helpdesk@saascoms.com
en English fr French es Spanish Mailmaster: Log In     Omnireach: Log In

Get Started

Banking fraud in the UK: What businesses need to know

Introduction

Criminals stole approximately £1.3 billion from individuals through banking fraud in the UK and scams in 2025, according to the House of Commons Library.

Fraud is no longer a peripheral crime. Banking and other forms of fraud accounted for more than 45% of crimes against individuals in England and Wales during 2025, with around 1 in 14 adults becoming a victim.

The financial impact extends far beyond the money taken directly from victims. The government estimated fraud cost UK society at least £14.4 billion in 2023–24. This includes financial losses, victim support, attempts to recover stolen funds, investigations and the prosecution of offenders.

As criminals increasingly exploit digital platforms, telecommunications networks and financial systems, fraud prevention has become a shared responsibility across public and private sectors.

The Scale of Banking Fraud in the UK

Industry body UK Finance estimates that criminals successfully stole £1.28 billion through banking fraud and scams in 2025.

This was divided into two main categories:

  • £703 million in unauthorised fraud
  • £576 million in authorised fraud

Although both result in financial loss, they happen in different ways.

Unauthorised Fraud

Unauthorised fraud occurs when a third party makes a fraudulent transaction without the victim’s permission. This may involve stolen card details, compromised accounts or identity theft. Payment providers reimburse victims of unauthorised fraud in most circumstances.

Authorised Push Payment fraud

Authorised fraud occurs when a victim is manipulated into making a payment to an account controlled by a criminal. It is commonly known as Authorised Push Payment fraud, or APP fraud.

These scams can be particularly convincing. Criminals may impersonate banks, government departments, suppliers, colleagues, family members or trusted organisations. They often create a sense of urgency, encouraging the victim to act before checking whether the request is genuine.

Since October 2024, payment providers have been legally required to reimburse eligible victims of APP fraud, subject to certain conditions. For example, reimbursement may not apply where a customer has acted with gross negligence.

Following the introduction of the new requirements, the APP fraud reimbursement rate increased from approximately 54% to 65%.

Reimbursement offers greater protection to victims, but it does not remove the wider consequences of fraud. Organisations still face operational disruption, investigation costs, reputational damage and a loss of customer trust.

How Fraud is Investigated

Most fraud cases are investigated by local police forces.

In England, Wales and Northern Ireland, Report Fraud, based within the City of London Police, acts as the national reporting centre. In Scotland, suspected fraud is reported directly to Police Scotland.

The City of London Police assesses reports and refers cases with investigative potential to local forces. Depending on their scale and complexity, cases may be handled by:

  • Individual territorial police forces
  • Regional Organised Crime Units
  • The National Crime Agency
  • The Serious Fraud Office

The most serious, complex or geographically widespread cases are more likely to be escalated to national agencies.

However, the policing response to fraud has faced considerable criticism. In the year ending March 2025, only 4% of recorded fraud offences were referred to territorial police forces for investigation.

This has contributed to concerns that fraud has historically been treated as a lower priority than other forms of crime, despite its prevalence and financial impact.

The Government’s Fraud Strategy 2026–2029

In March 2026, the government published its Fraud Strategy 2026–2029, intended to disrupt criminal activity, strengthen economic resilience and improve access to justice.

The strategy includes several major initiatives:

A new Online Crime Centre

The government plans to launch a public-private Online Crime Centre, bringing organisations together to share data and coordinate interventions.

Its purpose will be to identify and eliminate online fraud at scale. Collaboration will be essential because a single scam may involve online advertisements, social media accounts, messaging services, telephone numbers, payment providers and bank accounts.

A Streamlined Reporting Service

Report Fraud is intended to provide victims with a simpler and more effective way to report suspected fraud.

An improved reporting process should also help law enforcement agencies collect better information, identify connections between cases and determine which reports have the greatest potential for investigation.

A Fraud Victims Charter

The proposed Fraud Victims Charter will establish a minimum standard of care across organisations that support victims.

The aim is to make assistance more consistent, regardless of where or how the fraud occurred. Support may include practical guidance, emotional assistance, help securing compromised accounts and information about recovering losses.

A Stronger Proactive Policing Response

The government also intends to enhance the law enforcement PROTECT response.

This will include more data-led, proactive policing and targeted assistance for people considered particularly vulnerable to fraud.

Rather than responding only after money has been stolen, authorities will increasingly seek to identify patterns of risk and intervene sooner.

Greater Industry Collaboration

The strategy recognises that fraud cannot be addressed by law enforcement alone.

The government plans to work more closely with the:

  • Telecommunications sector
  • Online technology sector
  • Financial services sector

Each industry operates infrastructure that criminals can exploit. Fraudsters may use spoofed telephone numbers, fraudulent text messages, online advertisements, fake websites, compromised accounts and manipulated payment systems as part of the same attack.

Effective prevention therefore depends on organisations sharing intelligence, closing vulnerabilities and stopping suspicious activity before it reaches the victim.

Why Telecommunications Providers have a Crucial Role

Many fraud attempts begin with a phone call or text message.

Criminals frequently use communications networks to impersonate legitimate organisations, distribute malicious links and pressure victims into transferring money or disclosing sensitive information.

For telecommunications providers, fraud prevention is becoming an increasingly important part of protecting customers and maintaining trust.

Measures may include:

  • Detecting and blocking suspicious calls and messages
  • Reducing number spoofing
  • Monitoring unusual communications activity
  • Strengthening customer identity checks
  • Sharing fraud intelligence with banks, technology companies and law enforcement
  • Educating customers about common warning signs

No individual measure will stop every scam. However, coordinated action across communications, technology and financial services can make fraudulent activity more difficult, expensive and risky for criminals.

A Shared Responsibility

Public-sector reviews have repeatedly identified weaknesses in the UK’s response to fraud.

Scrutiny from the policing inspectorate, the Home Affairs Committee and the National Audit Office has highlighted several recurring concerns, including:

  • The absence of a sufficiently joined-up strategy
  • Fraud being treated as a low policing priority
  • Limited investigative capacity
  • Insufficient action from technology and banking companies
  • Fragmented support for victims

The Fraud Strategy 2026–2029 is intended to address many of these problems. Its success, however, will depend on effective delivery and meaningful cooperation between government, police, banks, technology platforms and telecommunications providers.

Building a Stronger Defence against Fraud

The scale of banking fraud in the UK demonstrates that scams are not simply a problem for individual victims or financial institutions.

They are a wider economic and societal threat that relies on interconnected digital and communications infrastructure.

For businesses, the message is clear: fraud prevention must be built into everyday operations, rather than treated solely as a response to incidents.

As fraud techniques continue to evolve, businesses that act proactively will be better placed to protect their customers, employees, finances and reputation.

At Saascoms we are Cyber Essentials Plus, ISO27001 and Government G Cloud, develop our platforms in the UK and ensure client data is kept in the UK.