Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script.
Social Engineering Examples·5 sources
In April 2024, the owner of a long-established, family-run UK jewellery business received a phone call from a man calling himself "Andrew," claiming to be from Barclays Bank's fraud department. "Andrew" told him there had been suspicious activity on his account, specifically citing an alleged GBP 18,123 payment to a company called "Energy One Limited," and instructed him to call back on a Barclays phone number "for legitimacy reasons," quoting a reference number.
The callback number was a cloned/spoofed version of Barclays' real number, and the fraudsters played Barclays' actual hold music while the victim waited, both of which he checked and found convincing (he could verify the number matched Barclays' via Google, and recognized the hold music from genuine past calls with the bank). He was then connected to a second fraudster, "Charlie Adams," who asked him to confirm his overdraft limit and then guided him to log into his business online banking on his desktop computer.
During that session he unknowingly downloaded and ran AnyDesk remote-access software, believing it was part of a bank security process; he was told his screen would go blank and that this signaled the issue was resolved. Overnight, suspicious and unable to sleep, he checked his accounts himself and discovered two of his business accounts had been drained, with only a few pence left, totaling GBP 48,451.78 stolen.
The attackers combined caller-ID spoofing/cloning of Barclays' genuine phone number with playback of Barclays' actual telephone hold music, which let the victim "verify" the number himself via a Google search and hear what sounded like the bank's real on-hold system. Both checks a normal customer would consider sufficient proof of authenticity, but neither actually authenticates a caller, since both the number and the audio experience can be spoofed or replicated.
The first caller ("Andrew") opened with a specific, plausible-sounding suspicious transaction (a named payee, "Energy One Limited," and an exact amount, GBP 18,123) to establish urgency and credibility, then told the victim to call back on the (spoofed) number "for legitimacy reasons" and to quote a reference number, a classic technique that keeps the victim inside a fraudster-controlled call loop while feeling like they initiated the safety check themselves.
On the callback, a second caller ("Charlie Adams," posing as being from Barclays' fraud team) asked the victim to confirm his overdraft limit (a pretext-building/rapport step) and then walked him through logging into his business online banking on his desktop computer. During that guided session the victim was talked into downloading and running AnyDesk, a legitimate remote-desktop tool, believing it was part of the bank's security process; the caller told him the screen would go blank as part of the "fix," which is when the fraudsters actually took remote control and drained the accounts.
The victim did not realize funds were missing until he checked his accounts overnight and found only a few pence left, confirming a loss of GBP 48,451.78 from two accounts.
The lure was a fabricated fraud alert: a caller identifying himself as "Andrew" from Barclays' fraud team claimed the victim's account showed an £18,123 payment to an unfamiliar payee, "Energy One Limited," and told him to call back on a number he could verify himself via Google, a spoofed/cloned Barclays number that appeared legitimate. The "tell," visible only in hindsight, was that no genuine bank fraud team instructs a customer to install third-party remote-access software (AnyDesk) or asks them to "confirm" security details like an overdraft limit over an inbound/callback phone call; legitimate banks never require screen-sharing or remote-control software to investigate suspicious transactions, and a caller directing a customer toward a specific verification method (Google the number, call this line, quote this reference) is itself a red flag, since real banks don't need to coach customers through their own verification process.
The victim discovered the theft himself overnight after growing suspicious, finding his accounts nearly emptied (GBP 48,451.78 gone). Barclays' initial response was to return just GBP 30.21 and offer GBP 100 in compensation, which the victim and his family-run jewellery business (already needing to borrow roughly GBP 30,000 from a relative to keep operating) considered wholly inadequate.
He engaged National Fraud Helpline (trading name of solicitors Richardson Hartley Law), whose lawyer Lena Abuagla argued Barclays should have detected the sudden large/unusual outbound payments and intervened; this pressure led Barclays to pay out GBP 25,650, roughly half the stolen total. National Fraud Helpline stated publicly (as of early 2025) that it intended to escalate the remaining unrecovered balance to the Financial Ombudsman Service, but no published Ombudsman ruling or further recovery for this case has been identified in available reporting.
This case is a clean, well-documented illustration of how caller-ID spoofing plus mimicry of incidental sensory details (hold music) can defeat the exact self-verification steps ("check the number on Google," "you'll recognize our hold music") that banks and consumer-advice guidance often tell customers to use, turning a customer's own diligence into part of the con.
It also shows the endgame pivot common in bank-impersonation vishing: once trust is established, the ask shifts from information disclosure to installing remote-access software, at which point the fraudster no longer needs the victim to authorize anything further: they simply operate the victim's own banking session. Finally, it demonstrates that the initial bank response to APP (authorised push payment) fraud claims can be minimal (GBP 30.21 plus a GBP 100 goodwill offer against a GBP 48,451.78 loss) and that specialist legal advocacy, arguing the bank's own transaction-monitoring should have caught the anomaly, materially changed the recovery outcome (to GBP 25,650), underscoring both a gap in first-line bank fraud response and the value (and necessity) of escalation routes like the Financial Ombudsman Service for victims who receive inadequate initial redress.
Reported defensive/remediation lessons drawn from the case: (1) banks cannot fully rely on customers to "verify" a caller by Google-searching a phone number, since number cloning/spoofing defeats that check; verification must instead use a callback to a number obtained independently of the call itself (e.g. from a card or statement, or via the bank's app), never a number given or confirmed by the caller; (2) hold music and on-brand call scripting are not proof of authenticity and should not be treated as identity signals; (3) never install remote-access software (AnyDesk, TeamViewer, etc.) at the request of an unsolicited caller claiming to be from a bank, and never log into online/business banking while screen-sharing with someone reached via an inbound "fraud team" call; (4) banks' fraud-detection systems should flag and interdict sudden large or unusual outbound payments (as the victim's lawyers successfully argued Barclays should have done), and customers/businesses should set up transaction alerts and lower standing payment limits where possible; (5) victims of authorised push payment (APP) fraud who receive inadequate first-line compensation from their bank have recourse via a specialist solicitor and ultimately the Financial Ombudsman Service, and should not accept a low goodwill offer as final; (6) businesses, especially those handling large sums like jewellers, should have a documented protocol requiring any account/payment "security" instructions received by phone to be independently verified in person or via a separately-initiated channel before acting.
Social Engineering Examples. “Barclays-Impersonation Vishing of UK Jeweller (2024)”. Accessed 19 September 2026. https://socialengineeringexamples.com/barclays-jeweller-anydesk-vishing-2024
No public reporting describes individualized research on this specific jeweller; the targeting is likely consistent with opportunistic bank-impersonation vishing operations that work through bulk phone-number lists, previously breached contact data, or cold-called number pools rather than bespoke OSINT on each victim.
Opportunistic target selection through bulk number lists or breached contact data sits outside any single business's ability to prevent; the realistic control is generalized fraud-awareness training for SME owners and staff, especially those handling high transaction values like jewellers, so that any inbound "bank fraud team" call is treated as suspect regardless of why that business was called.
The attackers used caller-ID spoofing/cloning to display Barclays' genuine phone number and prepared a recording or replay of Barclays' actual telephone hold music, plus a two-persona script ("Andrew," then "Charlie Adams") to run a first-caller/second-caller handoff.
Caller-ID spoofing and hold-music replication are invisible to the person receiving the call and defeat the exact self-checks banks often recommend; the practical control sits with telecoms and banks, through call-authentication standards such as STIR/SHAKEN-style number attestation, and clear customer messaging that a matching caller ID or familiar hold music is never proof of identity.
The first caller opened with a specific, plausible-sounding fraud alert, a named payee ("Energy One Limited") and an exact amount (GBP 18,123), then directed the victim to call back "for legitimacy reasons" on the spoofed number and quote a reference number.
Customers should treat any unsolicited call reporting suspicious account activity, however specific the transaction detail sounds, as unverified by default, and hang up and initiate contact themselves rather than accepting a callback number or reference quoted by the caller.
The victim's own diligence, Googling the number and recognizing the hold music, appeared to confirm legitimacy, because both checks were satisfied by attacker-controlled infrastructure rather than genuine verification, and the callback kept him inside the fraudster's call loop.
Verification must use a channel obtained independently of the call itself, such as the number on a card or statement or the bank's official app, never a number or method suggested during the call, since accepting the caller's suggested check keeps the victim inside attacker-controlled infrastructure.
The second caller ("Charlie Adams") asked the victim to confirm his overdraft limit, a low-stakes incremental compliance step that built trust and normalized following further instructions before the larger ask came.
Any request to "confirm" account details such as an overdraft limit should be recognized as a rapport-building or information-harvesting step, since legitimate bank fraud teams do not need a customer to restate their own account parameters back to them.
The victim was guided to log into his business online banking on his desktop computer and, believing it was part of a bank security process, unknowingly downloaded and ran AnyDesk remote-access software.
A firm personal and organizational policy against installing remote-access software (AnyDesk, TeamViewer, and similar tools) or logging into banking while screen-sharing at an unsolicited caller's request removes the single step this attack actually depended on to succeed.
The caller told the victim his screen would go blank as part of the "fix"; that blank screen was in fact the fraudsters taking remote control and draining GBP 48,451.78 from two business accounts while the victim believed the issue was resolved.
Bank-side transaction-monitoring tuned to flag and hold sudden, large, or unusual outbound payments from a business account, the exact control the victim's solicitors argued Barclays should have applied, provides a last line of defense even after remote access has already been granted.
The stolen funds moved on into intermediary or receiving accounts; per reporting, Barclays' first recovery effort clawed back only GBP 30.21 from two receiving HSBC accounts, indicating the money had already been moved onward before broader negotiated recovery began.
Receiving-bank due diligence and cross-institution mule-account detection, KYC and transaction-monitoring at the bank that received the stolen funds, is the last-resort control once money has left the victim's account, and is consistent with how a small initial sum (GBP 30.21) was recovered from the receiving HSBC accounts ahead of the larger negotiated settlement.
Browse by what this case has in common with others in the library.
A Singaporean finance professional in her 50s lost S$1.2 million.
A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team.
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT.
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling…
A Metropolitan Police officer spotted customers' passports and tax-credit paperwork clearly visible through transparent bin bags left on the street.