Two Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.
Social Engineering Examples·5 sources
Two separate but structurally identical bank fraud-team impersonation vishing incidents against small Scottish businesses. In February 2019, an unnamed Perth business received a call from someone claiming to be from Bank of Scotland's "fraud squad" who said the account needed urgent securing due to an allegedly fraudulent pending payment; the business transferred £31,000 to the caller.
In January 2026, Mike Dixon of Handmade Craft House in Dumfries received a nearly two-hour call from someone claiming to be his bank's "fraud prevention team," who cited accurate account-balance figures, warned of hacking, pressured Mike to move funds to a "safe" account, and told him not to use his own phone; a second caller then posed as a building society representative to extend the fraud.
The family's business and savings accounts were drained, with a net loss of over £5,000 after a partial bank refund.
Two separate, structurally identical vishing incidents against small Scottish businesses, three years apart, both using bank fraud-team impersonation to induce an "urgent protective transfer."
2019, Perth: A caller phoned an unnamed Perth business claiming to be from Bank of Scotland's "fraud squad," stating the account needed to be secured immediately because of an allegedly fraudulent pending payment. Believing the call, the business transferred £31,000 to an account the caller controlled. Police Scotland (PC John Morrison, Preventions and Interventions team) later confirmed the case publicly and noted it followed a separate ~£1,000 fake-invoice fraud against another Perth business weeks earlier, prompting a police warning to local businesses.
2026, Dumfries (Handmade Craft House): Mike Dixon, 66, who runs the handcraft business with his wife Gail, daughter Gemma, son-in-law Tim Riddiford and two grandsons, took a call on a Monday afternoon from a man who introduced himself as being from Mike's "bank fraud prevention team." The caller said the account was being hacked and that funds needed to be "safeguarded," and demonstrated apparent legitimacy by correctly stating how much money was in the account and how much was "at risk." The call lasted roughly one hour 40 minutes, during which the caller pressured Mike to move money into a supposedly safe account, and warned him not to hang up or use his own phone because "hackers" would intercept the line.
Once the business account (and some savings) had been drained, a second caller phoned pretending to be from the building society holding a separate savings account, reinforcing the false premise and attempting to extend the fraud to Mike's personal savings. Suspicion only grew when Mike borrowed his son-in-law's phone to call the bank independently and was told he had been speaking to a scammer.
The lure in both cases was a phone call from someone claiming institutional authority over the victim's own money: "fraud squad"/"fraud prevention team" staff calling to protect the account from an active or imminent theft. The 2026 caller heightened credibility by reciting specific, accurate account-balance figures and by sustaining a calm, "professional... as though he was a banker" tone for nearly two hours, per victim Tim Riddiford's account: "The people that do things are very good at mind games and using suggestive wording.
It's like sleight of hand, very measured conversation. They suggest things and then bring it back around to you." The tell that should have broken the spell in both cases was the same one banks and police publish: a genuine bank or building society will never ask a customer to move money into a different "safe" account, and will never instruct a customer not to hang up or not to use their own phone.
In the 2026 case, the arrival of a second impersonator (posing as the building society) to extend the fraud to a separate savings account was itself a signal of a coordinated multi-caller scam operation rather than a single rogue employee.
2019 Perth case: £31,000 was stolen and, per the available Daily Record report, was not recovered; Police Scotland opened an investigation and publicly appealed to any other victims of similar scams to come forward. No arrest or prosecution has been reported. 2026 Handmade Craft House case: the family's business and personal/savings accounts were drained; the bank later returned some of the money but the family was left with a net loss of "over £5,000," which the bank told them was not its responsibility to cover.
The family publicly appealed for help via a GoFundMe and BuyMeACoffee page, describing the theft as wiping out their Christmas-season revenue right at the start of the year's quietest trading period, and said it forced them to cancel planned expansions (craft courses, new product lines) because they could no longer afford related insurance and costs.
These two cases, three years apart but structurally identical, show that classic bank-impersonation vishing remains effective against small, resource-constrained businesses that lack dedicated finance/security staff and cannot easily absorb a five-figure loss. The 2026 case is notable because the caller demonstrated accurate knowledge of the victim's account balance, which is a credibility signal that pushes past the "would my bank really know this / call like this" skepticism that basic security awareness training relies on; combined with a near-two-hour call designed to prevent independent verification, and a second impersonator call to extend the fraud into a separate account, it illustrates a coordinated, multi-step operation rather than a single opportunistic call.
Both banks involved ultimately treated most or all of the loss as the customer's responsibility (no recovery reported in 2019; partial-only refund in 2026), underscoring that authorised push payment fraud largely falls outside standard fraud-reimbursement protections when the customer was the one who initiated the transfer, however convincingly they were manipulated into doing so.
Both banks' own published guidance (Bank of Scotland) and Police Scotland state the core defense clearly: a genuine bank will never call and ask a customer to move money to a "safe account," and any call urging an urgent transfer should be treated as suspect regardless of how much the caller already knows about the account. Recommended controls, drawn directly from the police and bank statements in the sources: (1) hang up and call the bank back using a number from a card, statement, or the official website, never a number given by the caller, or dial 159 (UK bank-verification hotline) or 101 (non-emergency police); (2) use a different phone line/device to call back, since scammers can stay on an open landline line pretending the call has ended; (3) treat "don't hang up, hackers are listening" or "don't use your phone" instructions as a scam script, not a security measure; (4) verify unexpected invoices/payment-detail emails by phone via a known number before paying, since related email-invoice fraud (Perth, ~£1,000) hit the same town weeks before the £31k case; (5) businesses should have a second-person sign-off requirement for any "urgent" fund transfer request received by phone; (6) report suspected scam calls to Action Fraud/Police Scotland (101) even if no money was lost, to help build pattern intelligence, since police in the 2019 case explicitly asked prior victims to come forward.
Social Engineering Examples. “Bank Fraud-Team Impersonation Vishing Drains Scottish Small Businesses: Perth (£31,000, 2019) and Handmade Craft House, Dumfries (£5,000+, 2026)”. Accessed 19 September 2026. https://socialengineeringexamples.com/scottish-small-business-bank-fraud-vishing-2019-2026
Neither source details exactly how the callers picked these two small businesses or learned account specifics in advance, but the 2026 case shows the caller correctly stating the victim's account balance and how much was "at risk" before Mike Dixon confirmed anything, consistent with fraudsters typically working from previously breached, purchased, or leaked banking, invoice, or personal data (a common feeder for bank-impersonation scams) rather than a cold, uninformed guess.
Whatever data source fed the caller's advance knowledge of account details is outside the victim's visibility or control at the point of the call, so the realistic control sits downstream: businesses should assume a caller may already know real account figures and should never treat that knowledge alone as proof of legitimacy.
Bank and police guidance cited in this case (Bank of Scotland, Police Scotland) both warn that fraudsters can spoof caller ID to display a genuine-looking bank number, and typically rehearse a calm, "banker-like" script and cover story (a named "fraud squad" or "fraud prevention team") before placing the call, so the victim's caller-ID display and the caller's tone both read as legitimate from the first second.
Caller-ID spoofing cannot be reliably detected by the person receiving the call, per Bank of Scotland's own guidance, so the defense is procedural rather than technical, always verify by calling back on an independently sourced number, never one supplied by or displayed during the suspicious call.
The caller phones the business claiming to be bank fraud-prevention staff, asserts the account is being hacked or a fraudulent payment is pending, and frames the call as protective, an urgent, one-time chance to "safeguard" the money before it is stolen.
Treat any unsolicited call urging an urgent account-protective transfer as suspect by default, regardless of who the caller claims to be. Both Bank of Scotland and Police Scotland guidance state a genuine bank will never ask a customer to move money to another account.
The caller cites accurate, specific details, such as the exact balance and the amount supposedly "at risk", to defeat the victim's instinct to question whether a real bank employee would call this way.
Train staff and business owners that a caller knowing your balance or transaction detail is not evidence of legitimacy, since that data can be obtained elsewhere; verification must always happen through an independently dialed callback, not by assessing how much the caller seems to know.
The caller sustains a long call (roughly one hour 40 minutes in the 2026 case), instructs the victim not to hang up and not to use their own phone because "hackers" will intercept it, and uses measured, suggestive language to prevent the victim from pausing to call the bank back independently.
Recognize "don't hang up" and "don't use your own phone" as scam-script red flags rather than security instructions, since a genuine bank will never object to a customer's hanging up to verify. Using a second phone or device to call the bank back, as Mike Dixon eventually did, is the single action that exposed both cases.
Believing the funds are being moved to a bank-controlled "safe account," the victim transfers business (and in the 2026 case, personal savings) funds directly into an account the caller controls.
A mandatory second-person sign-off for any "urgent" phone-instructed fund transfer, especially to a newly specified account, gives a business one more chance to catch the fraud before money actually moves.
In the 2026 case, a second caller poses as a representative of a separate building society holding the victim's personal savings, reusing the same pretext to try to extend the theft into a second account, a coordinated multi-caller pattern rather than a single opportunistic call.
Because the second call reuses the same pretext, the same don't-trust-unsolicited-callers and independent-callback rules from Stage 3 and Stage 5 apply again; treating a second "institution" call arriving on the heels of the first as equally suspect, rather than as independent corroboration, would have stopped the extension into the personal savings account.
The stolen funds are moved out of the victim's reach; per the Herald's reporting on the 2026 case, some of the money was traced to spending at a retailer in London, far from the Dumfries victim, consistent with fraudsters quickly moving and spending stolen funds through intermediary accounts and cards before a bank or victim can claw them back.
Once funds are transferred to a scammer-controlled account and spent, recovery is largely outside the victim's control and depends on the receiving bank and the victim's own bank's fraud response. This case shows both banks treated the loss as largely the customer's responsibility, which is why prevention at Stages 3 through 6 is the only reliable control; reporting to Action Fraud/Police Scotland and the bank immediately at minimum preserves a chance at partial recovery, as happened in the 2026 case.
Browse by what this case has in common with others in the library.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO.
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
A low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.