Posing as NatWest bank security, vishing criminals convinced Surrey solicitor Karen Mackie to wire £734,000 of client money to fraudulent accounts.
Social Engineering Examples·5 sources
In late April 2015, Karen Mackie, a sole-practitioner solicitor in Surrey (firm registered in Alton, Hampshire), received a phone call from a woman identifying herself as "Joanne Howard from NatWest," who claimed one of Mackie's accounts had been compromised and told her to call the number on the back of her debit card to verify. Mackie hung up and immediately redialed on her landline, but due to the several-second "line-clearing" delay inherent to UK landlines at the time, her callback reconnected to the same criminals rather than to NatWest's genuine security line.
Believing she was now speaking to legitimate bank security, she was told her funds were at risk and that the "bank" would call back the next day to move her money into "safe" accounts. When that call came, a frightened Mackie transferred £734,000 of client money into new, criminal-controlled accounts in tranches of up to £99,000. She grew suspicious shortly afterward, alerted police and NatWest, and the bank recovered nearly £222,000; the remaining roughly £512,000 had already been withdrawn.
The case was first reported publicly by BBC News and BBC Radio 4's Money Box on 2-3 October 2015, in the same week Financial Fraud Action UK (FFA UK) published figures showing UK financial fraud losses up 6% to £325.3 million in H1 2015, with telephone-banking fraud specifically up 95% to £14.4 million, a surge FFA UK attributed to this same impersonation/"safe account" tactic.
The Solicitors Regulation Authority intervened, suspending Mackie's practising certificate for failing to safeguard client funds (a core professional obligation) even though she had believed she was protecting them; her professional indemnity insurer refused to pay her claim; and she was subsequently declared bankrupt, facing loss of her home. Her clients were made whole through the Solicitors Compensation Scheme rather than any documented reimbursement from NatWest to Mackie herself.
The scheme relied on a well-known but under-publicized telecom quirk: when a landline call ends, the exchange does not disconnect the line instantly: there is a several-second "line-clearing" delay before a new outbound call is actually routed. If a victim hangs up and immediately redials, the call can still connect to whoever they were just speaking with, not to the new number dialed.
The fraud crew exploited this directly: after the initial "your account is compromised, call the number on your card" call, they simply stayed on the line, and Mackie's immediate callback reconnected her to them rather than to NatWest's genuine security line. Believing she was now genuinely speaking to bank security (on what she thought was a freshly-dialed, independently-verified number), she was told her funds were at risk and that "the bank" would call again the next day to move the money into "safe" accounts.
When that follow-up call came, she transferred the full £734,000 in multiple tranches capped at £99,000 each, a structuring pattern consistent with staying under commonly-referenced reporting/scrutiny thresholds and spreading the movement across several new destination accounts to speed extraction of the funds before discovery.
The lure had two stages. Stage one: a caller identifying herself as "Joanne Howard from NatWest" told Mackie one of her accounts had been compromised and instructed her to call the number on the back of her own debit card, advice that sounds exactly like standard, trustworthy anti-fraud guidance ("verify by calling the number on your card," not a number the caller gives you).
Stage two exploited that trust: because Mackie redialed immediately on the same landline, the call reconnected to the criminals rather than to NatWest, so when "the bank" called back the next day to walk her through moving money into "safe" accounts, she believed she was dealing with a verified, independently-reached NatWest line rather than the same fraud crew.
The tell, in hindsight, was that no genuine bank ever asks a customer to move money into a new "safe" account to protect it from fraud: that instruction is itself the fraud; and immediate redialing on a landline was not the safe verification step it appeared to be.
Mackie became suspicious after the transfers and alerted police and NatWest, which recovered nearly £222,000 of the £734,000; the rest had already been withdrawn. The Solicitors Regulation Authority suspended her practising certificate over the failure to safeguard client money, one of the profession's core rules, even though she believed she was protecting the funds.
Her professional indemnity insurer refused to pay out, arguing she had effectively "condoned dishonesty activities" by others and posed a public risk. She was declared bankrupt, faced losing her home, and told BBC Money Box she was in counselling and on medication for anxiety and depression. Her clients' losses were covered through the Solicitors Compensation Scheme, triggered by the SRA action.
SRA public records show that years later (2023 and 2024) her practising certificate was still subject to conditions barring her from holding client money, acting as a signatory on client/office accounts, or acting as a manager/owner of an authorised firm, indicating she returned to restricted practice but never regained full authority over client funds.
No named individuals behind the fraud were reported identified or prosecuted in available sources.
The case is a textbook illustration of how vishing attacks can weaponize the very security advice victims are taught to trust: "hang up and call the number on the back of your card" is standard, sound guidance, but it silently failed here because of an obscure telecom infrastructure quirk (landline call-clearing delay) that most consumers, and even professionals handling large sums of client money, had no reason to know about.
It shows that even a compliance-conscious solicitor, precisely by following what she believed was correct verification procedure, could be defrauded of nearly three-quarters of a million pounds in a single day. It also demonstrates the asymmetric fallout of vishing: the criminals were never identified or prosecuted in public reporting, NatWest recovered only part of the funds and reimbursed no one directly, the clients were ultimately protected only because a third-party compensation scheme existed, and the professional who was deceived bore the full personal cost: career-ending suspension, bankruptcy, and the threatened loss of her home, despite having no fraudulent intent.
The case also had a measurable industry impact: it was cited in contemporaneous reporting on BT's decision to cut landline call-clearing delay to two seconds, and it fed into the SRA's and FFA UK's public warnings about solicitor practices being deliberately targeted (three to four firms per week in 2015) because they routinely hold large, liquid client funds for time-pressured transactions like property purchases.
Never call back a "bank security" number given during the same call, and never dial back immediately on the same landline: UK landlines of the era had a multi-second "line-clearing" delay after a caller hung up, during which a callback could be silently intercepted by the original caller; BT subsequently announced it would cut this clearing delay to two seconds specifically in response to this fraud pattern.
Best practice: hang up, wait at least a couple of minutes (or use a different phone/mobile line entirely), and dial a number sourced independently (e.g., from a card, statement, or the bank's official website) rather than one given verbally by the caller. For firms holding client money (law firms, conveyancers, accountants), require dual authorization/maker-checker controls and a mandatory cooling-off period for any "urgent" transfer to a new or previously-unused "safe" account, and train staff that legitimate banks never ask customers to move money to a different account to "protect" it.
The Solicitors Regulation Authority (SRA) began actively warning firms in 2015 after finding three to four solicitor practices were being targeted by these calls every week, and industry body FFA UK (now UK Finance) tracked the broader telephone-banking fraud surge (95% YoY increase in H1 2015) driven by this same impersonation/"safe account" tactic.
Social Engineering Examples. “NatWest "Vishing" Callback Fraud Costs Surrey Solicitor Karen Mackie £734,000 and Her Career”. Accessed 19 September 2026. https://socialengineeringexamples.com/karen-mackie-solicitor-vishing-fraud-2015
Attackers likely identified Karen Mackie Solicitor as a small conveyancing and family-law practice holding a NatWest client account, consistent with the SRA's account of a broader wave of criminal gangs deliberately targeting solicitor firms, three to four practices per week in 2015, known to hold large, liquid client balances for property and other transactions; this kind of firm-level targeting is typically enabled by public solicitor directories, conveyancing-chain visibility, and routine company or regulatory filings that make it easy to identify which small firms handle high-value client money.
Public visibility of which solicitor firms hold client money is difficult to eliminate given regulatory registration requirements; the realistic control sits downstream, in how firms and banks handle unsolicited "your account is compromised" contact, rather than in hiding firm identity.
The crew prepared a caller persona, a woman identifying herself as "Joanne Howard from NatWest," posing as bank fraud and security staff, and built the scam around a known landline telecom quirk rather than any purchased spoofing tool, a low-tech method that required no caller-ID manipulation.
Because this pretext relied on a telecom timing gap rather than exotic spoofing technology, the most direct structural fix is telecom-side: shortening or eliminating the landline call-clearing delay, which BT did in fact announce it would cut to two seconds in response to this exact fraud pattern.
The caller told Mackie one of her accounts had been compromised and instructed her to hang up and call the number on the back of her own debit card, mimicking legitimate bank anti-fraud advice almost exactly.
Train account holders and staff that a genuine bank does not call to say an account is compromised and then supply its own callback instructions; treat any such inbound call as unverified no matter how official the caller sounds or how standard the advice seems.
The crew stayed on the line through the multi-second "line-clearing" delay inherent to UK landlines of the era, so Mackie's immediate redial reconnected to them instead of NatWest, letting them pose as verified bank security on what she believed was an independently dialed line.
Never redial on the same line a suspicious call just came in on; wait several minutes or use a separate phone, and dial a number sourced independently from a card, statement, or the bank's official website rather than one given verbally by the caller.
Posing as confirmed NatWest security, the criminals told Mackie her funds were at risk and said "the bank" would call again the next day to move her money into "safe" accounts, building urgency while giving the crew time to prepare destination accounts.
Treat "we'll call you back to help move your money to a safe account" as a defining signature of this scam category; legitimate banks never ask a customer to relocate funds to protect them from fraud.
On the follow-up call, the crew directed Mackie to move client funds into new accounts they controlled, framed as protective action rather than a transfer to attacker-owned accounts.
Firms holding client money should require dual authorization or maker-checker sign-off, plus a mandatory cooling-off period, before any transfer to a new or previously unused destination account, particularly when the request is framed as urgent.
Mackie wired £734,000 in structured tranches capped at £99,000 each; the criminals withdrew roughly £512,000 before the fraud was discovered and reported, completing the theft.
Bank-side controls such as value and velocity thresholds and real-time monitoring on high-value transfers to newly added payees can flag or delay structured transfers, for example several transfers just under £99,000 to new accounts in quick succession, long enough to enable recovery before funds are withdrawn, consistent with NatWest's partial recovery of roughly £222,000 in this case.
Browse by what this case has in common with others in the library.
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team.
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012.
A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
A Singaporean finance professional in her 50s lost S$1.2 million.