Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 17 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Payment diversion fraud poses significant threat to businesses

New figures find one in four UK businesses were hit by payment diversion fraud last year

by The Gurus
September 7, 2023
in Featured
Fraud and online banking
Share on FacebookShare on Twitter

Nearly a quarter (24%) of businesses across the UK experienced payment diversion fraud in 2022 according to data from the Hiscox Cyber Readiness Report*.

Payment diversion fraud (PDF) involves cyber criminals posing as a trusted supplier and manipulating individuals within the business to make a false bank transfer or other payment. In 2022, the average cost of a claim for customers requiring help (following an attempted or successful PDF attack) was £15,484**. These claims tended to be more prevalent in May and November, as businesses either prepared for a busy summer or festive season.

A total of 982 UK businesses were surveyed for the report, which found that for this type of fraud, company size is not a discriminating factor. Criminals are more interested in businesses suffering from weakened IT systems or otherwise rely on human error, with the latter being the most common reason for a business falling victim to this type of scam.

Alana Muir, Head of Cyber – Hiscox UK, said: “Payment diversion fraud is the gift that keeps on giving for cyber criminals and can pose a significant threat to any business. Most attacks happen because businesses fail to carry out basic checks before making a payment – it’s human error and often avoidable. Attacks of this nature could leave businesses significantly out of pocket or even worse, bankrupt.”

Steps to take to prevent PDF

  • Make a test payment to the payee and check they receive the money before transferring a large sum.
  • Take time to check a change of bank details notification – it may not be genuine. Contact the payee on the number you know is correct to confirm their details have changed.
  • Carry out regular training to remind employees what to look out for when making payments, and the steps they should take to ensure due diligence.
  • Change passwords on a regular basis and make them complicated so that they are not easily identifiable. Use Multi Factor Authentication to help accounts, such as email, from being compromised.
  • Adopt a four eyes approach – dual signatories for payments over a certain amount.
  • Carry out regular checks on IT equipment to ensure there are no weaknesses in the systems.
  • If you are in doubt about the transaction, don’t hand over the money.
  • If you realise it is a scam, contact your bank immediately.

In 2017, Hiscox introduced the CyberClear Academy which has trained almost 36,000 individuals from 7,000 organisations. Training helps identify specific knowledge gaps in their systems that could lead to a cyber attack and is carried out through a mix of videos and interactive materials.

 

* The Hiscox Cyber Readiness Report 2023 was compiled in collaboration with Forrester Consulting. It is based on a survey of 5,005 executives, departmental heads, IT managers and other key professionals, from across the USA, UK, Germany, France, Spain, Netherlands, Belgium and Ireland. Drawn from a representative sample of organisations by size and sector, these are the people on the front line of the business battle against cyber crime. Respondents completed the online survey between 9th January 2023 and 2nd February 2023. The full Hiscox Cyber Readiness Report 2023 will be available from September.

** Based on Hiscox UK claims data for 2022.

ShareTweet
Previous Post

More than half of UK organisations know they aren’t well protected against cyber threats

Next Post

KnowBe4 Opens New Office to Bolster UK’s Northern Powerhouse

Recent News

Proton removes the last barrier to leaving Google Workspace

Proton removes the last barrier to leaving Google Workspace

June 17, 2026
partnership

Check Point and Illumio Deepen Alliance to Counter AI-Powered Cyberattacks

June 17, 2026
Staying Safe After a Cyber Attack

AI-Powered Attacks Become Top Concern for Security Professionals

June 17, 2026
KnowBe4 Appoints Alex Callihan as Chief Technology Officer

KnowBe4 Appoints Alex Callihan as Chief Technology Officer

June 16, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol