Posing as NatWest bank security, vishing criminals exploited a landline callback delay to convince Surrey solicitor Karen Mackie to wire £734,000 of client money to "safe" accounts, costing her nearly £512,000 unrecovered, her legal career, and ultimately her home and solvency.
Reviewed by the Social Engineering Examples team.
In late April 2015, Karen Mackie, a sole-practitioner solicitor in Surrey (firm registered in Alton, Hampshire), received a phone call from a woman identifying herself as "Joanne Howard from NatWest," who claimed one of Mackie's accounts had been compromised and told her to call the number on the back of her debit card to verify. Mackie hung up and immediately redialed on her landline, but due to the several-second "line-clearing" delay inherent to UK landlines at the time, her callback reconnected to the same criminals rather than to NatWest's genuine security line. Believing she was now speaking to legitimate bank security, she was told her funds were at risk and that the "bank" would call back the next day to move her money into "safe" accounts. When that call came, a frightened Mackie transferred £734,000 of client money into new, criminal-controlled accounts in tranches of up to £99,000. She grew suspicious shortly afterward, alerted police and NatWest, and the bank recovered nearly £222,000; the remaining roughly £512,000 had already been withdrawn. The case was first reported publicly by BBC News and BBC Radio 4's Money Box on 2-3 October 2015, in the same week Financial Fraud Action UK (FFA UK) published figures showing UK financial fraud losses up 6% to £325.3 million in H1 2015, with telephone-banking fraud specifically up 95% to £14.4 million, a surge FFA UK attributed to this same impersonation/"safe account" tactic. The Solicitors Regulation Authority intervened, suspending Mackie's practising certificate for failing to safeguard client funds (a core professional obligation) even though she had believed she was protecting them; her professional indemnity insurer refused to pay her claim; and she was subsequently declared bankrupt, facing loss of her home. Her clients were made whole through the Solicitors Compensation Scheme rather than any documented reimbursement from NatWest to Mackie herself.
The scheme relied on a well-known but under-publicized telecom quirk: when a landline call ends, the exchange does not disconnect the line instantly: there is a several-second "line-clearing" delay before a new outbound call is actually routed. If a victim hangs up and immediately redials, the call can still connect to whoever they were just speaking with, not to the new number dialed. The fraud crew exploited this directly: after the initial "your account is compromised, call the number on your card" call, they simply stayed on the line, and Mackie's immediate callback reconnected her to them rather than to NatWest's genuine security line. Believing she was now genuinely speaking to bank security (on what she thought was a freshly-dialed, independently-verified number), she was told her funds were at risk and that "the bank" would call again the next day to move the money into "safe" accounts. When that follow-up call came, she transferred the full £734,000 in multiple tranches capped at £99,000 each, a structuring pattern consistent with staying under commonly-referenced reporting/scrutiny thresholds and spreading the movement across several new destination accounts to speed extraction of the funds before discovery.
The lure had two stages. Stage one: a caller identifying herself as "Joanne Howard from NatWest" told Mackie one of her accounts had been compromised and instructed her to call the number on the back of her own debit card, advice that sounds exactly like standard, trustworthy anti-fraud guidance ("verify by calling the number on your card," not a number the caller gives you). Stage two exploited that trust: because Mackie redialed immediately on the same landline, the call reconnected to the criminals rather than to NatWest, so when "the bank" called back the next day to walk her through moving money into "safe" accounts, she believed she was dealing with a verified, independently-reached NatWest line rather than the same fraud crew. The tell, in hindsight, was that no genuine bank ever asks a customer to move money into a new "safe" account to protect it from fraud: that instruction is itself the fraud; and immediate redialing on a landline was not the safe verification step it appeared to be.
Mackie became suspicious after the transfers and alerted police and NatWest, which recovered nearly £222,000 of the £734,000; the rest had already been withdrawn. The Solicitors Regulation Authority suspended her practising certificate over the failure to safeguard client money, one of the profession's core rules, even though she believed she was protecting the funds. Her professional indemnity insurer refused to pay out, arguing she had effectively "condoned dishonesty activities" by others and posed a public risk. She was declared bankrupt, faced losing her home, and told BBC Money Box she was in counselling and on medication for anxiety and depression. Her clients' losses were covered through the Solicitors Compensation Scheme, triggered by the SRA action. SRA public records show that years later (2023 and 2024) her practising certificate was still subject to conditions barring her from holding client money, acting as a signatory on client/office accounts, or acting as a manager/owner of an authorised firm, indicating she returned to restricted practice but never regained full authority over client funds. No named individuals behind the fraud were reported identified or prosecuted in available sources.
The case is a textbook illustration of how vishing attacks can weaponize the very security advice victims are taught to trust: "hang up and call the number on the back of your card" is standard, sound guidance, but it silently failed here because of an obscure telecom infrastructure quirk (landline call-clearing delay) that most consumers, and even professionals handling large sums of client money, had no reason to know about. It shows that even a compliance-conscious solicitor, precisely by following what she believed was correct verification procedure, could be defrauded of nearly three-quarters of a million pounds in a single day. It also demonstrates the asymmetric fallout of vishing: the criminals were never identified or prosecuted in public reporting, NatWest recovered only part of the funds and reimbursed no one directly, the clients were ultimately protected only because a third-party compensation scheme existed, and the professional who was deceived bore the full personal cost: career-ending suspension, bankruptcy, and the threatened loss of her home, despite having no fraudulent intent. The case also had a measurable industry impact: it was cited in contemporaneous reporting on BT's decision to cut landline call-clearing delay to two seconds, and it fed into the SRA's and FFA UK's public warnings about solicitor practices being deliberately targeted (three to four firms per week in 2015) because they routinely hold large, liquid client funds for time-pressured transactions like property purchases.
Never call back a "bank security" number given during the same call, and never dial back immediately on the same landline: UK landlines of the era had a multi-second "line-clearing" delay after a caller hung up, during which a callback could be silently intercepted by the original caller; BT subsequently announced it would cut this clearing delay to two seconds specifically in response to this fraud pattern. Best practice: hang up, wait at least a couple of minutes (or use a different phone/mobile line entirely), and dial a number sourced independently (e.g., from a card, statement, or the bank's official website) rather than one given verbally by the caller. For firms holding client money (law firms, conveyancers, accountants), require dual authorization/maker-checker controls and a mandatory cooling-off period for any "urgent" transfer to a new or previously-unused "safe" account, and train staff that legitimate banks never ask customers to move money to a different account to "protect" it. The Solicitors Regulation Authority (SRA) began actively warning firms in 2015 after finding three to four solicitor practices were being targeted by these calls every week, and industry body FFA UK (now UK Finance) tracked the broader telephone-banking fraud surge (95% YoY increase in H1 2015) driven by this same impersonation/"safe account" tactic.
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii…
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support…