Impersonation scams are often presented as isolated incidents in which a criminal pretends to be a bank employee, police officer or government official. In practice, impersonation is better understood as a reusable fraud technique—one that can be inserted into account takeover, authorised push payment fraud, investment fraud, invoice diversion, remote-access scams and money-mule operations.
The criminal’s objective is to borrow the authority, familiarity or emotional significance of another identity. That identity may belong to a financial institution, regulator, utility provider, senior executive, supplier, family member or public figure. Once the victim accepts the false identity, normal fraud controls can be reframed as obstacles: a bank warning becomes evidence that the “investigation” is active, a payment delay becomes a threat to the supposed emergency, and independent verification is presented as a breach of confidentiality.
The latest UK Finance figures show that £55.5 million was lost during 2025 to scams involving the impersonation of police officers or bank staff. A further £36.9 million was lost to other organisational impersonation schemes. Together, these categories generated more than £92 million in losses across approximately 24,450 confirmed cases. Both categories declined compared with 2024, but they remain a material component of the wider authorised push payment fraud landscape.
For a FinCrime audience, the key issue is not simply that customers continue to believe convincing callers. It is that impersonation fraud now combines social engineering with compromised personal data, spoofed communications, cloned websites, remote-access tools, artificial intelligence and rapid laundering through recipient-account networks.
Key Takeaways
- Impersonation Scams Exploit Trust in Recognised Institutions
- Fraudsters Frequently Pose as Banks, Government Officials and Law Enforcement
- Phone Calls, Emails and Text Messages Remain Core Attack Channels
- Social Engineering Is Central to Successful Impersonation Fraud
- Urgency and Fear Are Common Manipulation Techniques
- Victims May Be Persuaded to Transfer Money Voluntarily
- Impersonation Fraud Can Generate Significant Individual Losses
- Fraudulent Communications Can Also Harvest Sensitive Personal Information
- Verification of the Supposed Caller or Organisation Is a Critical Defensive Step
- Customer Awareness Remains an Important Layer of Fraud Prevention
- Online Platforms Can Facilitate the Distribution of Fraudulent Content
- Effective Prevention Requires Cooperation Between Banks, Platforms and Law Enforcement
- Authentication Alone Does Not Establish Genuine Customer Intent
- Impersonation Fraud Should Be Viewed as a Full Customer-Journey Risk
Listen the podcast
Watch the video
Why impersonation remains effective
Financial services depend on trusted identities. Customers are expected to recognise their bank, respond to security warnings, follow instructions from public authorities and act quickly where fraud may be occurring.
Criminals exploit those same expectations.
A fraudster claiming to be from a bank does not need to create trust from nothing. The institution’s reputation, branding and existing customer relationship provide the initial credibility. The criminal then reinforces it with personal information obtained from social media, data breaches, previous phishing attempts or commercially available datasets.
The target may be addressed by name and told about their bank, telephone provider, approximate account balance or recent purchase. None of these details proves that the caller is genuine, but their combined effect can make the story feel independently verified.
Urgency completes the manipulation. The victim is told that money is being stolen, an account will be frozen, tax is overdue, a family member is in danger or a confidential investigation will fail unless instructions are followed immediately.
The fraud succeeds by restricting the victim’s decision-making environment. There is no time to consult another person, verify the claim or reconsider the payment.
The bank and police impersonation model
Bank and police impersonation scams commonly begin with a call or text stating that suspicious activity has been detected. The victim may be told that an employee at their local branch is involved, that their account has been compromised or that they must assist an undercover investigation.
The criminal then instructs the victim to move funds to a supposedly safe account. No bank or police force creates protected accounts for customers through an unsolicited telephone call.
In some cases, the victim is directed to withdraw cash, purchase gold or transfer funds through several accounts. The criminal may remain on the telephone throughout the process and coach the victim on what to say if bank staff ask questions.
This coaching is important. Criminals know that institutions use payment warnings, branch interventions and enhanced questioning. They prepare victims to describe the transaction as a property purchase, family loan or personal investment and may claim that bank employees cannot be trusted.
The customer may therefore appear calm, provide a credible explanation and insist that the payment proceed. Authentication and customer confirmation do not necessarily demonstrate genuine informed intent when the explanation itself has been supplied by the fraudster.
UK Finance recorded 6,016 confirmed police and bank impersonation cases in 2025, involving 19,196 payments and £55.5 million in losses. Although losses fell by 18% and cases by 23% from the previous year, the average impact remained substantial. Approximately 80% of recorded losses were ultimately returned to victims.
Government, regulator and service-provider impersonation
The second major category involves criminals claiming to represent government departments, regulators, utility providers, communications companies or technology-support services.
The story may concern unpaid tax, an outstanding fine, an erroneous refund, a compromised internet connection or money supposedly recovered from an earlier scam. The victim is directed to pay a fee, provide credentials or grant remote access to their computer.
FCA impersonation offers a particularly effective form of false authority because the regulator is associated with consumer protection and financial redress. During the first half of 2025, the FCA received 4,465 reports concerning criminals pretending to represent the organisation. In 480 cases, victims were persuaded to send money, and almost two-thirds of reports came from people aged 56 or above. A common narrative claimed that the FCA had recovered assets from a cryptocurrency wallet opened illegally in the victim’s name.
Recovery scams frequently follow an earlier loss. The fraudster claims to be a regulator, lawyer, law-enforcement official or asset-recovery specialist with access to the stolen money. An advance fee is required for tax, insurance, legal costs or identity verification.
The detailed knowledge used in the second approach may come from the original criminal group or from victim information sold within fraud networks. A person who has already lost money can therefore become more valuable to criminals rather than less.
From first contact to controlled payment
A successful impersonation scam is rarely one conversation. It is a managed customer journey.
The initial contact identifies whether the recipient is responsive. A second actor may then appear as a supervisor, fraud investigator or police officer, creating the impression that several independent organisations have confirmed the same story.
Victims may be transferred between fake departments, given reference numbers and instructed to keep the matter confidential. Criminals reproduce the language of legitimate customer service and investigation processes because procedural detail creates credibility.
The payment method is then selected according to speed, value and reversibility. Bank transfers allow large amounts to move quickly. Cash and precious metals can be collected by couriers. Gift cards provide transferable codes. Cryptoassets can be transmitted across borders and layered through multiple wallets.
The impersonated identity may change during the operation, but the underlying control remains constant: the fraudster determines who the victim trusts, what information they receive and how they respond to warnings.
Spoofing, cloned interfaces and remote access
Caller identification and message appearance are weak forms of authentication. Criminals can manipulate caller IDs so that calls appear to come from a UK number, financial institution, public authority or known contact. Ofcom describes this practice as number spoofing and has continued strengthening requirements intended to identify and block fraudulent calls and messaging activity.
Text messages may appear in an existing banking thread. Emails can use domains differing from the genuine address by one character. Cloned websites can reproduce logos, security language and online-banking interfaces.
The presence of correct branding, a padlock symbol or an apparently familiar number does not verify the sender’s identity.
Remote-access software creates a further layer of risk. A supposed technology or bank employee asks the victim to install an application so that a security problem can be fixed. Once access is granted, the criminal can observe account information, manipulate what appears on screen and guide the victim through payments.
The victim may see a fabricated refund, duplicate transaction or negative account balance and believe that transferring money is necessary to correct an error.
AI changes scale and credibility
Artificial intelligence does not replace traditional social engineering; it improves its speed, personalisation and consistency.
Criminals can use generative systems to produce well-written messages, translate scripts, create convincing profiles and maintain simultaneous conversations with large numbers of targets. Voice-cloning tools can imitate relatives, executives and public figures using relatively short audio samples.
Deepfake video and audio can support investment scams, family-emergency fraud and executive impersonation. A finance employee may receive a voice message appearing to come from a senior manager, while a consumer may encounter a fabricated endorsement from a recognised public figure.
The practical risk is not that every synthetic voice or image will be indistinguishable under forensic examination. The content only needs to be credible during a short, high-pressure interaction.
Visual and audio familiarity can no longer be treated as proof of identity. Sensitive instructions must be confirmed through an independently established channel.
Business impersonation and payment diversion
Impersonation also creates material corporate exposure. Fraudsters may pretend to be a chief executive, supplier, lawyer or employee and request an urgent payment or change to bank details.
UK Finance recorded £5.6 million in CEO-fraud losses during 2025. Although this represented a significant decline from the previous year, CEO fraud retained the highest average loss per confirmed case among the main APP scam categories, at more than £28,000.
Business-email compromise may involve a genuine mailbox rather than an obviously fake message. Criminals can monitor correspondence, understand invoicing cycles and intervene when a high-value payment is expected.
An instruction to change supplier details may therefore appear inside a legitimate email chain and include accurate project or invoice information.
Controls must focus on the requested action, not only the apparent sender. Changes to payment details, urgent transfers and exceptions to normal approval processes should be verified through a known contact using a separate communication channel.
The recipient account is part of the scam
Impersonation creates the payment, but money-mule infrastructure converts the deception into usable proceeds.
Receiving accounts may belong to recruited individuals, compromised businesses, synthetic identities or companies established specifically to receive fraud proceeds. Funds can be divided, transferred onward, withdrawn as cash or converted into cryptoassets within minutes.
The victim’s bank sees the behavioural departure and the payment instruction. The receiving institution may see the broader pattern: multiple transfers from unrelated customers, rapid pass-through activity, shared devices or linked beneficiaries.
This makes recipient-side monitoring central to impersonation-scam prevention. Stopping one customer from paying is valuable. Identifying the mule network can prevent losses across multiple institutions.
What a resilient personal control stack looks like
Independent verification is the strongest consumer control. Anyone receiving an unexpected request for money, credentials or remote access should end the interaction and reconnect through a known channel.
The number printed on a bank card, the institution’s official application or a previously verified contact should be used. The telephone number, link or email address supplied by the caller cannot be treated as independent evidence.
One-time codes and banking approvals should be read carefully. The customer should confirm that the merchant, recipient, amount and action correspond exactly to something they initiated. A code should never be disclosed to an unsolicited caller.
No legitimate bank, regulator, police officer or technology company should ask a customer to transfer money to protect it, conceal the transaction from bank staff or hand cash and valuables to a courier.
Suspicious emails can be forwarded to the NCSC’s reporting service, texts can be sent to 7726, and suspected scam websites can be submitted for investigation and potential removal. Anyone who has transferred funds or disclosed credentials should contact their bank immediately and report the incident to the appropriate fraud-reporting authority.
What financial institutions need to detect
Effective controls must combine customer, device, communication and payment signals.
A transaction may require intervention where it follows an unexpected device registration, password reset, telephone-number change, new payee creation or unusual login location. Repeated payments to a new recipient, sudden liquidation of savings and activity inconsistent with the customer’s established profile should increase concern.
Customer interaction is itself a source of fraud intelligence. Warning signs include scripted explanations, reluctance to answer privately, insistence that the matter is confidential or evidence that another person is directing the customer in real time.
Payment warnings should be specific to the detected risk. Generic statements are easily ignored. A targeted prompt asking whether a caller instructed the customer to move money to a safe account is more likely to interrupt the scam narrative.
Institutions also need rapid escalation between fraud operations, AML teams, call centres, branch staff, cybersecurity functions and recipient-bank investigators. Impersonation fraud crosses organisational boundaries, and controls operating in isolation will see only part of the attack.
Reimbursement is protection, not prevention
The UK’s mandatory APP-scam reimbursement requirements came into effect on 7 October 2024 for eligible Faster Payments and CHAPS transactions. In-scope consumers are generally entitled to reimbursement up to £85,000, with most claims expected to be resolved within five business days unless additional investigation is required.
These protections reduce the financial harm suffered by many victims, but reimbursement does not disrupt the criminal network. If the proceeds have already moved through mule accounts, the fraud economy may still retain the money.
The regime therefore strengthens the case for prevention at both ends of the payment. Sending institutions must recognise manipulated customers, while receiving institutions must prevent their accounts from being used as fraud infrastructure.

What this means for financial crime leaders
Impersonation scams succeed because criminals understand how trust is created inside financial and institutional relationships. They reproduce the language of security, enforcement, customer service and authority, then use that borrowed credibility to control the victim’s decisions.
The most effective response is not another generic reminder to remain vigilant. It is a control environment capable of identifying when identity, communication, authentication and payment behaviour no longer align.
For FinCrime leaders, impersonation should be treated as a cross-channel operating model rather than a narrow APP-fraud category. It connects phishing, account takeover, data compromise, remote access, AI-generated content and money laundering through mule accounts.
The institutions best positioned to reduce losses will combine behavioural intelligence, device and identity signals, targeted customer interventions, recipient-network analytics and rapid cross-sector information sharing.
The objective is not only to determine whether a payment was technically authorised. It is to establish whether the customer understood the transaction, acted independently and intended to pay the actual recipient.
Impersonation fraud turns legitimate trust into a criminal control mechanism. Defeating it requires financial institutions to recognise the manufactured identity before it becomes an authorised payment—and to disrupt the account network before the proceeds disappear.
What Financial Institutions Should Consider
- Strengthen Impersonation Scam Detection
- Apply Behavioural Analytics to Unusual Payment Activity
- Monitor New Beneficiaries and Sudden High-Value Transfers
- Detect Payments Following Unusual Authentication Events
- Apply Risk-Based Payment Interventions
- Incorporate Customer Vulnerability Into Fraud Decisioning
- Strengthen Bank Impersonation Warning Messages
- Detect Rapid Changes in Customer Payment Behaviour
- Monitor Receiving Accounts Linked to Multiple Scam Victims
- Strengthen Money Mule Detection
- Connect Device, Authentication and Transaction Intelligence
- Capture Scam Origination Channels During Investigations
- Feed Confirmed Impersonation Typologies Back Into Detection Models
- Improve Rapid Payment Recall and Account Freezing Processes
- Strengthen Fraud Intelligence Sharing Across Institutions
- Coordinate Fraud, AML, Cyber and Customer-Support Teams
- Work With Telecommunications and Digital Platforms on Scam Disruption
- Measure Prevention Across the Entire Scam Journey




Impersonation fraud succeeds because criminals exploit the trust associated with banks, regulators, police forces, employers and family members. By combining stolen personal information with spoofed calls, cloned websites, remote-access tools and AI-generated content, they can create highly convincing scenarios that push victims into acting before they verify what is happening.
For customers and businesses, the strongest defence is independent confirmation. Unexpected payment requests, changes to bank details, security alerts and demands for confidentiality should always be checked through a known and trusted communication channel. A familiar voice, telephone number or email thread should no longer be treated as sufficient proof of identity.
Financial institutions must also look beyond whether a payment was technically authorised. Effective controls should assess device changes, behavioural anomalies, customer interactions, recipient-account activity and signs that the payer is being coached or manipulated.
Ultimately, reducing impersonation fraud requires coordinated prevention across banks, payment providers, telecommunications companies, online platforms and law enforcement. The objective is to identify the manufactured identity, interrupt the manipulated payment and dismantle the mule-account infrastructure before the proceeds disappear.