Security Tips: Stopping Payment Fraud in Freight


Shared with our trusted agent network

The one procedure that stops payment fraud

A practical, no-cost control that any freight forwarder can implement this week — built by Westbound after we learned the hard way.

Why we wrote this

We got scammed. Here’s what we learned.

Our industry is an unusually attractive target. Forwarders move large sums to a rotating cast of overseas suppliers, carriers, hauliers and agents — often at speed, often against a demurrage clock, and often with genuine last-minute changes to who gets paid. That is precisely the noise a fraudster hides inside.

We won’t pretend it didn’t happen. Westbound was scammed. In the grand scheme of what these frauds can cost, it was a relatively small sum — but it was a costly lesson, and it was one we did not want to pay for. The sting is that the loss was preventable. What it cost us in money, it repaid us in clarity: we rebuilt our payment authorisation process around a single assumption: at some point, someone will send us a convincing email that is not who it claims to be. The control below is what came out of that. It costs nothing, takes about twenty minutes to configure, and it removes the weakness that nearly every payment scam depends on.

We are publishing it openly because a fraud that succeeds against one agent in a network tends to be attempted against the rest. If it helps one of our partners avoid a loss, it has paid for itself.

The scale of it

This is not a rare event

Payment diversion is now one of the most financially damaging crimes committed against businesses anywhere. These are reported figures only — the real totals are higher, because many businesses never report.

£1.28bn
stolen through payment fraud in the UK in 2025, across more than four million cases — UK Finance
$3.05bn
reported losses from business email compromise in 2025 alone, from 24,768 complaints — FBI IC3
£75.6m
of 2025 UK authorised push payment losses fell on businesses rather than individuals — UK Finance

Encouragingly, UK losses specifically from invoice and mandate scams, CEO fraud and impersonation fell to record lows in 2025, which UK Finance attributes to sustained investment in prevention and staff awareness (Annual Fraud Report 2026). Controls like the one on this page are why that number is falling. They work.

Know the playbook

Four approaches you will actually see

Different stories, one identical goal: to get a payment authorised without anyone independently confirming the request is genuine. UK police classify most of this as mandate fraud or payment diversion fraud.

The change of bank details

An email arrives from a supplier, carrier or agent you genuinely work with, advising that their bank account has changed. The invoice looks right. The signature block looks right. The sender address is a near-perfect lookalike, or in the worst case a real mailbox that has been compromised.

The tellBank details changing is always worth a phone call — to a number you already held, never one printed on the new invoice.

The urgent request from the boss

A short, slightly clipped message appearing to come from a director: a payment must go today, it’s commercially sensitive, please don’t discuss it with the wider team. The pressure and the secrecy are the product. They exist to stop your accounts staff doing the one thing that would expose it — asking someone.

The tellGenuine directors do not mind being verified. Any instruction discouraging you from checking is itself the red flag.

The gift card errand

“I’m stuck in a meeting / at the airport and need vouchers for a client gift — I’ll reimburse you.” It sounds trivial and personal, which is exactly why it slips through. Gift cards are the withdrawal method of choice because the codes are spendable within minutes and are effectively untraceable and irreversible.

The tellNo legitimate business need has ever required an employee to buy vouchers urgently and send photographs of the codes.

The bank on the phone

A caller presenting as your bank’s fraud team, warning of suspicious activity and offering to help you move funds to a “safe account”, or asking you to confirm codes and passwords to stop a payment. They may already know your name, your bank and recent transactions — and the number may even appear genuine, because caller ID can be spoofed.

The tellA real bank will never ask you to move money to a safe account, and never asks for full passcodes. Hang up and call back on the number on your card or statement.

The fix

A mailbox that outsiders physically cannot email

Awareness training helps, but it relies on a tired person spotting a good forgery on a bad day. This control does not. It removes the fraudster’s ability to make first contact at all.

The principle in one line: create a single internal-only address that every payment request must pass through, and configure it so that mail from outside your organisation is rejected outright.

In Microsoft 365 — and in Google Workspace and most other business platforms — a distribution group or shared mailbox can be restricted so that only authenticated internal senders are accepted. Everything from the outside world bounces. It never lands in a human inbox, so there is no forgery to evaluate, no judgement call to get wrong, and no busy Friday afternoon on which someone gets it wrong.

Call it something plain and procedural, such as [email protected]. Then make one rule absolute: if a payment request did not arrive through that address, it does not get paid. No exceptions for urgency, seniority, or a good story. The strength of the control is entirely in the absence of exceptions.

Why this is so effective: a fraudster’s entire approach depends on getting a believable instruction in front of the person who can make a payment. If that person only ever acts on requests arriving via a channel that outsiders cannot reach, the attack has nowhere to land. You are no longer asking staff to detect fraud — you have made the fraudulent route structurally unavailable.

Implementation

Setting it up in Microsoft 365

Roughly twenty minutes of work in the Exchange admin centre. Your IT provider can do it in one ticket if you’d rather not touch it yourself.

  1. Create the group

    In the Microsoft 365 admin centre, create a new distribution list — for example [email protected]. Keep the name boring and self-explanatory so nobody is tempted to invent their own alternative.

  2. Lock it to internal senders only

    Open the group’s Settings and find the delivery management or message approval options. Ensure “Allow people inside my organisation to send” is selected and that the option permitting external senders is switched off. This is the step that does the actual work — do not skip or soften it.

  3. Add your accounts team as members

    Mail to the group forwards to the finance or accounts staff who process payments. Add at least two people so the process survives holiday and sickness without anyone inventing a workaround.

  4. Test it from the outside

    Send a message to the address from a personal webmail account on your phone. It must bounce. If it arrives, the restriction is not applied correctly — fix it before relying on the process.

  5. Announce the rule, then hold the line

    Tell the whole team, directors included, that this is now the only accepted route for payment requests. Then make sure the directors actually follow it. A control that senior staff bypass is not a control, and staff will quickly learn that exceptions are available.

Day to day

How the process runs

Four steps. Adds seconds to a genuine payment, and stops a fraudulent one dead.

Step 1
Everything goes to the group
Any supplier invoice or payment request — including from the owners — is forwarded internally to the restricted address.
Step 2
Accounts receives it
The group forwards to your usual accounts staff, who now know that anything arriving here has an internal origin.
Step 3
Fresh thread back
Accounts start a brand-new email to the colleague, asking them to confirm and approve. Never reply within the original chain.
Step 4
Approved, then paid
A “yes” or a thumbs up is enough. No confirmation, no payment — however urgent the original request claimed to be.

Step 3 matters more than it looks. Always compose a fresh message rather than hitting reply. If a mailbox has been compromised, or the original address is a lookalike, your reply travels straight back to the fraudster — who will happily confirm their own request. Starting a new email means your confirmation goes to the address in your own directory, which is the one you can trust. Better still, walk over and ask, or pick up the phone.

Worth adding

Sensible reinforcements

The restricted group is the backbone. These layers make the surrounding process harder to attack.

  • Treat any change of bank details as suspicious by default, and verify by phone on a number you already held on file.
  • Never use contact details printed on the invoice or email that is requesting the change.
  • No invoice, no payment. Every payment request — including from directors — must have a proper invoice or remittance attached. An email saying “these bank details need paying” is not a payment request; it is a red flag. Accounts staff must enforce this rule on everyone, owners included.
  • Set a payment value above which two named people must authorise, independently.
  • Turn on external sender warning tags in Microsoft 365 so outside mail is visibly flagged.
  • Enforce multi-factor authentication on every mailbox — most compromises start with a stolen password. This is not the burden people imagine: you verify once per device, not every time you log in. Once your phone has trusted the machine, you’re done.
  • Use Confirmation of Payee on UK transfers and stop if the account name does not match.
  • Make a small test payment first when onboarding a genuinely new supplier, and confirm receipt verbally.
  • Tell staff plainly that they will never be criticised for delaying a payment to verify it.
Manufactured urgencyDeadlines, penalties, a container supposedly about to incur demurrage — all designed to shorten your thinking time.
Requests for secrecy“Don’t mention this to the others.” Isolation from colleagues is a fraud technique, not a business practice.
Changed channel or toneA supplier who always phones now only emails, or a familiar contact suddenly writing in an unfamiliar register.

If the worst happens

The first hour is what counts

Funds can sometimes be recalled if you move immediately. Speed matters far more than working out how it happened, or who is to blame — do that afterwards.

  • Call your bank straight away and ask them to attempt a recall, then contact the receiving bank.
  • Report it to Action Fraud on 0300 123 2040, or online. In Scotland, call Police Scotland on 101.
  • Force a password reset and check mailbox rules — fraudsters often add hidden forwarding rules to stay invisible.
  • Preserve the evidence. Keep the original emails with full headers; do not delete anything.
  • Warn the genuine supplier — their mailbox may be the one that was compromised.
  • Tell your team and your network. The same attempt is usually made against several agents at once.

Action Fraud’s guidance is worth repeating verbatim: Stop. Challenge. Protect. Stop and think before acting on any urgent payment request, challenge whether it could be fake, and protect the business by verifying independently before money moves (Action Fraud).

Pass it on

There is nothing commercial on this page and nothing to sign up to. If it is useful, send it to your accounts team, your agents and anyone in your network who moves money on someone else’s instruction.

westboundglobal.com/security-tips

Shared in good faith by Westbound Logistics Services Ltd for the benefit of our trusted agent network. This page describes the controls we operate ourselves and is offered as general guidance, not as formal security, legal or financial advice. Configuration steps vary between platforms and versions — confirm arrangements with your own IT and finance advisers before relying on them.

Sources
UK Finance, Annual Fraud Report 2026 press release and full report (PDF) — 2025 UK payment fraud losses of £1.28bn, APP losses of £576.4m including £75.6m of business losses, and record lows in invoice, mandate and CEO fraud.
FBI Internet Crime Complaint Center, 2025 Internet Crime Report (PDF) — $3.05bn in reported business email compromise losses from 24,768 complaints.
Action Fraud, Mandate Fraud guidance — definitions of mandate fraud and payment diversion fraud, the Stop / Challenge / Protect framework, and reporting routes.