Why financial data in email is a serious risk
Email is not a secure channel. Messages can be intercepted, accounts can be compromised, and attackers can impersonate trusted senders to trick finance teams into making fraudulent payments or disclosing sensitive account details.
How attackers target your finances
Financial fraud via email comes in several forms. Knowing what to look for makes it significantly easier to spot before any damage is done.
CEO / Director fraud (mandate fraud)
An attacker impersonates a senior member of staff — often a director or CEO — and urgently requests a payment to a new account or asks for bank details. The email looks legitimate and may even come from a compromised company account.
Invoice fraud (payment redirect)
A fraudster intercepts or spoofs a supplier email and sends a fake invoice — or a message claiming the supplier's bank details have changed. Payments then go directly to the attacker's account instead of the real supplier.
Payroll / HR diversion
An attacker poses as an employee (or uses a compromised account) to request a change to payroll bank details shortly before payday. Salary is then paid to a fraudulent account.
Supplier impersonation
Fraudsters create email addresses very similar to a known supplier (e.g. changing one letter) and send routine-looking messages requesting financial information or confirming updated payment details.
What a financial fraud email looks like
These emails are often well-written, appear to come from a trusted sender, and create a sense of urgency. Here is a typical example.
Hi,
I'm tied up in back-to-back meetings today and need you to arrange an urgent payment to a new supplier. It's time-sensitive — can you transfer £8,500 to the following account before close of business?
Account name: ACE Supplies Ltd
Sort code: 20-45-12
Account number: 73849201
Please confirm by reply once done. Don't call me as I'm in meetings all day. Thanks.
Always verify before you act
The most effective defence against financial fraud is a simple one: before transferring any money or sharing any financial details in response to an email, always verify the request through a separate, trusted channel.
Call back using a number you already have — not one in the email
If you receive a request to make a payment or change bank details, phone the person or company using a number from your contacts, a previous invoice, or your company directory. Never use a number provided in the suspicious email itself — it may connect you directly to the fraudster.
What to do if you receive a suspicious financial email
Follow these steps if you receive an unexpected request involving bank details, payments, or financial information.
Do not reply, pay, or share any details
Stop immediately. Do not respond to the email, click any links, or provide any financial information. Even acknowledging the email can encourage further attempts.
Contact your finance team or manager directly
Speak to your finance team, line manager, or the person the email claims to be from — using a known, trusted contact method. Do not reply to the email to check if it is genuine.
Report it to your IT team immediately
Forward the email to your IT support team so they can investigate whether an account has been compromised and alert others in the organisation if necessary.
If a payment has already been made — act fast
Contact your bank immediately to request a recall. Report it to Action Fraud (0300 123 2040 or actionfraud.police.uk). Speed is critical — the sooner you act, the greater the chance of recovery.
Contact The Cloud Network if your IT systems may be involved
If you suspect an email account has been compromised or you need help securing your systems, call us on 0345 450 9666 and we will assist immediately.
Dos and don'ts for financial emails
These apply to everyone who handles payments, invoices, or financial information.
- Verify any new or changed bank details by phone before making payment
- Use a two-person authorisation process for large or unusual payments
- Check the sender's full email address carefully before trusting a message
- Report suspicious emails to IT and your manager immediately
- Keep a record of all payment requests and approvals
- Send bank details, card numbers, or financial credentials via email
- Act on urgent payment requests without independent verification
- Use a callback number provided in the suspicious email itself
- Assume an email is safe because it appears to come from a director or colleague
- Let urgency or pressure override your verification process
