UK NCA and NatWest Warn of Rising Invoice Fraud Threats
Summary
Hide ▲
Show ▼
The UK National Crime Agency (NCA) and NatWest Bank initially warned of rising invoice fraud in January 2026, reporting nearly £4 million in losses from 83 cases in September 2025 and urging businesses to verify payment details. Recent attention has focused on the construction sector, where complex supply chains and high-value email payments create elevated risks. Invoice fraud, a form of business email compromise (BEC), involves impersonating suppliers by changing bank details on fake invoices or hijacking supplier email accounts to gather intelligence before issuing fraudulent invoices. The NCA reports that construction and manufacturing accounted for a quarter of all invoice fraud cases in 2024/25—the highest of any sector. The agency is actively disrupting criminal networks while promoting prevention measures such as checking for email anomalies, verifying invoices via trusted channels, and requiring colleague authorization for high-value payments. Globally, BEC scams cost nearly $2.8 billion in 2024, according to the FBI, underscoring the severity of the threat.
Timeline
-
30.01.2026 13:10 2 articles · 1mo ago
NCA and NatWest Launch Joint Campaign Against Invoice Fraud
The UK’s National Crime Agency (NCA) and NatWest Bank issued a joint warning about rising invoice fraud, reporting nearly £4 million in losses from 83 cases in September 2025 and recommending verification of payment details and avoidance of urgent transfers. The campaign also emphasizes the severe financial impact on businesses and promotes the 'Check, Verify, Never' approach. New details from this article clarify that construction and manufacturing accounted for a quarter of all invoice fraud cases in 2024/25—the highest among all sectors. It also explains operational tactics used by fraudsters, including email hijacking, domain spoofing, and targeted pressure tactics on finance personnel in complex supply chains. The NCA reiterates its dual strategy of disrupting criminal networks through investigations and international intelligence sharing while stressing that prevention remains equally critical.
Show sources
- National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat — www.infosecurity-magazine.com — 30.01.2026 13:10
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
Information Snippets
-
Invoice fraud involves impersonating suppliers or intercepting emails to redirect payments.
First reported: 30.01.2026 13:101 source, 2 articlesShow sources
- National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat — www.infosecurity-magazine.com — 30.01.2026 13:10
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
-
In September 2025, 83 reported cases of invoice fraud resulted in nearly £4 million in losses.
First reported: 30.01.2026 13:101 source, 2 articlesShow sources
- National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat — www.infosecurity-magazine.com — 30.01.2026 13:10
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
-
The average loss per victim in September 2025 was £47,000.
First reported: 30.01.2026 13:101 source, 2 articlesShow sources
- National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat — www.infosecurity-magazine.com — 30.01.2026 13:10
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
-
The NCA and NatWest recommend verifying payment details and avoiding urgent transfers.
First reported: 30.01.2026 13:101 source, 2 articlesShow sources
- National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat — www.infosecurity-magazine.com — 30.01.2026 13:10
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
-
The campaign advises checking for changes in invoice details and calling suppliers on previously used phone numbers.
First reported: 30.01.2026 13:101 source, 1 articleShow sources
- National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat — www.infosecurity-magazine.com — 30.01.2026 13:10
-
Construction and manufacturing accounted for a quarter of invoice fraud cases in 2024/25, the highest among all sectors.
First reported: 26.03.2026 12:071 source, 1 articleShow sources
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
-
Invoice fraud often involves hijacking supplier email accounts to gather intelligence on typical invoice details and timing before issuing fake invoices.
First reported: 26.03.2026 12:071 source, 1 articleShow sources
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
-
Sender domains are sometimes spoofed or supplier emails are hacked to send fraudulent invoices.
First reported: 26.03.2026 12:071 source, 1 articleShow sources
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
-
Nick Sharp, NCA deputy director of fraud, stated that invoice fraud can destroy businesses through cashflow loss and devastate livelihoods.
First reported: 26.03.2026 12:071 source, 1 articleShow sources
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
-
The FBI reported that BEC scams, including invoice fraud, cost victims nearly $2.8bn globally in 2024, ranking as the second-highest grossing cybercrime type.
First reported: 26.03.2026 12:071 source, 1 articleShow sources
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
-
The NCA is actively disrupting criminal networks behind invoice fraud through investigations and international intelligence sharing, emphasizing prevention as equally critical.
First reported: 26.03.2026 12:071 source, 1 articleShow sources
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
-
The NCA and NFB recommend checking for changes in supplier email addresses, unusual language or grammar, and authorizing high-value payments only after colleague verification.
First reported: 26.03.2026 12:071 source, 1 articleShow sources
- Invoice Fraud Costs UK Construction Sector Millions, NCA Warns — www.infosecurity-magazine.com — 26.03.2026 12:07
Similar Happenings
Credential Theft and Account Compromise Surge in 2025
In 2025, cyber threat actors significantly increased their focus on credential theft, leading to a 389% rise in account compromise incidents, which constituted 55% of all attacks observed by eSentire. Credential access represented 75% of malicious activity, with two-thirds aimed at account takeovers and the remaining third used for phishing campaigns. Microsoft 365 accounts were primary targets. The use of phishing-as-a-service (PhaaS) kits, such as Tycoon2FA, FlowerStorm, and EvilProxy, fueled business email compromise (BEC) attacks. These kits are sophisticated, continuously updated, and designed to bypass modern security controls like multifactor authentication (MFA). While BEC attacks declined to less than 10% of malicious activity, they remained a top threat for companies, particularly in real estate, finance, retail, and construction. The report also highlighted a 14-fold increase in security incidents involving email bombing and IT Help Desk impersonation, a 300% spike in the ClickFix lure, and varying trends in cyber incidents across different industries.
Cyber Fraud Surpasses Ransomware as Top Business Concern
Cyber fraud, particularly phishing, has overtaken ransomware as the primary cybersecurity concern for business leaders, according to the World Economic Forum’s (WEF) Global Cybersecurity Outlook for 2026. The report highlights the pervasive nature of cyber-enabled fraud, which is causing significant financial losses and undermining trust in systems. Phishing attacks, including email, voice (vishing), and SMS (smishing), are the most commonly reported form of cyber fraud, affecting 62% of respondents. Other notable threats include invoice or payment fraud (37%), identity fraud (32%), insider threats (20%), and romance or impersonation scams (17%). The rise of AI-powered cyber threats is also a key concern, with 87% of respondents experiencing increased AI-related vulnerabilities in the past year.
Misconfigured Email Routing Exploited for Internal Domain Phishing
Threat actors are exploiting misconfigured email routing and spoof protections to impersonate organizations' domains and distribute phishing emails that appear to originate internally. This tactic has surged since May 2025, targeting various industries with phishing-as-a-service (PhaaS) platforms like Typhoon2FA. Successful attacks can lead to credential theft and business email compromise (BEC). The issue arises when complex routing scenarios are configured without strict spoof protections, allowing spoofed emails to bypass security measures. Microsoft blocked over 13 million malicious emails linked to the Typhoon2FA kit in October 2025. Organizations are advised to enforce strict DMARC and SPF policies, properly configure third-party connectors, and ensure MX records point directly to Office 365 to mitigate this risk.