Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's sole authorised banking employee into moving nearly £1 million into 26 "safe" accounts over two days in October 2017, netting roughly £800,000 after partial recovery and triggering a club lawsuit against the bank over its duty of care.
Reviewed by the Social Engineering Examples team.
Over 9-10 October 2017, fraudsters phoned Hamilton Academical FC's finance department claiming to be RBS cyber-security/fraud staff and, over a sustained live-call social-engineering operation, convinced the club's sole authorised Bankline (business banking) user that the club's money was under threat from bank-insider theft and had to be urgently moved into new "safe" accounts. Across two days the employee authorised transfers totalling £989,000 out of three club accounts into 26 different recipient accounts, using disguised payment references (including player and football-club names) at the fraudsters' instruction. RBS's own fraud team suspended the first two payments (£40,000 and £70,000) as suspicious and called the club twice more to question the activity, but each time the employee, still following the scammers' script, told the bank to proceed, and £655,000 went out in 20 further transactions on the second day alone. The club later recovered about £170,000 through suspended/clawed-back payments, leaving a net loss of roughly £800,000, which CEO Colin McGowan said wiped out the bulk of the club's financial reserves. In February 2018 Hamilton announced it would sue RBS for 50% of the loss (£400,000-£415,000), arguing the bank's security procedures and duty of care had failed given it had already flagged two of the payments as suspicious; RBS denied any security breakdown, stating all payments were approved by the account's authorised user and that it had appropriately challenged the transactions twice. Police Scotland's economic crime unit investigated as one of over a dozen similar high-value vishing frauds against Scottish businesses around that time, including a near-identical scam against fellow club Heart of Midlothian; no publicly reported arrests, prosecution, or civil settlement/judgment was found in the sources reviewed.
Over 9-10 October 2017, a fraudster (using the alias "Stuart Davis") phoned Hamilton Academical Football Club claiming to be from RBS's cyber-security/fraud team, using a spoofed or plausible fraud-line-style number, and told the club's finance employee, who was the sole person authorised to operate the club's RBS Bankline (business online banking) accounts, that criminals inside the bank had compromised the club's accounts and that money needed to be moved into new "safe" accounts to protect it from theft. The caller built a false narrative (including a fabricated large fraudulent payment to a fertiliser company in Spain) and, per STV's reporting of a written case narrative shown to the outlet, referenced having had prior contact with the club and felt confident recognising the CEO's voice, lending the calls credibility. The employee was walked through moving funds via Bankline into a rotating set of 26 recipient accounts, reportedly using disguised references such as player names and football club names to make the transfers look legitimate on statements. RBS's own cyber-security team flagged and suspended the first two attempted payments (£40,000 and £70,000) as suspicious and contacted the club to question them, but the employee, still under the fraudster's direction, told the bank to proceed. By the end of day one, over £250,000 had moved across six payments; on day two, a further 20 transactions totalling £655,000 went out, again without being challenged, emptying three of the club's accounts of a combined £989,000. The fraudster told the employee he would "complete the clean-up operation" and return the money that evening; no such call came, and the club realised the next day it had been defrauded.
The lure was a fabricated bank-fraud emergency: a caller impersonating RBS's cyber-security/fraud team ("Stuart Davis") claiming the club's accounts had been compromised from inside the bank (citing a bogus large payment to a Spanish fertiliser company as "evidence") and that funds must be urgently moved to new "protected" accounts, with a promise that everything would be reconciled and returned that same evening. Tells that stood out only in hindsight: a real bank will never ask a customer to move money into different accounts to "protect" it, will never ask that transfers be disguised with unrelated reference names (player/club names), and will not keep pushing a customer to override its own fraud team's suspension of a payment; RBS's cyber-security system did in fact suspend the first two transfers and call to question the pattern twice more, which in retrospect was the clearest signal something was wrong, but the employee, coached by the fraudster throughout, told the bank to continue each time.
Hamilton Academical recovered about £170,000 of the £989,000 taken, via payments RBS was able to suspend/claw back, leaving the club roughly £800,000 out of pocket by the February 2018 reporting (later cited as £830,000 in a March 2018 follow-up), described by CEO Colin McGowan as the bulk of the club's financial reserves. In February 2018 the club's board instructed law firm Levy & McRae to pursue RBS for 50% of the loss (reported as £400,000, and as £415,000 once the loss estimate was revised to £830,000), arguing the bank's security and duty of care had lapsed given that it had already suspended two payments as suspicious yet let hundreds of further transfers proceed unchallenged the next day. RBS rejected liability, stating all payments were "keyed and approved by the authorised user of the club's account," that it had twice questioned the transactions and been instructed by the club to continue, and that it was working with Police Scotland to identify the perpetrators. As of the most recent dated reporting reviewed (BBC, 6 February 2018), RBS said it had not yet received a formal legal response from the club's lawyers, and no publicly reported settlement, court judgment, arrest, or prosecution outcome was found. In a March 2018 follow-up, the club's CEO said RBS had also refused his request to set a daily Bankline transfer limit on the club's account, telling the local paper the bank's system does not support customer-set daily limits and calling the bank "morally bankrupt" over the refusal. A near-identical vishing fraud was separately reported against fellow Scottish Premiership club Heart of Midlothian around the same period, and Police Scotland's economic crime unit said it was investigating over a dozen similar high-value frauds against Scottish businesses at the time.
The case is a textbook example of vishing/TOAD (telephone-oriented attack delivery) fraud against a business, and a rare instance where the victim organization publicly disclosed the loss, went on record with exact figures and CEO quotes, and pursued the bank rather than absorbing the loss quietly, surfacing a genuine and still-unresolved industry question about where liability sits when a bank's own fraud system flags a scam but a socially-engineered, authorised employee overrides the warning. It illustrates that having automated fraud-detection triggers is not sufficient if the escalation path still terminates in "ask the customer, and comply if they say continue": the fraud succeeded specifically at the moments RBS's system worked correctly (flagging the first two payments) because the human control that followed was engineered to fail. It also shows how a single point of payment authority (one sole signatory) at an organization with meaningful cash reserves is a high-value target, and how fraud crews scale the same script across multiple similar victims (here, two Scottish Premiership football clubs) rather than one-off attacks.
RBS's cyber-security team did flag and initially suspend the first two transactions (£40,000 and £70,000) on day one, and the bank says it called the club twice more during the two-day episode to question the pattern of payments, but each time the employee, still on the phone with (or having just spoken to) the fraudsters, instructed RBS to proceed, and the bank complied rather than escalating to a hard block, a callback-to-a-verified-number check, or a mandatory cooling-off period for a business account being emptied into 26 new payees inside 24 hours. Case-relevant lessons drawn out in the reporting and by security commentators: (1) never rely on a single authorised signatory for all business banking: dual-authorisation/maker-checker for high-value or unusual transfers would have given a second person the chance to question the calls; (2) treat any inbound call claiming to be "the bank" as unverified by default: hang up and dial the number on the back of the card or a previously-known statement, never a number or "fraud team" the caller supplies; (3) a real bank fraud team will never instruct a customer to move money to a new "safe" account, use disguised reference/payee names (e.g. player or club names), or keep a customer on the phone through repeated large transfers; (4) transaction-monitoring thresholds and velocity checks should trigger hard stops, not just phone challenges, when a business account moves from suspended £40k/£70k payments to 20+ further transfers totalling £655,000 in a single day; (5) staff training specific to vishing/TOAD scripts (urgency, "your money is at risk," fabricated case narratives) for anyone with payment authority.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
Fraudsters impersonating Leoni AG's senior executives tricked the German cable manufacturer's Romanian subsidiary finance team into wiring roughly EUR 40…
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad, India call-center conglomerates for a 2012-2016 IRS/USCIS impersonation vishing scheme…