Social engineering fraud works by manipulating people into doing something they would not normally do — sending money, revealing credentials, approving access or trusting a false identity. The attack may use email, telephone, text, social media, video, messaging apps or a compromised genuine account. The technical sophistication varies; the psychological pressure is usually the constant.

At Trojan Investigations, we assist organisations through business investigations where fraud, impersonation or internal compromise needs to be reconstructed. Our focus is evidence: what contact occurred, which identity was used, what changed, who authorised the action and what can be preserved for recovery, reporting or legal proceedings.

Originally published: 13th August 2026  |  Updated: 7th September 2026

What should you do immediately after a social-engineering fraud?

If money has been sent, contact the bank or payment provider immediately. Preserve the original emails, messages, telephone numbers, payment details and timeline. Reset compromised credentials through a trusted device, contain affected accounts, report the incident through the appropriate police/fraud channel and avoid continuing contact with the fraudster.

Fraud Remains a Major UK Crime Problem

4.5 millionEstimated fraud incidents in England and Wales in the Crime Survey year ending March 2026.
7.8%Estimated proportion of adults who were victims of fraud in the previous 12 months.
3.8 millionEstimated fraud victims, up from 3.4 million the previous year.

Those ONS figures cover fraud against individuals and households, not every business fraud, but they show the scale of the environment in which social-engineering attacks operate. Separate government fraud strategy material also describes millions of incidents against businesses with employees.

Why Social Engineering Works

Fraudsters often combine four pressures: authority, urgency, familiarity and fear. A message appears to come from a director, bank, solicitor, supplier, police officer or colleague. It demands quick action, refers to information the recipient recognises and discourages independent verification.

The attacker may have researched the target using public information. The National Cyber Security Centre warns small organisations to think carefully about what staff and supplier information they publish online because unnecessary detail can help criminals craft convincing messages.

The Main Forms of Social Engineering

Common social-engineering attack types
MethodTypical tacticKey verification step
PhishingMass or targeted email encourages a click, login or paymentOpen the service independently rather than through the message link
Spear phishingHighly tailored email using information about a specific person or companyVerify the sender through a known contact route
VishingTelephone caller impersonates a bank, authority or trusted professionalEnd the call and ring back using an independently sourced number
SmishingText message creates urgency around delivery, banking or account securityDo not use the message link; use the official app or website
Business email compromiseCompromised or impersonated executive/supplier requests paymentUse dual approval and independent confirmation
QR phishingQR code redirects the victim to a fraudulent login or payment pageTreat unexpected QR codes like unknown links
AI-enabled impersonationGenerated voice, image or text increases credibilityVerify through a pre-agreed channel or known contact detail

Business Email Compromise Is Often a Process Failure

In a BEC case, the attacker does not always need to hack the finance system. If a convincing message persuades an employee to change supplier bank details or make an urgent transfer, the fraud can succeed through normal business processes.

That is why prevention should be designed around the decision, not just the inbox. Payment-detail changes, exceptional transfers and new beneficiaries should require independent verification and, for higher-risk payments, a second authorised person.

Supplier Impersonation Exploits Familiarity

A criminal may monitor an existing supplier relationship, compromise one mailbox or create a near-identical domain. The request may refer to real invoices, genuine staff names and correct contract details. The presence of accurate information does not prove the request is genuine.

Never verify a payment change using only the contact details in the change request

Use a telephone number, supplier portal or other contact route already held independently by the organisation. If the message itself provides the new number and the new bank details, both may belong to the fraudster.

AI Makes Impersonation More Convincing, Not Automatically More Powerful

Generated voice, images and text can make scams more believable and faster to produce. City of London Police reported in September 2026 that fraud reports identifying AI as a factor rose sharply in 2025/26. The practical response is the same: do not rely on a voice, image, caller ID or writing style as the sole proof of identity.

Pre-agreed verification methods — a known number, separate channel, challenge phrase or second approver — are more robust than trying to guess whether media is “real”.

Public Information Helps Criminals Build Credibility

Company websites and LinkedIn profiles often reveal who controls budgets, who is on leave, which suppliers are used and how senior staff communicate. The NCSC's 2026 guidance for small organisations advises reviewing what public information is genuinely necessary because staff biographies and supplier details can be useful to attackers.

This does not mean organisations should disappear from the internet. It means publishing deliberately and avoiding operational detail that creates unnecessary fraud risk.

How to Preserve Evidence After a Scam

Preserve before deleting or forwarding extensively:

  • The original email in its native form where possible, including headers.
  • Text messages, chat logs and screenshots showing the full context.
  • Telephone numbers, call times, voicemails and caller details.
  • Fraudulent domains, profile URLs and account names.
  • Bank details, sort codes, beneficiary names and transaction references.
  • Internal approval records showing who saw and authorised the request.
  • Any credential-reset, login or security alerts connected to the incident.

A forwarded screenshot may be useful for awareness, but it can strip technical information. If the case is serious, preserve the original material before users start editing, deleting or replying to it.

Contact the Bank Quickly If Money Has Been Sent

Speed can matter. The bank or payment provider may be able to intervene, flag the receiving account or begin recovery procedures. Do not delay bank contact while waiting for a private investigation to start.

The investigation can then reconstruct how the request reached the organisation, whether an account was compromised, what controls were bypassed and whether the recipient account or identities connect to other evidence.

Report Fraud Is the National Reporting Service

Report Fraud replaced Action Fraud as the national fraud and cyber-crime reporting service for England, Wales and Northern Ireland from December 2025. Victims can report fraud through the service, while people in Scotland should use Police Scotland routes.

What a Social-Engineering Investigation Tries to Establish

1. The initial contact

Which account, number or identity approached the victim, and through which channel?

2. The credibility mechanism

What genuine information did the fraudster know, and how may it have been obtained?

3. The decision point

Which employee, customer or victim took the action, and what verification controls were available?

4. The destination

Where did money, credentials, documents or data go, and what identifiers are lawfully available?

5. The compromise question

Was a genuine account breached, or was the attack purely impersonation? IT or forensic specialists may be needed to answer this.

6. The prevention gap

Which control would have stopped or slowed the attack, and what should change now?

Private Investigators Cannot “Trace Any IP Address” on Demand

Clients often expect a fraud investigator to obtain the subscriber behind an email or social account immediately. Internet service providers and platforms hold protected customer information and do not simply disclose it to a private investigator. Lawful technical data can be analysed when it is available, but subscriber disclosure usually requires the provider's legal process or law-enforcement powers.

Our work therefore focuses on evidence that can be obtained lawfully: public identities, domains, corporate links, transaction information provided by the client, witness accounts and other relevant open-source material.

Prevention Should Focus on Verification and Least Privilege

High-value controls include:

  • Independent verification of supplier payment changes.
  • Multi-factor authentication on email and finance systems.
  • Separate approval for higher-risk or unusual payments.
  • Role-based access to sensitive data and payment functions.
  • Regular staff exercises using realistic fraud scenarios.
  • Simple internal reporting routes for suspicious messages.
  • Review of public information that exposes unnecessary operational detail.
  • Incident plans that tell staff whom to contact before panic takes over.

Security Controls and Investigation Should Work Together

Where social engineering exposes a wider security weakness, our security services can sit alongside the factual investigation. The objective is not simply to identify how one scam happened, but to reduce the chance that the same method works again.

If legal proceedings or recovery action are contemplated, our legal and litigation support can be coordinated with solicitors so the evidential chronology and reporting structure meet the next stage of the case.

Do Not Blame the Victim

Modern social-engineering attacks are designed to defeat normal human judgement under pressure. A useful post-incident review should ask which systems and controls allowed one mistaken decision to create a major loss. Shame makes staff hide near misses; good reporting culture makes future attacks easier to stop.

Was the Account Compromised or Merely Impersonated?

This distinction can change the entire response. A lookalike domain or spoofed caller may mean the genuine supplier or executive account was never breached. By contrast, messages sent from a real mailbox, unexpected forwarding rules or unfamiliar login alerts may indicate account compromise and require urgent IT containment.

The investigation should not guess which scenario occurred. Email headers, security logs, domain-registration details, mailbox rules and the timing of password changes can help technical teams determine the route of compromise. A private investigator can then connect the technical findings to the people, companies and transactions involved.

Interview Staff While Memory Is Fresh

Where an employee spoke to the fraudster, approved a payment or received a suspicious call, record their account early and neutrally. Ask what they saw, what they were told, which checks they performed and why the request appeared genuine at the time. Avoid leading questions designed to make the person admit fault.

Near misses are useful too. If another employee received a similar message and recognised it as suspicious, that may reveal the attack pattern, additional numbers or domains and the point at which the fraudster changed tactics.

Review the Whole Control Chain

Social engineering succeeds when several controls fail together. The message reaches the right person, the request looks plausible, verification is weak, the user has enough access to act, and there is no effective secondary approval. Reviewing only the employee who clicked or paid misses the systemic cause.

A post-incident review should therefore test identity verification, permissions, payment approval, supplier-master changes, MFA, staff escalation, logging and management response. The goal is to make the same story fail next time even if a future message is more convincing.

Near Misses Are Valuable Evidence Too

They also provide an opportunity to test controls before a real financial loss occurs.

An organisation should record suspicious messages that did not result in loss. Repeated near misses can expose the same domain, telephone number, payment instruction, executive identity or supplier theme before a successful attack occurs. They can also show which teams are being targeted and which controls are working.

Centralising those reports makes pattern recognition easier. If one employee receives a fake supplier-bank-change email and another receives a matching telephone call, the combined picture may reveal a coordinated campaign rather than two unrelated events.

Recovery and Investigation Run on Different Timelines

Financial recovery steps should begin immediately, while the investigation may take longer. Banks, insurers, cyber responders, police, solicitors and private investigators can all have different roles. Waiting for one workstream to finish before starting the others can reduce options.

A sensible incident lead keeps a single chronology showing who was contacted, what was preserved, which accounts were secured, when the bank was notified and what external reports were made. That record becomes useful evidence in its own right.

The best defence is a verified process, not perfect intuition

Staff do not need to identify every sophisticated fake. They need a process that makes unusual requests slow down, move to a trusted channel and receive independent approval before money, credentials or sensitive information leave the organisation.

Need help reconstructing a fraud or impersonation incident?

We can help preserve the chronology, investigate lawful public connections and coordinate evidence with your advisers. Book a confidential consultation.

Sources and References

  • Office for National Statistics — Crime in England and Wales: year ending March 2026, released 23 July 2026.
  • City of London Police — Report Fraud Annual Assessment announcement, published 4 September 2026.
  • GOV.UK / Serious Fraud Office — Report Fraud: new national service replacing Action Fraud from December 2025.
  • National Cyber Security Centre — Small organisations guide to cyber security: spotting cyber attacks, published April 2026 and reviewed July 2026.
  • GOV.UK — Fraud Strategy 2026 to 2029.
  • Fraud Act 2006.
  • Computer Misuse Act 1990.
  • UK GDPR and Data Protection Act 2018.

Frequently Asked Questions About Social Engineering & Fraud Explained

Practical answers about phishing, vishing, smishing, business email compromise, supplier impersonation, AI-enabled scams, payment fraud, evidence preservation, Report Fraud and prevention controls.


It is fraud that uses manipulation or impersonation to persuade a person to reveal information, approve access or send money. The attack targets human decision-making rather than relying only on a technical exploit.

Phishing usually uses email to trick recipients into clicking a link, opening a malicious attachment, entering credentials or making a payment. Spear phishing is a more targeted version aimed at a specific person or organisation.

Vishing is voice phishing. The fraudster phones the victim while impersonating a bank, authority, colleague, supplier or other trusted person and pressures them to disclose information or act.

Smishing is social engineering by SMS or text message. It often uses delivery, banking, tax or account-security themes to create urgency.

BEC is a fraud in which a genuine or impersonated business email identity is used to cause an unauthorised payment, bank-detail change or disclosure of valuable information.

Yes. Generated voice, image and text can make impersonation more convincing. Organisations should verify identity through an independent channel rather than relying on voice or appearance alone.

Contact your bank or payment provider immediately, preserve the evidence, secure any compromised accounts and report the fraud through the appropriate national reporting channel. Do not wait for a private investigation before contacting the bank.

Keep the original email where possible, including headers, links, sender details and attachments. Also preserve internal approval records, payment details and any related login or security alerts.

Report Fraud is the national fraud and cyber-crime reporting service for England, Wales and Northern Ireland. It replaced Action Fraud from December 2025.

No. Subscriber information held by internet providers or platforms is protected and is not generally disclosed to private investigators simply on request.

Use a known contact route already held independently by the organisation and confirm the change with an authorised person. Do not rely on the telephone number or email contained only in the change request.

No. Caller information can be spoofed or manipulated. End the call and use an independently sourced official number if the request is sensitive or unusual.

No single control stops every attack, but independent payment verification, dual approval, MFA and clear escalation for unusual requests are especially valuable.

A fair review should consider training, the sophistication of the attack, available controls and whether the process made one human mistake catastrophic. Blame-first cultures can discourage future reporting.

It is useful where the organisation needs a structured chronology, public-source research, relationship or identity enquiries, witness evidence or support for civil, employment or legal decisions beyond the immediate technical response.



Five-Star Rated Private Investigator

With a wealth of five-star reviews, Trojan Investigations is a highly rated, professional, and trustworthy private investigation service expertly led by Anthony Butlin, whose 25 years of covert policing experience ensures every case is handled with precision, discretion, and unparalleled expertise.