United Kingdom flagIndependent UK business banking research
UK Business Banking Research · BanksGB
Business typesCards & expensesCash flowSecurityDigital bankingMerchant servicesFX & tradeInsightsAll topics
BanksGB · Security

Bank impersonation and vishing: a real caller ID does not prove the bank is calling

A practical UK business guide to bank-impersonation phone scams covering spoofed numbers, safe-account requests, approval prompts, verification and incident response.

Vishing is phishing by voice. Criminals call pretending to be a bank, police force, Companies House or another trusted organisation and pressure staff to reveal security information or move money. Caller ID can be spoofed, and the most dangerous calls often sound calm and professional rather than obviously fraudulent.

Fraudsters imitate trusted organisations

The National Cyber Security Centre says phone scammers can call unsolicited while pretending to be a bank or the police and ask for banking details or tell the victim to transfer money. Business callers can add believable details from public filings, social media or previous phishing.

Train finance staff to recognise the request, not the accent or confidence of the caller. A fraudster can know supplier names, director names and recent transaction amounts without being the bank.

Caller ID is not reliable authentication

Telephone numbers displayed on the handset can be spoofed. A call that appears to come from the bank's public number should still be treated as unverified until the employee independently contacts the bank.

Do not use a callback number supplied by the caller. End the call and use the number on the bank card, official website or existing relationship records.

Never move money to a so-called safe account

Scammers can claim the business account is under attack and instruct staff to move funds to a new account for protection. A legitimate bank should not require a customer to transfer money to a stranger's account to keep it safe.

Any urgent new-beneficiary request should go through normal payment approval and beneficiary verification even when the caller says delay will cause a loss.

Do not disclose one-time codes or approve unexpected prompts

A caller can already have the password and need only an MFA code or app approval to complete account takeover. Staff should never read authentication codes or approve a bank-app prompt solely because a caller requests it.

If unexpected prompts appear during a call, end the conversation and contact the bank directly because that can be evidence the attacker is actively trying to log in.

Use a known verification script for bank calls

Finance teams should have a simple rule: the caller can give information, but staff do not release credentials or money until they independently reconnect with the bank. High-value or unusual requests should be reviewed by another employee.

Record the bank's genuine relationship contacts and fraud numbers in a controlled directory so staff do not need to search the web while under pressure.

Call the real bank immediately after a suspected scam

If information or money was disclosed, contact the bank through an official channel immediately and explain exactly what was shared or transferred. Early action can improve the chance of freezing funds or credentials.

Preserve the caller number, time, notes and any related email or text. Report material fraud through the appropriate UK reporting and law-enforcement channels.

Worked example: an employee receives a call showing the bank's usual number. The caller knows the company name and says a £95,000 fraudulent payment is pending. They ask the employee to approve a mobile prompt to "cancel" it. The correct response is to deny the prompt, end the call and contact the bank independently.

Run short vishing exercises with finance and executive assistants. Phone fraud works because staff are trained to spot suspicious emails but can still treat a confident voice as proof of identity.

Include directors in the rule. A genuine chief executive should accept that treasury will verify an unusual bank request rather than bypass control because the bank allegedly called them first.

Use a no-transfer rule during inbound calls. Even if the caller passes some security questions, staff should not create a new beneficiary or release a high-value payment while the call remains active. End the call, verify internally and initiate any legitimate transaction through the normal workflow.

Worked example: a caller claims to be from the bank fraud team and says the company must move £500,000 before 4pm. The finance director independently calls the relationship manager on the stored number and learns no such request exists. The company loses minutes rather than the money.

Record common scam scripts and circulate them after incidents. Attackers reuse themes such as safe accounts, suspicious login cancellation and test payments. Familiarity with the pattern makes urgency less persuasive.

Keep a written policy that employees can never be penalised for delaying a payment to verify an inbound banking call. Social pressure works best when staff believe speed matters more than control, so management behaviour must reinforce the verification rule.

Editorial Verdict

Bank impersonation fraud succeeds by creating urgency and authority over the phone.

Treat caller ID as untrusted, never transfer to a safe account and independently reconnect with the bank before taking financial action. A short verification delay is cheaper than recovering an authorised fraudulent payment.

Sources

Keep the banking structure tied to the business model

Use the provider directory, comparisons and practical guides to narrow the questions before choosing products.

Start comparison