
Most people who fall for a fraudulent payment request are not careless. Rather, they are competent staff who did what a colleague appeared to ask, on a day when the request looked ordinary. Business email compromise works because it uses the normal shape of a working day, and the AI-generated version has also removed the signals staff were trained to notice, whether the request arrives as an email, a voice on the phone or a face on a video call.
Government figures give a more careful picture than the headlines do, and the careful picture is the useful one.
What the data supports, and what it does not
The Cyber Security Breaches Survey 2025/2026, published in April 2026, records phishing as the most prevalent attack type by a wide margin, experienced by 38% of businesses, and names it the most disruptive category among businesses that were breached, at 69%. Businesses experiencing phishing and nothing else rose from 45% to 51%.
Impersonation attacks are measured separately, and they fell, from 17% in 2023 to 12%. So anyone arguing that impersonation fraud is surging in volume is arguing against the government’s own measure.
The case for changing what you do rests on two things the data does support. Firstly, phishing remains both the most common and the most disruptive category. Secondly, the specific tells that awareness training was built around have stopped working, which changes detection from a content problem into a process problem.
Three shapes business email compromise takes
Voice cloning. A short clip of public audio, from a conference recording, a podcast or a LinkedIn video, produces a convincing imitation of someone’s voice.
Live video impersonation. Face-swap on a Teams or Zoom call, helped considerably by low bandwidth, where the visual artefacts get attributed to a poor connection.
AI-generated email. The spelling and grammar signals disappear, and the register matches the sender because a model has read their public writing.
All three arrive at the same place: someone with payment authority is persuaded to move money, share credentials, or grant access to a person they believe they know.
Why the four classic training signals stopped working
Awareness programmes written between 2020 and 2022 taught four tells: poor spelling, a mismatched sender address, suspicious links, and urgency. Three of the four, however, have gone.
Spelling and grammar are clean. Meanwhile, the sender address can be spoofed, and voice or video attacks skip email entirely. No link appears, because the requested action is a bank transfer. Urgency survives as a signal, and it is routinely softened with a plausible reason for the hurry.
What replaces them, then, is pattern. A request arriving on an unusual channel, when it would normally come by email. A tone or pace that feels slightly wrong even though the words are right. Notably, secrecy framing, where the reader is asked to keep it between themselves. And refusal to verify, which is still the strongest single signal there is.
Three checks staff can use without any technical training
Callback verification. Any payment request above an agreed size triggers a callback on a number from your own records, never a number supplied in the request. Hold that list somewhere reachable without email. Indeed, this one check stops most voice attacks on its own.
Out-of-band confirmation. Instead, confirm unusual requests through a different channel from the one they arrived on. Email in, Teams out. Phone in, email out. After all, controlling two channels at once is considerably harder for an attacker.
A hold on urgency. A written rule that urgent payment requests wait a defined period while verification completes. Explain it once and enforce it every time, including for the chief executive. Legitimate senior people understand why the rule exists, and a caller who objects to it has told you something useful.
Technical controls that catch what training misses
Awareness reduces the odds. These five, however, stop the payment.
- Payment approval workflows above a threshold, configured in the accounts system with two named approvers signing independently.
- Dual authorisation on the bank account. Business banking platforms support it. Turning it on means a second signatory is needed before anything leaves.
- Phishing-resistant MFA on finance and executive accounts. Adversary-in-the-middle attacks defeat SMS codes and push notifications. Passkeys and hardware keys hold.
- DMARC, SPF and DKIM on outbound email, configured properly, which makes spoofing your own domain against your own staff considerably harder.
- Managed detection with identity monitoring, which catches the account takeover route where the request comes from a genuine inbox. Impossible-travel sign-ins in Microsoft Entra ID Protection surface here.
Set a threshold that matches your normal payment sizes.
Items 3, 4 and 5 need administrative access to your systems. Items 1 and 2 need access to your accounts platform and your bank. Ultimately, none of the five can be completed by reading about them, which is the practical difference between this list and the policy work above it.
What Cyber Essentials and cyber insurers ask about
Assessors now ask about awareness training coverage, payment approval workflows, and MFA on finance accounts. Our Cyber Essentials service covers where those sit in the assessment.
Equally, insurers increasingly ask what controls sit around payment approval at renewal.
Underwriters ask three things at renewal: what training addresses AI-generated fraud, what payment size triggers dual approval, and what happens when a senior person appears to request an unusual transfer. Businesses without answers therefore see a higher premium or an exclusion for social engineering losses. Finally, our guide to cyber insurance renewal in 2026 lists the full evidence pack.
Actions worth completing this quarter
- Update awareness training to cover cloned voice, video impersonation and AI-generated email, built around behavioural patterns instead of spelling.
- Agree a payment threshold for dual authorisation and tell Finance, the PAs and the executive team.
- Turn on dual authorisation in the banking platform.
- Audit MFA on every account that can approve a payment, and move those accounts to passkeys or hardware keys.
- Write the callback policy. One page: who calls, which number, what to do when verification fails.
- Run a tabletop exercise. Simulate the call to the finance team and time how long a confirmed answer takes. Fix whatever was slow.
Our 30-second social engineering script gives the team something to use during item 1, and the invoice fraud guide covers the seasonal pattern.
Five ways this goes wrong
- Training from 2022. Content built around spelling and links describes an attack that has changed.
- No defined callback process. Staff know they should verify, hesitate because no process exists, and process the request.
- Treated as an IT matter alone. Finance holds the payment controls, HR holds the training, IT holds the identity configuration. So all three need to be in the room.
- No playbook for the first ten minutes. Bank recovery, above all, depends on speed. NCSC’s incident management guidance sets out that a response plan should connect to business continuity planning. The payment-recall sequence belongs there.
- Assuming size is protection. Smaller businesses are targeted for having fewer controls, which is a reason to hold the cheap ones.
Where to start
The policy half of this costs nothing. A callback rule, an agreed threshold and a hold on urgent requests can be written this week and will stop most attempts on their own.
The configuration half, by contrast, needs access. Phishing-resistant MFA on finance accounts, DMARC and SPF and DKIM set correctly, identity monitoring that flags an impossible sign-in, and payment approval workflows built into the accounts system.
Ask your IT partner, then, which of these they configure, and what evidence they can produce.
If a renewal or an assessment is coming up, we can audit MFA on your finance and executive accounts, check your outbound email authentication, and show you what a cloned-voice request would meet on the way in. Review your email and identity security, or start with the callback and payment policy if you would rather do the free half first.
