Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
Social Engineering Examples·8 sources
Over 9-10 October 2017, fraudsters phoned Hamilton Academical FC's finance department claiming to be RBS cyber-security/fraud staff and, over a sustained live-call social-engineering operation, convinced the club's sole authorised Bankline (business banking) user that the club's money was under threat from bank-insider theft and had to be urgently moved into new "safe" accounts.
Across two days the employee authorised transfers totalling £989,000 out of three club accounts into 26 different recipient accounts, using disguised payment references (including player and football-club names) at the fraudsters' instruction. RBS's own fraud team suspended the first two payments (£40,000 and £70,000) as suspicious and called the club twice more to question the activity, but each time the employee, still following the scammers' script, told the bank to proceed, and £655,000 went out in 20 further transactions on the second day alone.
The club later recovered about £170,000 through suspended/clawed-back payments, leaving a net loss of roughly £800,000, which CEO Colin McGowan said wiped out the bulk of the club's financial reserves. In February 2018 Hamilton announced it would sue RBS for 50% of the loss (£400,000-£415,000), arguing the bank's security procedures and duty of care had failed given it had already flagged two of the payments as suspicious; RBS denied any security breakdown, stating all payments were approved by the account's authorised user and that it had appropriately challenged the transactions twice.
Police Scotland's economic crime unit investigated as one of over a dozen similar high-value vishing frauds against Scottish businesses around that time, including a near-identical scam against fellow club Heart of Midlothian; no publicly reported arrests, prosecution, or civil settlement/judgment was found in the sources reviewed.
Over 9-10 October 2017, a fraudster (using the alias "Stuart Davis") phoned Hamilton Academical Football Club claiming to be from RBS's cyber-security/fraud team, using a spoofed or plausible fraud-line-style number, and told the club's finance employee, who was the sole person authorised to operate the club's RBS Bankline (business online banking) accounts, that criminals inside the bank had compromised the club's accounts and that money needed to be moved into new "safe" accounts to protect it from theft.
The caller built a false narrative (including a fabricated large fraudulent payment to a fertiliser company in Spain) and, per STV's reporting of a written case narrative shown to the outlet, referenced having had prior contact with the club and felt confident recognising the CEO's voice, lending the calls credibility. The employee was walked through moving funds via Bankline into a rotating set of 26 recipient accounts, reportedly using disguised references such as player names and football club names to make the transfers look legitimate on statements.
RBS's own cyber-security team flagged and suspended the first two attempted payments (£40,000 and £70,000) as suspicious and contacted the club to question them, but the employee, still under the fraudster's direction, told the bank to proceed. By the end of day one, over £250,000 had moved across six payments; on day two, a further 20 transactions totalling £655,000 went out, again without being challenged, emptying three of the club's accounts of a combined £989,000. The fraudster told the employee he would "complete the clean-up operation" and return the money that evening; no such call came, and the club realised the next day it had been defrauded.
The lure was a fabricated bank-fraud emergency: a caller impersonating RBS's cyber-security/fraud team ("Stuart Davis") claiming the club's accounts had been compromised from inside the bank (citing a bogus large payment to a Spanish fertiliser company as "evidence") and that funds must be urgently moved to new "protected" accounts, with a promise that everything would be reconciled and returned that same evening.
Tells that stood out only in hindsight: a real bank will never ask a customer to move money into different accounts to "protect" it, will never ask that transfers be disguised with unrelated reference names (player/club names), and will not keep pushing a customer to override its own fraud team's suspension of a payment; RBS's cyber-security system did in fact suspend the first two transfers and call to question the pattern twice more, which in retrospect was the clearest signal something was wrong, but the employee, coached by the fraudster throughout, told the bank to continue each time.
Hamilton Academical recovered about £170,000 of the £989,000 taken, via payments RBS was able to suspend/claw back, leaving the club roughly £800,000 out of pocket by the February 2018 reporting (later cited as £830,000 in a March 2018 follow-up), described by CEO Colin McGowan as the bulk of the club's financial reserves. In February 2018 the club's board instructed law firm Levy & McRae to pursue RBS for 50% of the loss (reported as £400,000, and as £415,000 once the loss estimate was revised to £830,000), arguing the bank's security and duty of care had lapsed given that it had already suspended two payments as suspicious yet let hundreds of further transfers proceed unchallenged the next day.
RBS rejected liability, stating all payments were "keyed and approved by the authorised user of the club's account," that it had twice questioned the transactions and been instructed by the club to continue, and that it was working with Police Scotland to identify the perpetrators. As of the most recent dated reporting reviewed (BBC, 6 February 2018), RBS said it had not yet received a formal legal response from the club's lawyers, and no publicly reported settlement, court judgment, arrest, or prosecution outcome was found.
In a March 2018 follow-up, the club's CEO said RBS had also refused his request to set a daily Bankline transfer limit on the club's account, telling the local paper the bank's system does not support customer-set daily limits and calling the bank "morally bankrupt" over the refusal. A near-identical vishing fraud was separately reported against fellow Scottish Premiership club Heart of Midlothian around the same period, and Police Scotland's economic crime unit said it was investigating over a dozen similar high-value frauds against Scottish businesses at the time.
The case is a textbook example of vishing/TOAD (telephone-oriented attack delivery) fraud against a business, and a rare instance where the victim organization publicly disclosed the loss, went on record with exact figures and CEO quotes, and pursued the bank rather than absorbing the loss quietly, surfacing a genuine and still-unresolved industry question about where liability sits when a bank's own fraud system flags a scam but a socially-engineered, authorised employee overrides the warning.
It illustrates that having automated fraud-detection triggers is not sufficient if the escalation path still terminates in "ask the customer, and comply if they say continue": the fraud succeeded specifically at the moments RBS's system worked correctly (flagging the first two payments) because the human control that followed was engineered to fail.
It also shows how a single point of payment authority (one sole signatory) at an organization with meaningful cash reserves is a high-value target, and how fraud crews scale the same script across multiple similar victims (here, two Scottish Premiership football clubs) rather than one-off attacks.
RBS's cyber-security team did flag and initially suspend the first two transactions (£40,000 and £70,000) on day one, and the bank says it called the club twice more during the two-day episode to question the pattern of payments, but each time the employee, still on the phone with (or having just spoken to) the fraudsters, instructed RBS to proceed, and the bank complied rather than escalating to a hard block, a callback-to-a-verified-number check, or a mandatory cooling-off period for a business account being emptied into 26 new payees inside 24 hours.
Case-relevant lessons drawn out in the reporting and by security commentators: (1) never rely on a single authorised signatory for all business banking: dual-authorisation/maker-checker for high-value or unusual transfers would have given a second person the chance to question the calls; (2) treat any inbound call claiming to be "the bank" as unverified by default: hang up and dial the number on the back of the card or a previously-known statement, never a number or "fraud team" the caller supplies; (3) a real bank fraud team will never instruct a customer to move money to a new "safe" account, use disguised reference/payee names (e.g. player or club names), or keep a customer on the phone through repeated large transfers; (4) transaction-monitoring thresholds and velocity checks should trigger hard stops, not just phone challenges, when a business account moves from suspended £40k/£70k payments to 20+ further transfers totalling £655,000 in a single day; (5) staff training specific to vishing/TOAD scripts (urgency, "your money is at risk," fabricated case narratives) for anyone with payment authority.
Social Engineering Examples. “Hamilton Academical FC £989,000 Vishing Fraud (RBS Bank Impersonation)”. Accessed 19 September 2026. https://socialengineeringexamples.com/hamilton-academical-rbs-vishing-fraud-2017
The fraudsters plausibly gathered basic organizational and staff information (e.g., that a former director had left the club, and enough about the CEO's history with a specific bank employee to reference it) before contact, consistent with the caller's ability to name a former director and to lean on an existing relationship between the CEO and a bank employee.
Limiting how much operational detail about staff, roles, and departures is discoverable externally helps only at the margins; the more durable control is training anyone with payment authority that a caller citing accurate internal details is not, by itself, proof of legitimacy.
Per STV's reporting, the fraudster used software to mimic the appearance of RBS's official fraud line, so the calls looked like they were coming from a legitimate bank source before any conversation began.
Caller-ID and source-line spoofing generally cannot be detected by the person receiving the call, so the effective control is procedural: treat every inbound call claiming to be "the bank" as unverified regardless of how it displays, and independently dial a number sourced from a card, statement, or prior correspondence rather than one the caller provides.
Using the alias "Stuart Davis," the caller opened by claiming to be an RBS internal fraud investigator and presented a fabricated case narrative, a bogus large payment to a Spanish fertiliser company, to establish urgency and legitimacy.
Staff training specific to vishing/TOAD scripts, urgent claims of internal bank theft, fabricated case narratives, and unsolicited authority claims, should make an aggressive opening pitch a trigger for suspicion rather than compliance.
The caller instructed the club's sole Bankline-authorised employee not to alert RBS's real relationship team and coached him to give reassuring, evasive answers when the bank's genuine fraud team called to check in, cutting off the normal path to independent verification.
A documented rule that any instruction to "not tell anyone" or bypass a colleague is itself a stop-and-escalate signal would counter this isolation step directly; genuine bank fraud teams do not ask customers to conceal contact from other bank staff.
The scam benefited from a bank employee's own prior contact with the CEO and stated confidence in recognising his voice, an existing-relationship shortcut that added unearned credibility to the fraud.
Voice recognition and relationship familiarity should never substitute for a real authentication mechanism; agreeing on dedicated verification codewords or a mandatory callback procedure for sensitive requests removes the value of this shortcut.
Over two days the caller walked the employee through dozens of Bankline transfers into 26 new recipient accounts, instructing him to disguise payment references with player and club names so the outgoing payments looked routine.
Dual-authorisation or maker-checker requirements for high-value or unusual transfers would have given a second person the chance to question the calls, mirroring the two-signatory rule the club itself already applied to far smaller community-programme spending but not to top-level Bankline transfers.
When RBS's system suspended two early payments (40,000 pounds and 70,000 pounds) and called to question them, the coached employee told the bank to proceed rather than escalating, neutralising the one control that had actually triggered.
When a bank's own system flags and suspends payments, a customer's verbal instruction to continue should trigger a harder control than a phone challenge, such as a mandatory cooling-off period, a callback to a previously verified contact, or a temporary hold, rather than immediate compliance with the same coached employee.
The fraudster moved a combined 989,000 pounds into the 26 accounts, then promised to "complete the clean-up operation" and return the funds that evening, a stalling tactic that delayed discovery until the following day, by which point the funds had already been dispersed.
Velocity- and volume-based transaction-monitoring thresholds, for example automatic holds once a business account sends funds to an unusually large number of new payees or moves an unusually large cumulative sum within 24 hours, would cut off the payout stage before funds reach dozens of recipient accounts and become effectively unrecoverable.
Browse by what this case has in common with others in the library.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
Fraudsters impersonating Leoni AG executives tricked its Romanian subsidiary into wiring roughly EUR 40 million ($44.6M) to attackers.
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…
Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition.
Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona…
A Metropolitan Police officer spotted customers' passports and tax-credit paperwork clearly visible through transparent bin bags left on the street.
JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
DOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used…