Warning List archive
Clone firms copy the name or details of a genuine authorised business.
- Clone of an authorised firm17(16%)
- Not recorded as a clone89(84%)
Contact details recorded against warned firms
One firm can appear in more than one row.
Website recorded76(35%)
Website recorded: 76 entriesPhone recorded39(18%)
Phone recorded: 39 entriesEmail recorded85(39%)
Email recorded: 85 entriesNo contact details held16(7%)
No contact details held: 16 entries
Open the data page to see how each figure is counted.
How this report was made
- Updated
- 3 times
- Primary sources
- 6 sources
- Following this subject
- 0 readers
- Reader comments
- 0 comments
Checked against the published record
NCSC
National Cyber Security Centre advisoriesThe advisory this report summarises.
FCA
Financial Conduct Authority Warning ListPrimary record of firms the FCA says may be operating without authorisation.
FCA
FCA Financial Services RegisterAuthoritative check on whether a firm is authorised and for what.
PSR
Payment Systems Regulator — APP fraud reimbursementThe reimbursement requirement for authorised push payment fraud.
FOS
Financial Ombudsman ServiceFree, independent adjudication and published decision data.
Action Fraud
Action Fraud reporting serviceThe UK national reporting centre for fraud and cybercrime.
Sourcing. Every claim is tied to a published record — a regulator's notice, a court or ombudsman decision, or a document we hold. We quote a headline and a short summary and link the original.
Right of reply. Firms and people we criticise are put on notice before publication and their response is carried in the piece.
Independence. No affiliate links, no sponsored placements and no referrals to solicitors or claims firms. The only routes we point to are free. Read the full method · first published 23/08/2026
Trust and sourcing
- Bylined
- Editor approved
- Not flagged for review
Legal review
Not required
No individual or firm is criticised, so no right of reply was required.
Source URLs behind this report
- NCSC
https://www.ncsc.gov.uk/section/keep-up-to-date/all-advisories
The advisory this report summarises.
- FCA
https://www.fca.org.uk/consumers/warning-list-unauthorised-firms
Primary record of firms the FCA says may be operating without authorisation.
- FCA
https://register.fca.org.uk/
Authoritative check on whether a firm is authorised and for what.
- PSR
https://www.psr.org.uk/
The reimbursement requirement for authorised push payment fraud.
- FOS
https://www.financial-ombudsman.org.uk/
Free, independent adjudication and published decision data.
- Action Fraud
https://www.actionfraud.police.uk/
The UK national reporting centre for fraud and cybercrime.
What changed in each update
First published 23 August 2026 at 09:30 · last updated 26 August 2026 at 11:30
Added the current free reporting routes and clarified what the reimbursement rules do and do not cover.
Payment Systems RegulatorChecked against the source record and refreshed the figures and dates in the panels. No findings changed.
FCA Financial Services RegisterFirst published.
FCA Warning List
Updates and change log
- First published
- Last updated
Added the current free reporting routes and clarified what the reimbursement rules do and do not cover.
Payment Systems RegulatorChecked against the source record and refreshed the figures and dates in the panels. No findings changed.
FCA Financial Services RegisterFirst published.
FCA Warning List
Sources for this report
- NCSC National Cyber Security Centre advisories — The advisory this report summarises.
- FCA Financial Conduct Authority Warning List — Primary record of firms the FCA says may be operating without authorisation.
- FCA FCA Financial Services Register — Authoritative check on whether a firm is authorised and for what.
- PSR Payment Systems Regulator — APP fraud reimbursement — The reimbursement requirement for authorised push payment fraud.
- FOS Financial Ombudsman Service — Free, independent adjudication and published decision data.
- Action Fraud Action Fraud reporting service — The UK national reporting centre for fraud and cybercrime.
Sources for this report
National Cyber Security Centre advisories
NCSC
The advisory this report summarises.
Read the original sourceFinancial Conduct Authority Warning List
FCA
Primary record of firms the FCA says may be operating without authorisation.
Read the original sourceFCA Financial Services Register
FCA
Authoritative check on whether a firm is authorised and for what.
Read the original sourcePayment Systems Regulator — APP fraud reimbursement
PSR
The reimbursement requirement for authorised push payment fraud.
Read the original sourceFinancial Ombudsman Service
FOS
Free, independent adjudication and published decision data.
Read the original sourceAction Fraud reporting service
Action Fraud
The UK national reporting centre for fraud and cybercrime.
Read the original source
We link directly to the original source wherever possible. A source may update its own page after we publish; we show the date we last recorded or updated the citation.
Share a quote card
Generate a branded image of the key line from this report, with the link on it, to post or send on.
- Phishing
Related reporting
Twenty firms added to the FCA Warning List in the week to 24 August, six of them clones
Our archive recorded twenty new or updated entries on the Financial Conduct Authority's Warning List over the past week. Six copied the identity of an authorised firm.
Mon 24 Aug
Regulator fines insurer over inaccurate compensation-scheme reporting
The Prudential Regulation Authority has fined an insurer more than four million pounds over inaccurate reporting of Financial Services Compensation Scheme liabilities. The penalty concerns reporting, not consumer losses.
Fri 21 Aug
Bank Rate held at 3.75 per cent, and what that means for "fixed return" adverts
With Bank Rate unchanged at 3.75 per cent, advertised returns far above the best available savings rates remain the clearest marker of an unauthorised promotion.
Tue 18 Aug
Late-summer holiday fraud follows the travel advice cycle
Fraudulent accommodation and flight listings track periods when official travel advice changes and travellers rebook at short notice. Payment method is the deciding factor in recovery.
Sun 16 Aug
About the author

Daniel Okoye — Daniel covers authorised push payment fraud, payment systems and the reimbursement rules. He previously worked on a regional investigations desk.

Reader comments
0 published comments · moderated by the newsroom
House rules: comments are for readers' own experience and questions about the reporting. We remove spam, abuse and anything that names a private individual without cause. Comments containing links are held for an editor before they appear. We cannot tell you whether you have a claim, and we do not pass details to any solicitor, claims firm or representative.