The client who sends the money to the wrong account
A client is releasing tax-free cash, or funding an ISA, or settling an adviser charge. They get an email that reads exactly like the last dozen — your signature, your turn of phrase, the right reference — telling them the account details have changed. They send it. Nobody notices for a fortnight.
You are not a bank and you may never touch client money at all, which is precisely why this is dangerous: the money moves on your say-so without passing through anything you control. When it goes wrong the client does not say “I was defrauded”, they say “my adviser told me to send it there” — and that is a complaint, a Financial Ombudsman file and a PI notification, whether or not your systems were ever breached. Frequently they were not. The attacker is often sitting in the client’s own webmail reading a thread you are only one participant in. The FCA’s own consumer warnings are dominated by exactly this pattern: cloned firms and impersonated advisers using details that check out against the Register.
of UK businesses experienced phishing in the last twelve months — the most common form of attack by a wide margin, and the delivery mechanism for almost every case of this kind
DSIT — Cyber Security Breaches Survey 2025/26 (43% of businesses identified a breach or attack; phishing 38%, impersonation 12%)- Multi-factor authentication on every mailbox, with legacy authentication switched off so it cannot simply be walked around
- Alerting on new mailbox forwarding and inbox rules — the first thing an intruder sets up, and the thing that keeps them invisible
- SPF, DKIM and DMARC set to reject, so that somebody else cannot send email as your domain
- External-sender warnings, and impersonation protection tuned to your own advisers’ names
- A written rule, told to clients at the outset, that payment details are confirmed by phone on a number you already held — and that they will never change by email