COB fraud

COB fraud, short for Change of Bank fraud, is a form of financial crime in which fraudsters manipulate legitimate payment processes by intercepting and altering bank account details. The goal is to divert funds that are intended for a genuine supplier, client, or employee into fraudulent accounts controlled by the criminal. This type of fraud has become increasingly prevalent in the digital era, targeting both businesses and individuals through sophisticated social engineering and cybercrime tactics.

In essence, COB fraud occurs when a fraudster convinces a payer to send money to a different bank account under the pretext that the intended recipient’s bank details have changed. The deception often appears credible because it typically involves impersonating trusted entities and using convincing documentation or communication methods.

Change of Bank fraud is one of the fastest-growing financial crimes in the United Kingdom and across Europe, resulting in substantial financial losses for businesses each year. Understanding how it operates, recognising warning signs, and implementing preventive measures are essential to minimise exposure to this kind of fraud.

How COB Fraud Works

COB fraud exploits trust and familiarity within normal business operations. Fraudsters often monitor the communication between two legitimate parties, such as a supplier and a client, and intervene at the right moment to divert payments. The typical process involves several key stages:

  1. Information gathering: The fraudster first obtains information about an organisation’s suppliers, payment procedures, or ongoing transactions. This may occur through phishing emails, hacked accounts, or publicly available data.

  2. Impersonation: Once the target is identified, the fraudster impersonates a legitimate supplier or company representative, usually by email or phone. They may use fake email addresses that closely resemble genuine ones or compromise real accounts.

  3. Notification of new bank details: The fraudster contacts the victim, often posing as the supplier’s accounts department, and claims that the supplier’s banking information has changed. They provide new details, which are actually for an account they control.

  4. Payment redirection: The victim updates their records and unknowingly transfers the next payment to the fraudulent account. By the time the fraud is discovered, the funds are often withdrawn or transferred through multiple accounts to conceal the trail.

This type of fraud can affect organisations of any size, but small and medium-sized enterprises (SMEs) are often more vulnerable due to limited internal controls and less formal verification procedures.

Common Methods Used in COB Fraud

Change of Bank fraud can be carried out through various methods, each leveraging different weaknesses in business communication or systems.

  • Email compromise: Fraudsters gain access to or spoof business email accounts to send convincing messages. For example, a criminal might use an email domain that is only slightly different from a legitimate one (such as replacing a letter with a similar-looking character).

  • Invoice manipulation: Criminals may intercept genuine invoices sent by suppliers and alter the bank details before forwarding them to the payer. This approach is particularly common when invoices are sent in unsecured digital formats such as PDFs.

  • Social engineering: Attackers often conduct extensive research to understand an organisation’s structure, personnel, and suppliers. They may impersonate senior staff members or suppliers with urgent requests to process payments quickly, exploiting employees’ trust or fear of authority.

  • Compromised accounts: In more sophisticated cases, fraudsters hack into supplier email systems and send legitimate-looking messages from genuine addresses, making the fraud even harder to detect.

Because these attacks rely heavily on deception rather than purely technical intrusion, staff awareness and robust internal procedures are key to prevention.

Why COB Fraud Is So Effective

COB fraud is particularly successful because it exploits the natural trust inherent in ongoing business relationships. The communications used are often indistinguishable from genuine correspondence, especially when criminals have access to real invoices, email signatures, and company branding.

Several factors contribute to the effectiveness of COB fraud:

  • Lack of verification procedures: Many businesses do not have strict processes for confirming bank detail changes, relying instead on email communication alone.

  • High transaction volumes: In organisations with frequent payments to multiple suppliers, it is easy for a fraudulent change request to go unnoticed.

  • Time pressure: Fraudsters often create a sense of urgency, claiming that immediate payment is required to secure goods or avoid late fees.

  • Human error: Even well-trained employees can be deceived by realistic-looking emails or documents, especially when the request seems routine.

Fraudsters are adept at using psychological manipulation, often targeting accounts staff or individuals authorised to approve payments.

The Financial and Reputational Impact

The consequences of COB fraud can be devastating, particularly for small businesses. Financial losses can range from thousands to millions of pounds, depending on the size of the transaction.

Beyond direct monetary loss, the impact often extends further:

  • Cash flow disruption: Businesses may face liquidity problems after losing funds, especially if the stolen payment was substantial.

  • Operational delays: Legitimate suppliers may withhold goods or services until the missing payment is resolved, causing further disruption.

  • Reputational damage: Being the victim of fraud can harm a company’s reputation, leading to a loss of trust among clients and partners.

  • Legal and compliance issues: In some cases, disputes arise over liability between the paying organisation and the genuine supplier, leading to potential legal costs.

While some victims recover a portion of the funds through bank intervention, the chances of full recovery decrease significantly as time passes after the fraudulent transfer.

Examples of COB Fraud in Practice

COB fraud can occur in various forms and across multiple sectors. Common scenarios include:

  • A supplier sends an invoice for £50,000 to a construction company. A fraudster intercepts the email, alters the bank details, and forwards it to the company’s accounts department. The company pays the invoice, unaware that the funds have gone to the fraudster’s account.

  • An employee receives an urgent email from a senior executive instructing them to change the payment details for an overseas partner. The email is fake, but it appears genuine because the fraudster has carefully mimicked the executive’s writing style and signature.

  • A university receives a message from a research partner claiming their banking information has changed. The finance office updates the records and sends a large grant payment to the fraudulent account.

These examples demonstrate how COB fraud can target both private and public sector organisations, regardless of their size or industry.

Detecting and Preventing COB Fraud

Preventing COB fraud requires a combination of strong internal controls, employee training, and technological safeguards. Because the fraud often relies on deception rather than technical intrusion, human awareness plays a critical role in defence.

Effective preventive measures include:

  • Verification procedures: Always confirm any request to change bank details by calling a verified contact using a known phone number, not one provided in the email.

  • Dual authorisation: Implement systems that require two levels of approval for any changes to supplier banking details.

  • Regular staff training: Educate employees about COB fraud techniques and encourage them to question unusual or urgent requests.

  • Secure communication channels: Use encrypted email systems or secure online portals for transmitting payment details and invoices.

  • Fraud monitoring tools: Employ transaction monitoring software that flags unusual payment patterns or new bank accounts.

  • Supplier verification: Keep supplier records up to date and communicate regularly to confirm details outside of email correspondence.

A culture of vigilance and accountability is one of the strongest defences against COB fraud.

The Role of Financial Institutions

Banks play a key role in preventing and mitigating COB fraud. They are responsible for monitoring transactions, detecting suspicious activity, and working with clients to recover funds when fraud occurs.

In the United Kingdom, many banks participate in the Contingent Reimbursement Model Code, which outlines how victims of authorised push payment (APP) fraud, including COB fraud, may be eligible for reimbursement under certain conditions. To qualify, victims must demonstrate that they took reasonable steps to verify the payment and were not grossly negligent.

Banks also collaborate with law enforcement agencies such as Action Fraud and the National Crime Agency (NCA) to share intelligence and identify patterns of criminal activity.

Reporting and Recovery

If a business or individual suspects that they have been the victim of COB fraud, immediate action is essential to maximise the chance of recovery.

Recommended steps include:

  1. Contact the bank immediately: Inform the bank about the fraudulent transfer as soon as possible. Early notification increases the likelihood of freezing the funds before they are withdrawn.

  2. Notify the genuine supplier: Make them aware of the situation to prevent further confusion and ensure that future payments are secure.

  3. Report to Action Fraud: In the UK, Action Fraud serves as the national reporting centre for fraud and cybercrime.

  4. Preserve evidence: Retain all emails, invoices, and communications related to the fraud for investigation purposes.

  5. Inform staff and review procedures: Conduct an internal review to identify how the fraud occurred and strengthen future safeguards.

Although recovery rates for COB fraud vary, prompt reporting is the most critical factor in improving outcomes.

Regulatory and Legal Framework

In the United Kingdom, COB fraud is recognised under the broader category of authorised push payment (APP) fraud. While victims often authorise the transfer themselves, the payment is made under false pretences.

The Payment Services Regulations 2017 require payment service providers to act promptly when notified of fraud and to cooperate with investigations. Additionally, the Financial Conduct Authority (FCA) expects firms to maintain strong anti-fraud controls and treat customers fairly in the event of financial loss.

In 2019, the introduction of the Confirmation of Payee (CoP) system significantly enhanced fraud prevention. CoP verifies whether the name on the account matches the intended recipient’s details before payment is authorised, helping reduce misdirected transfers.

Legal responsibility in COB fraud cases can be complex, often depending on whether the victim followed appropriate verification processes and whether the bank met its obligations under the CoP framework.

Emerging Trends and Cybersecurity Implications

As businesses increasingly rely on digital communication, COB fraud is evolving with greater sophistication. Cybercriminals now use advanced tools such as deepfake technology, artificial intelligence, and data mining to create convincing imitations of legitimate communications.

Remote work and global supply chains have expanded the potential attack surface, making it easier for fraudsters to exploit fragmented communication channels. Meanwhile, social media platforms provide criminals with valuable information about company hierarchies and relationships, aiding impersonation efforts.

In response, many organisations are investing in advanced fraud detection systems, multi-factor authentication, and behavioural analytics to identify unusual patterns and prevent unauthorised changes to payment data.

Conclusion

COB fraud, or Change of Bank fraud, is a serious and growing threat to businesses and individuals alike. By exploiting trust, routine procedures, and digital communication channels, fraudsters can divert substantial sums of money before the deception is detected.

While technology and regulation provide important safeguards, the most effective defence lies in human awareness, strong internal controls, and prompt verification of financial information. Every organisation should establish clear policies for verifying changes in payment details, train employees to recognise red flags, and maintain close communication with suppliers and financial institutions.

In an increasingly digital and interconnected financial world, vigilance and due diligence are essential. Understanding COB fraud and adopting proactive measures can mean the difference between secure operations and costly financial loss.