Case Library / Vishing (Voice Phishing) / Bank Fraud-Team Impersonation Vishing Drains Scottish Small Businesses: Perth (£31,000, 2019) and Handmade Craft House, Dumfries (£5,000+, 2026)

Bank Fraud-Team Impersonation Vishing Drains Scottish Small Businesses: Perth (£31,000, 2019) and Handmade Craft House, Dumfries (£5,000+, 2026)

Two Scottish small businesses, an unnamed Perth firm in 2019 and Dumfries-based Handmade Craft House in 2026, lost £31,000 and over £5,000 respectively after callers impersonating bank fraud-team staff talked owners into "safeguarding" money by transferring it straight to the scammers.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Two separate but structurally identical bank fraud-team impersonation vishing incidents against small Scottish businesses. In February 2019, an unnamed Perth business received a call from someone claiming to be from Bank of Scotland's "fraud squad" who said the account needed urgent securing due to an allegedly fraudulent pending payment; the business transferred £31,000 to the caller. In January 2026, Mike Dixon of Handmade Craft House in Dumfries received a nearly two-hour call from someone claiming to be his bank's "fraud prevention team," who cited accurate account-balance figures, warned of hacking, pressured Mike to move funds to a "safe" account, and told him not to use his own phone; a second caller then posed as a building society representative to extend the fraud. The family's business and savings accounts were drained, with a net loss of over £5,000 after a partial bank refund.

How the Attack Worked

Two separate, structurally identical vishing incidents against small Scottish businesses, three years apart, both using bank fraud-team impersonation to induce an "urgent protective transfer."

2019, Perth: A caller phoned an unnamed Perth business claiming to be from Bank of Scotland's "fraud squad," stating the account needed to be secured immediately because of an allegedly fraudulent pending payment. Believing the call, the business transferred £31,000 to an account the caller controlled. Police Scotland (PC John Morrison, Preventions and Interventions team) later confirmed the case publicly and noted it followed a separate ~£1,000 fake-invoice fraud against another Perth business weeks earlier, prompting a police warning to local businesses.

2026, Dumfries (Handmade Craft House): Mike Dixon, 66, who runs the handcraft business with his wife Gail, daughter Gemma, son-in-law Tim Riddiford and two grandsons, took a call on a Monday afternoon from a man who introduced himself as being from Mike's "bank fraud prevention team." The caller said the account was being hacked and that funds needed to be "safeguarded," and demonstrated apparent legitimacy by correctly stating how much money was in the account and how much was "at risk." The call lasted roughly one hour 40 minutes, during which the caller pressured Mike to move money into a supposedly safe account, and warned him not to hang up or use his own phone because "hackers" would intercept the line. Once the business account (and some savings) had been drained, a second caller phoned pretending to be from the building society holding a separate savings account, reinforcing the false premise and attempting to extend the fraud to Mike's personal savings. Suspicion only grew when Mike borrowed his son-in-law's phone to call the bank independently and was told he had been speaking to a scammer.

The Lure & the Tell

The lure in both cases was a phone call from someone claiming institutional authority over the victim's own money: "fraud squad"/"fraud prevention team" staff calling to protect the account from an active or imminent theft. The 2026 caller heightened credibility by reciting specific, accurate account-balance figures and by sustaining a calm, "professional... as though he was a banker" tone for nearly two hours, per victim Tim Riddiford's account: "The people that do things are very good at mind games and using suggestive wording. It's like sleight of hand, very measured conversation. They suggest things and then bring it back around to you." The tell that should have broken the spell in both cases was the same one banks and police publish: a genuine bank or building society will never ask a customer to move money into a different "safe" account, and will never instruct a customer not to hang up or not to use their own phone. In the 2026 case, the arrival of a second impersonator (posing as the building society) to extend the fraud to a separate savings account was itself a signal of a coordinated multi-caller scam operation rather than a single rogue employee.

Outcome

2019 Perth case: £31,000 was stolen and, per the available Daily Record report, was not recovered; Police Scotland opened an investigation and publicly appealed to any other victims of similar scams to come forward. No arrest or prosecution has been reported. 2026 Handmade Craft House case: the family's business and personal/savings accounts were drained; the bank later returned some of the money but the family was left with a net loss of "over £5,000," which the bank told them was not its responsibility to cover. The family publicly appealed for help via a GoFundMe and BuyMeACoffee page, describing the theft as wiping out their Christmas-season revenue right at the start of the year's quietest trading period, and said it forced them to cancel planned expansions (craft courses, new product lines) because they could no longer afford related insurance and costs.

Why It Matters

These two cases, three years apart but structurally identical, show that classic bank-impersonation vishing remains effective against small, resource-constrained businesses that lack dedicated finance/security staff and cannot easily absorb a five-figure loss. The 2026 case is notable because the caller demonstrated accurate knowledge of the victim's account balance, which is a credibility signal that pushes past the "would my bank really know this / call like this" skepticism that basic security awareness training relies on; combined with a near-two-hour call designed to prevent independent verification, and a second impersonator call to extend the fraud into a separate account, it illustrates a coordinated, multi-step operation rather than a single opportunistic call. Both banks involved ultimately treated most or all of the loss as the customer's responsibility (no recovery reported in 2019; partial-only refund in 2026), underscoring that authorised push payment fraud largely falls outside standard fraud-reimbursement protections when the customer was the one who initiated the transfer, however convincingly they were manipulated into doing so.

Defenses

Both banks' own published guidance (Bank of Scotland) and Police Scotland state the core defense clearly: a genuine bank will never call and ask a customer to move money to a "safe account," and any call urging an urgent transfer should be treated as suspect regardless of how much the caller already knows about the account. Recommended controls, drawn directly from the police and bank statements in the sources: (1) hang up and call the bank back using a number from a card, statement, or the official website, never a number given by the caller, or dial 159 (UK bank-verification hotline) or 101 (non-emergency police); (2) use a different phone line/device to call back, since scammers can stay on an open landline line pretending the call has ended; (3) treat "don't hang up, hackers are listening" or "don't use your phone" instructions as a scam script, not a security measure; (4) verify unexpected invoices/payment-detail emails by phone via a known number before paying, since related email-invoice fraud (Perth, ~£1,000) hit the same town weeks before the £31k case; (5) businesses should have a second-person sign-off requirement for any "urgent" fund transfer request received by phone; (6) report suspected scam calls to Action Fraud/Police Scotland (101) even if no money was lost, to help build pattern intelligence, since police in the 2019 case explicitly asked prior victims to come forward.

Sources
  • Perth business is left counting the cost after £31k fraud. Daily Record Secondary. 2019-02-15 report naming the Bank of Scotland 'fraud squad' impersonation and £31,000 loss; quotes Police Scotland PC John Morrison. Fetched and confirmed content matches.
  • Family business savings wiped out by heartless fraudsters in 'terrifying' scam. Daily Record Secondary. 2026-01-30 report naming Mike Dixon and Handmade Craft House, Dumfries; details the ~1hr40min call and >£5,000 loss. Fetched and confirmed content matches.
  • Scammers cleaned out our account - it felt personal. The Herald Secondary. 2026-02-08 follow-up with son-in-law Tim Riddiford's detailed account, confirms partial bank refund leaving ~£5,000 net loss, and UK Finance APP-fraud statistics. Fetched and confirmed content matches.
  • Please help us recover from heartbreaking theft. Handmade Craft House Primary. Victim's own 2026-01-28 first-party account of the theft and fundraising appeal. Fetched and confirmed content matches (GoFundMe/BuyMeACoffee mentions, cancelled course/product plans).
  • Scam calls | Fraud | Bank of Scotland Business. Bank of Scotland Primary. Official bank guidance confirming it will never ask customers to move money to another account and warning of caller-ID spoofing, used to source the defenses section. URL corrected from bare path (which returns a Cloudflare error page on direct fetch) to the working query-parameterized variant; content verified by fetch.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and targeting: Neither source details exactly how the callers picked these two small businesses or learned account specifics in advance, but the 2026 case shows the caller correctly stating the victim's account balance and how much was "at risk" before Mike Dixon confirmed anything, consistent with fraudsters typically working from previously breached, purchased, or leaked banking, invoice, or personal data (a common feeder for bank-impersonation scams) rather than a cold, uninformed guess.
Countering Stage 1: Whatever data source fed the caller's advance knowledge of account details is outside the victim's visibility or control at the point of the call, so the realistic control sits downstream: businesses should assume a caller may already know real account figures and should never treat that knowledge alone as proof of legitimacy.
2
Number spoofing and pretext setup: Bank and police guidance cited in this case (Bank of Scotland, Police Scotland) both warn that fraudsters can spoof caller ID to display a genuine-looking bank number, and typically rehearse a calm, "banker-like" script and cover story (a named "fraud squad" or "fraud prevention team") before placing the call, so the victim's caller-ID display and the caller's tone both read as legitimate from the first second.
Countering Stage 2: Caller-ID spoofing cannot be reliably detected by the person receiving the call, per Bank of Scotland's own guidance, so the defense is procedural rather than technical, always verify by calling back on an independently sourced number, never one supplied by or displayed during the suspicious call.
3
Initial contact and false-urgency framing: The caller phones the business claiming to be bank fraud-prevention staff, asserts the account is being hacked or a fraudulent payment is pending, and frames the call as protective, an urgent, one-time chance to "safeguard" the money before it is stolen.
Countering Stage 3: Treat any unsolicited call urging an urgent account-protective transfer as suspect by default, regardless of who the caller claims to be. Both Bank of Scotland and Police Scotland guidance state a genuine bank will never ask a customer to move money to another account.
4
Credibility-building via real account detail: The caller cites accurate, specific details, such as the exact balance and the amount supposedly "at risk", to defeat the victim's instinct to question whether a real bank employee would call this way.
Countering Stage 4: Train staff and business owners that a caller knowing your balance or transaction detail is not evidence of legitimacy, since that data can be obtained elsewhere; verification must always happen through an independently dialed callback, not by assessing how much the caller seems to know.
5
Isolation and anti-verification pressure: The caller sustains a long call (roughly one hour 40 minutes in the 2026 case), instructs the victim not to hang up and not to use their own phone because "hackers" will intercept it, and uses measured, suggestive language to prevent the victim from pausing to call the bank back independently.
Countering Stage 5: Recognize "don't hang up" and "don't use your own phone" as scam-script red flags rather than security instructions, since a genuine bank will never object to a customer's hanging up to verify. Using a second phone or device to call the bank back, as Mike Dixon eventually did, is the single action that exposed both cases.
6
Inducing the fraudulent transfer: Believing the funds are being moved to a bank-controlled "safe account," the victim transfers business (and in the 2026 case, personal savings) funds directly into an account the caller controls.
Countering Stage 6: A mandatory second-person sign-off for any "urgent" phone-instructed fund transfer, especially to a newly specified account, gives a business one more chance to catch the fraud before money actually moves.
7
Extension and follow-on targeting: In the 2026 case, a second caller poses as a representative of a separate building society holding the victim's personal savings, reusing the same pretext to try to extend the theft into a second account, a coordinated multi-caller pattern rather than a single opportunistic call.
Countering Stage 7: Because the second call reuses the same pretext, the same don't-trust-unsolicited-callers and independent-callback rules from Stage 3 and Stage 5 apply again; treating a second "institution" call arriving on the heels of the first as equally suspect, rather than as independent corroboration, would have stopped the extension into the personal savings account.
8
Cash-out and objective completion: The stolen funds are moved out of the victim's reach; per the Herald's reporting on the 2026 case, some of the money was traced to spending at a retailer in London, far from the Dumfries victim, consistent with fraudsters quickly moving and spending stolen funds through intermediary accounts and cards before a bank or victim can claw them back.
Countering Stage 8: Once funds are transferred to a scammer-controlled account and spent, recovery is largely outside the victim's control and depends on the receiving bank and the victim's own bank's fraud response. This case shows both banks treated the loss as largely the customer's responsibility, which is why prevention at Stages 3 through 6 is the only reliable control; reporting to Action Fraud/Police Scotland and the bank immediately at minimum preserves a chance at partial recovery, as happened in the 2026 case.
Quick Facts
Victim
An unnamed small business in Perth, Scotland (2019); Handmade Craft House, a family-run handcraft/woodware business in Dumfries, Scotland, owned and operated by Mike Dixon with wife Gail, daughter Gemma, son-in-law Tim Riddiford, and grandsons Joe and Ben (2026)
Location
Perth, Scotland, UK (2019 incident); Dumfries, Scotland, UK (2026 incident, Handmade Craft House)
Date
2019-02 (Perth case, reported 2019-02-15); 2026-01-26 (Handmade Craft House call, "Monday afternoon"), company statement 2026-01-28, Daily Record report 2026-01-30, Herald follow-up 2026-02-08
Impact
2019 Perth case: £31,000 stolen; no recovery reported in available coverage. 2026 Handmade Craft House case: total drained from business and personal/savings accounts, with "some money" later returned by the bank, leaving a net loss of "over £5,000" that the bank told the family was "not its responsibility." Both are UK-Finance-category authorised push payment (APP) fraud; bank-and-police impersonation accounted for 11% of APP scam losses (£27.1m) in the UK in H1 of the prior year, per UK Finance figures cited in the Herald's coverage of the 2026 case.
Status
Confirmed
Case Type
Real-World Incident
Sector
Retail & E-commerce
Related

Related Cases

UK Energy Firm AI Voice-Clone CEO Fraud (Euler Hermes Case)

The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…

Incident 2019Read →

New Jersey Life-Insurance-Beneficiary Pretexting of Elderly Widows/Widowers

An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their…

Incident 2020Read →

Hamilton Academical FC £989,000 Vishing Fraud (RBS Bank Impersonation)

Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's sole authorised banking employee into moving nearly £1 million into…

Incident 2017Read →