Security Tips: Stopping Payment Fraud in Freight
Shared with our trusted agent network
The one procedure that stops payment fraud
A practical, no-cost control that any freight forwarder can implement this week — built by Westbound after we learned the hard way.
Why we wrote this
We got scammed. Here’s what we learned.
Our industry is an unusually attractive target. Forwarders move large sums to a rotating cast of overseas suppliers, carriers, hauliers and agents — often at speed, often against a demurrage clock, and often with genuine last-minute changes to who gets paid. That is precisely the noise a fraudster hides inside.
We won’t pretend it didn’t happen. Westbound was scammed. In the grand scheme of what these frauds can cost, it was a relatively small sum — but it was a costly lesson, and it was one we did not want to pay for. The sting is that the loss was preventable. What it cost us in money, it repaid us in clarity: we rebuilt our payment authorisation process around a single assumption: at some point, someone will send us a convincing email that is not who it claims to be. The control below is what came out of that. It costs nothing, takes about twenty minutes to configure, and it removes the weakness that nearly every payment scam depends on.
We are publishing it openly because a fraud that succeeds against one agent in a network tends to be attempted against the rest. If it helps one of our partners avoid a loss, it has paid for itself.
The scale of it
This is not a rare event
Payment diversion is now one of the most financially damaging crimes committed against businesses anywhere. These are reported figures only — the real totals are higher, because many businesses never report.
stolen through payment fraud in the UK in 2025, across more than four million cases — UK Finance
reported losses from business email compromise in 2025 alone, from 24,768 complaints — FBI IC3
of 2025 UK authorised push payment losses fell on businesses rather than individuals — UK Finance
Encouragingly, UK losses specifically from invoice and mandate scams, CEO fraud and impersonation fell to record lows in 2025, which UK Finance attributes to sustained investment in prevention and staff awareness (Annual Fraud Report 2026). Controls like the one on this page are why that number is falling. They work.
Know the playbook
Four approaches you will actually see
Different stories, one identical goal: to get a payment authorised without anyone independently confirming the request is genuine. UK police classify most of this as mandate fraud or payment diversion fraud.
The change of bank details
An email arrives from a supplier, carrier or agent you genuinely work with, advising that their bank account has changed. The invoice looks right. The signature block looks right. The sender address is a near-perfect lookalike, or in the worst case a real mailbox that has been compromised.
The urgent request from the boss
A short, slightly clipped message appearing to come from a director: a payment must go today, it’s commercially sensitive, please don’t discuss it with the wider team. The pressure and the secrecy are the product. They exist to stop your accounts staff doing the one thing that would expose it — asking someone.
The gift card errand
“I’m stuck in a meeting / at the airport and need vouchers for a client gift — I’ll reimburse you.” It sounds trivial and personal, which is exactly why it slips through. Gift cards are the withdrawal method of choice because the codes are spendable within minutes and are effectively untraceable and irreversible.
The bank on the phone
A caller presenting as your bank’s fraud team, warning of suspicious activity and offering to help you move funds to a “safe account”, or asking you to confirm codes and passwords to stop a payment. They may already know your name, your bank and recent transactions — and the number may even appear genuine, because caller ID can be spoofed.
The fix
A mailbox that outsiders physically cannot email
Awareness training helps, but it relies on a tired person spotting a good forgery on a bad day. This control does not. It removes the fraudster’s ability to make first contact at all.
The principle in one line: create a single internal-only address that every payment request must pass through, and configure it so that mail from outside your organisation is rejected outright.
In Microsoft 365 — and in Google Workspace and most other business platforms — a distribution group or shared mailbox can be restricted so that only authenticated internal senders are accepted. Everything from the outside world bounces. It never lands in a human inbox, so there is no forgery to evaluate, no judgement call to get wrong, and no busy Friday afternoon on which someone gets it wrong.
Call it something plain and procedural, such as [email protected]. Then make one rule absolute: if a payment request did not arrive through that address, it does not get paid. No exceptions for urgency, seniority, or a good story. The strength of the control is entirely in the absence of exceptions.
Why this is so effective: a fraudster’s entire approach depends on getting a believable instruction in front of the person who can make a payment. If that person only ever acts on requests arriving via a channel that outsiders cannot reach, the attack has nowhere to land. You are no longer asking staff to detect fraud — you have made the fraudulent route structurally unavailable.
Implementation
Setting it up in Microsoft 365
Roughly twenty minutes of work in the Exchange admin centre. Your IT provider can do it in one ticket if you’d rather not touch it yourself.
-
Create the group
In the Microsoft 365 admin centre, create a new distribution list — for example
[email protected]. Keep the name boring and self-explanatory so nobody is tempted to invent their own alternative. -
Lock it to internal senders only
Open the group’s
Settingsand find the delivery management or message approval options. Ensure “Allow people inside my organisation to send” is selected and that the option permitting external senders is switched off. This is the step that does the actual work — do not skip or soften it. -
Add your accounts team as members
Mail to the group forwards to the finance or accounts staff who process payments. Add at least two people so the process survives holiday and sickness without anyone inventing a workaround.
-
Test it from the outside
Send a message to the address from a personal webmail account on your phone. It must bounce. If it arrives, the restriction is not applied correctly — fix it before relying on the process.
-
Announce the rule, then hold the line
Tell the whole team, directors included, that this is now the only accepted route for payment requests. Then make sure the directors actually follow it. A control that senior staff bypass is not a control, and staff will quickly learn that exceptions are available.
Day to day
How the process runs
Four steps. Adds seconds to a genuine payment, and stops a fraudulent one dead.
Step 3 matters more than it looks. Always compose a fresh message rather than hitting reply. If a mailbox has been compromised, or the original address is a lookalike, your reply travels straight back to the fraudster — who will happily confirm their own request. Starting a new email means your confirmation goes to the address in your own directory, which is the one you can trust. Better still, walk over and ask, or pick up the phone.
Worth adding
Sensible reinforcements
The restricted group is the backbone. These layers make the surrounding process harder to attack.
- Treat any change of bank details as suspicious by default, and verify by phone on a number you already held on file.
- Never use contact details printed on the invoice or email that is requesting the change.
- No invoice, no payment. Every payment request — including from directors — must have a proper invoice or remittance attached. An email saying “these bank details need paying” is not a payment request; it is a red flag. Accounts staff must enforce this rule on everyone, owners included.
- Set a payment value above which two named people must authorise, independently.
- Turn on external sender warning tags in Microsoft 365 so outside mail is visibly flagged.
- Enforce multi-factor authentication on every mailbox — most compromises start with a stolen password. This is not the burden people imagine: you verify once per device, not every time you log in. Once your phone has trusted the machine, you’re done.
- Use Confirmation of Payee on UK transfers and stop if the account name does not match.
- Make a small test payment first when onboarding a genuinely new supplier, and confirm receipt verbally.
- Tell staff plainly that they will never be criticised for delaying a payment to verify it.
If the worst happens
The first hour is what counts
Funds can sometimes be recalled if you move immediately. Speed matters far more than working out how it happened, or who is to blame — do that afterwards.
- Call your bank straight away and ask them to attempt a recall, then contact the receiving bank.
- Report it to Action Fraud on 0300 123 2040, or online. In Scotland, call Police Scotland on 101.
- Force a password reset and check mailbox rules — fraudsters often add hidden forwarding rules to stay invisible.
- Preserve the evidence. Keep the original emails with full headers; do not delete anything.
- Warn the genuine supplier — their mailbox may be the one that was compromised.
- Tell your team and your network. The same attempt is usually made against several agents at once.
Action Fraud’s guidance is worth repeating verbatim: Stop. Challenge. Protect. Stop and think before acting on any urgent payment request, challenge whether it could be fake, and protect the business by verifying independently before money moves (Action Fraud).
Pass it on
There is nothing commercial on this page and nothing to sign up to. If it is useful, send it to your accounts team, your agents and anyone in your network who moves money on someone else’s instruction.
Shared in good faith by Westbound Logistics Services Ltd for the benefit of our trusted agent network. This page describes the controls we operate ourselves and is offered as general guidance, not as formal security, legal or financial advice. Configuration steps vary between platforms and versions — confirm arrangements with your own IT and finance advisers before relying on them.
UK Finance, Annual Fraud Report 2026 press release and full report (PDF) — 2025 UK payment fraud losses of £1.28bn, APP losses of £576.4m including £75.6m of business losses, and record lows in invoice, mandate and CEO fraud.
FBI Internet Crime Complaint Center, 2025 Internet Crime Report (PDF) — $3.05bn in reported business email compromise losses from 24,768 complaints.
Action Fraud, Mandate Fraud guidance — definitions of mandate fraud and payment diversion fraud, the Stop / Challenge / Protect framework, and reporting routes.