Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script, and talked a 70-something UK jeweller into installing AnyDesk on his business PC, draining GBP 48,451.78 from two accounts before solicitors clawed back GBP 25,650 from the bank.
Reviewed by the Social Engineering Examples team.
In April 2024, the owner of a long-established, family-run UK jewellery business received a phone call from a man calling himself "Andrew," claiming to be from Barclays Bank's fraud department. "Andrew" told him there had been suspicious activity on his account, specifically citing an alleged GBP 18,123 payment to a company called "Energy One Limited," and instructed him to call back on a Barclays phone number "for legitimacy reasons," quoting a reference number. The callback number was a cloned/spoofed version of Barclays' real number, and the fraudsters played Barclays' actual hold music while the victim waited, both of which he checked and found convincing (he could verify the number matched Barclays' via Google, and recognized the hold music from genuine past calls with the bank). He was then connected to a second fraudster, "Charlie Adams," who asked him to confirm his overdraft limit and then guided him to log into his business online banking on his desktop computer. During that session he unknowingly downloaded and ran AnyDesk remote-access software, believing it was part of a bank security process; he was told his screen would go blank and that this signaled the issue was resolved. Overnight, suspicious and unable to sleep, he checked his accounts himself and discovered two of his business accounts had been drained, with only a few pence left, totaling GBP 48,451.78 stolen.
The attackers combined caller-ID spoofing/cloning of Barclays' genuine phone number with playback of Barclays' actual telephone hold music, which let the victim "verify" the number himself via a Google search and hear what sounded like the bank's real on-hold system. Both checks a normal customer would consider sufficient proof of authenticity, but neither actually authenticates a caller, since both the number and the audio experience can be spoofed or replicated. The first caller ("Andrew") opened with a specific, plausible-sounding suspicious transaction (a named payee, "Energy One Limited," and an exact amount, GBP 18,123) to establish urgency and credibility, then told the victim to call back on the (spoofed) number "for legitimacy reasons" and to quote a reference number, a classic technique that keeps the victim inside a fraudster-controlled call loop while feeling like they initiated the safety check themselves. On the callback, a second caller ("Charlie Adams," posing as being from Barclays' fraud team) asked the victim to confirm his overdraft limit (a pretext-building/rapport step) and then walked him through logging into his business online banking on his desktop computer. During that guided session the victim was talked into downloading and running AnyDesk, a legitimate remote-desktop tool, believing it was part of the bank's security process; the caller told him the screen would go blank as part of the "fix," which is when the fraudsters actually took remote control and drained the accounts. The victim did not realize funds were missing until he checked his accounts overnight and found only a few pence left, confirming a loss of GBP 48,451.78 from two accounts.
The lure was a fabricated fraud alert: a caller identifying himself as "Andrew" from Barclays' fraud team claimed the victim's account showed an £18,123 payment to an unfamiliar payee, "Energy One Limited," and told him to call back on a number he could verify himself via Google, a spoofed/cloned Barclays number that appeared legitimate. The "tell," visible only in hindsight, was that no genuine bank fraud team instructs a customer to install third-party remote-access software (AnyDesk) or asks them to "confirm" security details like an overdraft limit over an inbound/callback phone call; legitimate banks never require screen-sharing or remote-control software to investigate suspicious transactions, and a caller directing a customer toward a specific verification method (Google the number, call this line, quote this reference) is itself a red flag, since real banks don't need to coach customers through their own verification process.
The victim discovered the theft himself overnight after growing suspicious, finding his accounts nearly emptied (GBP 48,451.78 gone). Barclays' initial response was to return just GBP 30.21 and offer GBP 100 in compensation, which the victim and his family-run jewellery business (already needing to borrow roughly GBP 30,000 from a relative to keep operating) considered wholly inadequate. He engaged National Fraud Helpline (trading name of solicitors Richardson Hartley Law), whose lawyer Lena Abuagla argued Barclays should have detected the sudden large/unusual outbound payments and intervened; this pressure led Barclays to pay out GBP 25,650, roughly half the stolen total. National Fraud Helpline stated publicly (as of early 2025) that it intended to escalate the remaining unrecovered balance to the Financial Ombudsman Service, but no published Ombudsman ruling or further recovery for this case has been identified in available reporting.
This case is a clean, well-documented illustration of how caller-ID spoofing plus mimicry of incidental sensory details (hold music) can defeat the exact self-verification steps ("check the number on Google," "you'll recognize our hold music") that banks and consumer-advice guidance often tell customers to use, turning a customer's own diligence into part of the con. It also shows the endgame pivot common in bank-impersonation vishing: once trust is established, the ask shifts from information disclosure to installing remote-access software, at which point the fraudster no longer needs the victim to authorize anything further: they simply operate the victim's own banking session. Finally, it demonstrates that the initial bank response to APP (authorised push payment) fraud claims can be minimal (GBP 30.21 plus a GBP 100 goodwill offer against a GBP 48,451.78 loss) and that specialist legal advocacy, arguing the bank's own transaction-monitoring should have caught the anomaly, materially changed the recovery outcome (to GBP 25,650), underscoring both a gap in first-line bank fraud response and the value (and necessity) of escalation routes like the Financial Ombudsman Service for victims who receive inadequate initial redress.
Reported defensive/remediation lessons drawn from the case: (1) banks cannot fully rely on customers to "verify" a caller by Google-searching a phone number, since number cloning/spoofing defeats that check; verification must instead use a callback to a number obtained independently of the call itself (e.g. from a card or statement, or via the bank's app), never a number given or confirmed by the caller; (2) hold music and on-brand call scripting are not proof of authenticity and should not be treated as identity signals; (3) never install remote-access software (AnyDesk, TeamViewer, etc.) at the request of an unsolicited caller claiming to be from a bank, and never log into online/business banking while screen-sharing with someone reached via an inbound "fraud team" call; (4) banks' fraud-detection systems should flag and interdict sudden large or unusual outbound payments (as the victim's lawyers successfully argued Barclays should have done), and customers/businesses should set up transaction alerts and lower standing payment limits where possible; (5) victims of authorised push payment (APP) fraud who receive inadequate first-line compensation from their bank have recourse via a specialist solicitor and ultimately the Financial Ombudsman Service, and should not accept a low goodwill offer as final; (6) businesses, especially those handling large sums like jewellers, should have a documented protocol requiring any account/payment "security" instructions received by phone to be independently verified in person or via a separately-initiated channel before acting.
A Singaporean finance professional in her 50s lost S$1.2 million (~US$900,000) over two months after scammers impersonating an Anti-Scam Centre…
A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team, and talked a customer into…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…