Case Library / Vishing (Voice Phishing) / Barclays-Impersonation Vishing of UK Jeweller (2024)

Barclays-Impersonation Vishing of UK Jeweller (2024)

Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script, and talked a 70-something UK jeweller into installing AnyDesk on his business PC, draining GBP 48,451.78 from two accounts before solicitors clawed back GBP 25,650 from the bank.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In April 2024, the owner of a long-established, family-run UK jewellery business received a phone call from a man calling himself "Andrew," claiming to be from Barclays Bank's fraud department. "Andrew" told him there had been suspicious activity on his account, specifically citing an alleged GBP 18,123 payment to a company called "Energy One Limited," and instructed him to call back on a Barclays phone number "for legitimacy reasons," quoting a reference number. The callback number was a cloned/spoofed version of Barclays' real number, and the fraudsters played Barclays' actual hold music while the victim waited, both of which he checked and found convincing (he could verify the number matched Barclays' via Google, and recognized the hold music from genuine past calls with the bank). He was then connected to a second fraudster, "Charlie Adams," who asked him to confirm his overdraft limit and then guided him to log into his business online banking on his desktop computer. During that session he unknowingly downloaded and ran AnyDesk remote-access software, believing it was part of a bank security process; he was told his screen would go blank and that this signaled the issue was resolved. Overnight, suspicious and unable to sleep, he checked his accounts himself and discovered two of his business accounts had been drained, with only a few pence left, totaling GBP 48,451.78 stolen.

How the Attack Worked

The attackers combined caller-ID spoofing/cloning of Barclays' genuine phone number with playback of Barclays' actual telephone hold music, which let the victim "verify" the number himself via a Google search and hear what sounded like the bank's real on-hold system. Both checks a normal customer would consider sufficient proof of authenticity, but neither actually authenticates a caller, since both the number and the audio experience can be spoofed or replicated. The first caller ("Andrew") opened with a specific, plausible-sounding suspicious transaction (a named payee, "Energy One Limited," and an exact amount, GBP 18,123) to establish urgency and credibility, then told the victim to call back on the (spoofed) number "for legitimacy reasons" and to quote a reference number, a classic technique that keeps the victim inside a fraudster-controlled call loop while feeling like they initiated the safety check themselves. On the callback, a second caller ("Charlie Adams," posing as being from Barclays' fraud team) asked the victim to confirm his overdraft limit (a pretext-building/rapport step) and then walked him through logging into his business online banking on his desktop computer. During that guided session the victim was talked into downloading and running AnyDesk, a legitimate remote-desktop tool, believing it was part of the bank's security process; the caller told him the screen would go blank as part of the "fix," which is when the fraudsters actually took remote control and drained the accounts. The victim did not realize funds were missing until he checked his accounts overnight and found only a few pence left, confirming a loss of GBP 48,451.78 from two accounts.

The Lure & the Tell

The lure was a fabricated fraud alert: a caller identifying himself as "Andrew" from Barclays' fraud team claimed the victim's account showed an £18,123 payment to an unfamiliar payee, "Energy One Limited," and told him to call back on a number he could verify himself via Google, a spoofed/cloned Barclays number that appeared legitimate. The "tell," visible only in hindsight, was that no genuine bank fraud team instructs a customer to install third-party remote-access software (AnyDesk) or asks them to "confirm" security details like an overdraft limit over an inbound/callback phone call; legitimate banks never require screen-sharing or remote-control software to investigate suspicious transactions, and a caller directing a customer toward a specific verification method (Google the number, call this line, quote this reference) is itself a red flag, since real banks don't need to coach customers through their own verification process.

Outcome

The victim discovered the theft himself overnight after growing suspicious, finding his accounts nearly emptied (GBP 48,451.78 gone). Barclays' initial response was to return just GBP 30.21 and offer GBP 100 in compensation, which the victim and his family-run jewellery business (already needing to borrow roughly GBP 30,000 from a relative to keep operating) considered wholly inadequate. He engaged National Fraud Helpline (trading name of solicitors Richardson Hartley Law), whose lawyer Lena Abuagla argued Barclays should have detected the sudden large/unusual outbound payments and intervened; this pressure led Barclays to pay out GBP 25,650, roughly half the stolen total. National Fraud Helpline stated publicly (as of early 2025) that it intended to escalate the remaining unrecovered balance to the Financial Ombudsman Service, but no published Ombudsman ruling or further recovery for this case has been identified in available reporting.

Why It Matters

This case is a clean, well-documented illustration of how caller-ID spoofing plus mimicry of incidental sensory details (hold music) can defeat the exact self-verification steps ("check the number on Google," "you'll recognize our hold music") that banks and consumer-advice guidance often tell customers to use, turning a customer's own diligence into part of the con. It also shows the endgame pivot common in bank-impersonation vishing: once trust is established, the ask shifts from information disclosure to installing remote-access software, at which point the fraudster no longer needs the victim to authorize anything further: they simply operate the victim's own banking session. Finally, it demonstrates that the initial bank response to APP (authorised push payment) fraud claims can be minimal (GBP 30.21 plus a GBP 100 goodwill offer against a GBP 48,451.78 loss) and that specialist legal advocacy, arguing the bank's own transaction-monitoring should have caught the anomaly, materially changed the recovery outcome (to GBP 25,650), underscoring both a gap in first-line bank fraud response and the value (and necessity) of escalation routes like the Financial Ombudsman Service for victims who receive inadequate initial redress.

Defenses

Reported defensive/remediation lessons drawn from the case: (1) banks cannot fully rely on customers to "verify" a caller by Google-searching a phone number, since number cloning/spoofing defeats that check; verification must instead use a callback to a number obtained independently of the call itself (e.g. from a card or statement, or via the bank's app), never a number given or confirmed by the caller; (2) hold music and on-brand call scripting are not proof of authenticity and should not be treated as identity signals; (3) never install remote-access software (AnyDesk, TeamViewer, etc.) at the request of an unsolicited caller claiming to be from a bank, and never log into online/business banking while screen-sharing with someone reached via an inbound "fraud team" call; (4) banks' fraud-detection systems should flag and interdict sudden large or unusual outbound payments (as the victim's lawyers successfully argued Barclays should have done), and customers/businesses should set up transaction alerts and lower standing payment limits where possible; (5) victims of authorised push payment (APP) fraud who receive inadequate first-line compensation from their bank have recourse via a specialist solicitor and ultimately the Financial Ombudsman Service, and should not accept a low goodwill offer as final; (6) businesses, especially those handling large sums like jewellers, should have a documented protocol requiring any account/payment "security" instructions received by phone to be independently verified in person or via a separately-initiated channel before acting.

Sources
  • New Bank Fraud Scam. National Fraud Helpline Primary. Primary case account from the solicitors' firm (Richardson Hartley Law, trading as National Fraud Helpline) that represented the victim and negotiated the GBP 25,650 recovery from Barclays; includes direct quotes from the victim and lawyer Lena Abuagla. Fetched and confirmed live 2026-07-29; content matches all headline facts.
  • Jeweller loses £50k in bank scam. Jewellery Focus Secondary. Trade-press report with full narrative detail, including confirmation of the planned Financial Ombudsman Service escalation. Fetched and confirmed live 2026-07-29 (partially paywalled but visible lede/body confirms facts).
  • Jeweller loses £50k in sophisticated bank scam. Professional Jeweller Secondary. Fetched and confirmed live 2026-07-29; full-text article corroborates every specific fact in the case (amounts, aliases, HSBC receiving accounts, Ombudsman plan, direct quotes).
  • Jeweller loses £50,000 in sophisticated bank scam. Retail Jeweller Secondary. Fetched and confirmed live 2026-07-29 (paywalled beyond the lede, but visible content matches the case topic and headline facts).
  • New bank scam is music to a fraudster's ears. SME Magazine Secondary. Fetched and confirmed live 2026-07-29; full-text article corroborates all narrative and financial details.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target selection: No public reporting describes individualized research on this specific jeweller; the targeting is likely consistent with opportunistic bank-impersonation vishing operations that work through bulk phone-number lists, previously breached contact data, or cold-called number pools rather than bespoke OSINT on each victim.
Countering Stage 1: Opportunistic target selection through bulk number lists or breached contact data sits outside any single business's ability to prevent; the realistic control is generalized fraud-awareness training for SME owners and staff, especially those handling high transaction values like jewellers, so that any inbound "bank fraud team" call is treated as suspect regardless of why that business was called.
2
Infrastructure setup: The attackers used caller-ID spoofing/cloning to display Barclays' genuine phone number and prepared a recording or replay of Barclays' actual telephone hold music, plus a two-persona script ("Andrew," then "Charlie Adams") to run a first-caller/second-caller handoff.
Countering Stage 2: Caller-ID spoofing and hold-music replication are invisible to the person receiving the call and defeat the exact self-checks banks often recommend; the practical control sits with telecoms and banks, through call-authentication standards such as STIR/SHAKEN-style number attestation, and clear customer messaging that a matching caller ID or familiar hold music is never proof of identity.
3
Initial pretext call: The first caller opened with a specific, plausible-sounding fraud alert, a named payee ("Energy One Limited") and an exact amount (GBP 18,123), then directed the victim to call back "for legitimacy reasons" on the spoofed number and quote a reference number.
Countering Stage 3: Customers should treat any unsolicited call reporting suspicious account activity, however specific the transaction detail sounds, as unverified by default, and hang up and initiate contact themselves rather than accepting a callback number or reference quoted by the caller.
4
Manufactured self-verification loop: The victim's own diligence, Googling the number and recognizing the hold music, appeared to confirm legitimacy, because both checks were satisfied by attacker-controlled infrastructure rather than genuine verification, and the callback kept him inside the fraudster's call loop.
Countering Stage 4: Verification must use a channel obtained independently of the call itself, such as the number on a card or statement or the bank's official app, never a number or method suggested during the call, since accepting the caller's suggested check keeps the victim inside attacker-controlled infrastructure.
5
Rapport-building and pretext escalation: The second caller ("Charlie Adams") asked the victim to confirm his overdraft limit, a low-stakes incremental compliance step that built trust and normalized following further instructions before the larger ask came.
Countering Stage 5: Any request to "confirm" account details such as an overdraft limit should be recognized as a rapport-building or information-harvesting step, since legitimate bank fraud teams do not need a customer to restate their own account parameters back to them.
6
Remote-access tool installation: The victim was guided to log into his business online banking on his desktop computer and, believing it was part of a bank security process, unknowingly downloaded and ran AnyDesk remote-access software.
Countering Stage 6: A firm personal and organizational policy against installing remote-access software (AnyDesk, TeamViewer, and similar tools) or logging into banking while screen-sharing at an unsolicited caller's request removes the single step this attack actually depended on to succeed.
7
Account takeover and fund exfiltration: The caller told the victim his screen would go blank as part of the "fix"; that blank screen was in fact the fraudsters taking remote control and draining GBP 48,451.78 from two business accounts while the victim believed the issue was resolved.
Countering Stage 7: Bank-side transaction-monitoring tuned to flag and hold sudden, large, or unusual outbound payments from a business account, the exact control the victim's solicitors argued Barclays should have applied, provides a last line of defense even after remote access has already been granted.
8
Cash-out through receiving accounts: The stolen funds moved on into intermediary or receiving accounts; per reporting, Barclays' first recovery effort clawed back only GBP 30.21 from two receiving HSBC accounts, indicating the money had already been moved onward before broader negotiated recovery began.
Countering Stage 8: Receiving-bank due diligence and cross-institution mule-account detection, KYC and transaction-monitoring at the bank that received the stolen funds, is the last-resort control once money has left the victim's account, and is consistent with how a small initial sum (GBP 30.21) was recovered from the receiving HSBC accounts ahead of the larger negotiated settlement.
Quick Facts
Victim
Unnamed UK jeweller (family-run jewellery business; victim is the owner, a man in his 70s), client of National Fraud Helpline / Richardson Hartley Law
Location
United Kingdom (jeweller's business location not further specified in public reporting)
Date
2024-04 (scam call); reported publicly ~January 31, 2025 (Jewellery Focus) and February 7, 2025 (National Fraud Helpline)
Impact
GBP 48,451.78 stolen from two of the victim's business bank accounts. Barclays initially returned only GBP 30.21 and offered GBP 100 in goodwill compensation. After National Fraud Helpline solicitors intervened and argued Barclays should have flagged the unusual payment activity, the firm recovered GBP 25,650 from Barclays (a little over half the stolen amount) for the victim; National Fraud Helpline stated it intended to pursue the remaining shortfall via a complaint to the Financial Ombudsman Service, but no publicly reported Ombudsman decision/outcome for this specific case was found as of the reporting period.
Status
Confirmed
Case Type
Real-World Incident
Sector
Retail & E-commerce
Related

Related Cases

Singapore Anti-Scam Centre / Police Impersonation Scam: "Jane" Loses S$1.2 Million (2024-2025)

A Singaporean finance professional in her 50s lost S$1.2 million (~US$900,000) over two months after scammers impersonating an Anti-Scam Centre…

Incident 2024Read →

NZ Bank-Impersonation Spoofed-Callback Vishing Scam: $30,000 Banking Ombudsman Case

A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team, and talked a customer into…

Incident 2024Read →

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…

Incident 2024Read →