Fraud is now over 40% of Suffolk’s crime. Awareness isn’t fixing it.

Suffolk has just launched a county-wide partnership against fraud, because the threat keeps growing despite years of warnings. More awareness, more victims?

On 17 June, Suffolk Constabulary and Suffolk Trading Standards launched Suffolk Against Fraud, a new partnership bringing police, businesses, charities and community groups together to tackle what has become the county’s largest crime. Fraud now accounts for over 40 per cent of all recorded offences in Suffolk, according to the constabulary.1 That figure alone should reframe how every business owner thinks about risk: the most likely crime to cost you money this year is not a break-in or a theft from the till, but an email.

What is spectacular is that this is happening after the most sustained fraud-awareness effort this country has ever mounted. Every business owner could probably recite the advice ‘stop and think, verify bank details, beware of urgency’. The Take Five campaign, the bank alerts, the insurer briefings have made it close to ambient noise.

And still the national numbers climb. UK Finance’s latest annual figures show criminals stole £1.28 billion through payment fraud in 2025, up 4 per cent on the year, across more than four million cases.2 Awareness has gone up. So have the losses. The obvious question is why.

Awareness is not the missing piece

The assumption behind most campaigns is that fraud succeeds because people don’t know about it. Tell them it exists, and they’ll stop falling for it. But knowing that invoice fraud exists does almost nothing to help you spot the specific, plausible email in your inbox on a busy Tuesday, from a supplier you really do pay, about an invoice that really is outstanding, noting a change of bank account. Nothing about it feels like the thing the poster warned you about.

The gap is not knowledge but recognition, and you cannot campaign your way to recognition. A finance officer who has read every warning will still, in the moment, be doing their job, paying a familiar supplier promptly and without fuss. The fraud works because it wears the costume of routine.

In two decades building compliance and counter-fraud functions, and as an accredited counter-fraud specialist who has worked through these incidents at close quarters, I have come to expect a particular pattern. A successful fraud is almost never one dramatic failure. It is the coincidence of several ordinary ones: a control that existed on paper but not in practice, an approval step skipped because everyone was busy, a change waved through because the request looked normal and querying it felt awkward. Layer those everyday human behaviours together and the gap opens. That is also why the fix is rarely a single new rule, it is closing the small gaps before they line up.

The tells you were taught to spot have just been erased

There is a second reason awareness is losing ground, and it is getting worse quickly. The warning signs the guidance taught us, clumsy grammar, odd phrasing, a slightly wrong email address, are exactly what modern attackers have learned to remove. VIPRE’s Q1 2026 detection data shows business email compromise has become the single largest category, accounting for 44 per cent of all scam emails. More tellingly, these messages increasingly arrive from authenticated infrastructure, passing the SPF, DKIM and DMARC checks that were supposed to flag them.3 The FBI’s 2025 Internet Crime Report introduced its first-ever dedicated section on AI-enabled crime, recording 22,364 AI-related complaints with losses of nearly $893 million.4

Meanwhile, European Parliament research has warned that generative AI can be used to clone voices, stage deepfake video calls and build synthetic identities.5

The old tells are disappearing. When a fraudulent request becomes genuinely indistinguishable from a real one, telling staff to “be more careful” stops being a strategy.

You cannot spot your way out of a forgery you cannot see.

Modern fraud needs modern controls

The good news is that the defences have moved on too, and the most effective ones share a single principle. They protect the payment even when the human is fooled. Reliance on awareness requires a person not to make a mistake. Effective controls assume the person eventually will, and stop it costing money anyway. For a small business, four are worth knowing about.

Don’t ignore Confirmation of Payee. UK banks now check whether the name you’re paying matches the account behind the sort code and number and warn you if it doesn’t. That mismatch alert is not a glitch to click past, it is often the only outward sign that the account belongs to someone other than your supplier. Treat any “no match” as a stop signal, not a nuisance.

Put multi-factor authentication on your email, ask your key suppliers to use it too. Most of these frauds begin not with a hacked bank but with a compromised inbox (yours or your supplier’s), from which criminals watch a real invoice thread and strike. MFA is the single highest-value technical step a small firm can take, because it removes the foothold the whole fraud depends on. It is usually free and takes minutes to switch on.

Ask your IT provider about email authentication. Protocols with the initials DMARC, SPF and DKIM make it far harder for a criminal to spoof your own domain and impersonate you to your customers. They are not a complete answer on their own, the most sophisticated scams now pass these checks, but they close off the easiest impersonation route and are invisible to staff once set up. It is a five-minute conversation with whoever runs your email.

Always verify by a separate channel, and build it into the process. Any change to bank details is confirmed by phone, on a number you already hold, never one supplied in the request itself. This matters more than it sounds: a fast-growing scam works by giving you a number to call, often attached to a convincing fake invoice such as a confirmation for a purchase you never made, and a friendly “representative” answers to walk you into the fraud. The number in the message is the trap. Use the one you already had. Write the rule down so it survives a busy Friday, and pair it with simple separation of duties, meaning the person who can change a payee’s details should not be the only one who can pay them.

From a more careful human to a more resilient process

None of this is exotic or expensive, and that is the encouraging part. The rising losses are not evidence that fraud is unbeatable; they are evidence that we have leaned too long on the one lever, awareness, that was always going to hit a ceiling. The Suffolk Against Fraud partnership recognises the same thing at county level, that prevention takes shared systems and joined-up effort, not just louder warnings.

Neglect, not villainy, is what lets most of these frauds through and increasingly the neglect is structural, not personal. A well-trained employee can still be fooled by a perfect forgery. A well-designed process catches the payment before it leaves. The businesses that stop losing money are the ones that stop relying on never being fooled.

If you think you have been targeted, contact your bank immediately and report it through Report Fraud at reportfraud.police.uk or on 0300 123 2040.

Durrant Riley Advisory helps charities, social enterprises and SMEs across the East of England build the kind of quiet, proportionate controls that stop fraud before it starts. That includes outsourced DPO and AML support, alongside risk, business continuity and board assurance, all from a single named adviser. If you’d like to talk through where your organisation’s gaps are, get in touch.

Joseph Durrant-Riley is the founder of Durrant Riley Advisory Limited, a governance, risk and compliance consultancy working with charities, social enterprises and SMEs across the East of England. An accredited counter-fraud specialist (CFPAB) and certified business continuity practitioner (CBCI), he has spent over twenty years building and leading compliance, risk and counter-fraud functions, including managing serious fraud and data incidents through to resolution with the relevant regulators.

References

1. Suffolk County Council. Suffolk unites to fight fraud. 17 June 2026. Available at: suffolk.gov.uk (accessed 22 June 2026).

2. UK Finance. Annual Fraud Report 2026 (covering 2025 data). Available at: ukfinance.org.uk (accessed 22 June 2026).

3. VIPRE Security Group. Email Threat Trends Report: Q1 2026. Available at: vipre.com (accessed 22 June 2026).

4. Federal Bureau of Investigation. Internet Crime Report 2025. Internet Crime Complaint Center (IC3). Available at: ic3.gov (accessed 22 June 2026).

5. European Parliament. Scam calls in times of generative AI. European Parliamentary Research Service (EPRS), October 2025. Available at: europarl.europa.eu (accessed 22 June 2026).