Fraud frequently relies on urgency and authority.
Attackers may impersonate executives, bank staff, suppliers or professional advisers and then pressure the recipient to act before normal verification can occur. The requested action may be a payment, beneficiary change, document release or disclosure of authentication information.
A professional-looking email or document is not proof of authenticity.
- Unexpected beneficiary changes
- Requests for OTPs or login credentials
- Pressure to bypass approvals
- New payment instructions sent only by email
Use a trusted channel, not the contact details in the suspicious message.
If an instruction is unusual, contact the known relationship manager, supplier or colleague using a number or email address already on file. Do not rely on telephone numbers, QR codes or links contained in the message being verified.
For payment changes, confirm the full beneficiary name, bank and account information before release.
Speed matters after a suspected compromise.
Stop further instructions, preserve the message or document, change affected credentials and contact the relevant bank or service provider. If funds have already moved, immediate notification gives the best chance of intervention.
