Phone scams cause 28% of APP fraud losses. A client's crime policy needs the right wording

UK Finance's 2026 fraud report puts £576 million in APP losses on the table. The telecoms channel's disproportionate share points directly to a social engineering coverage question brokers should be asking before a claim forces it

Phone scams cause 28% of APP fraud losses. A client's crime policy needs the right wording

Insurance News

By Josh Recamara

Criminals stole £1.28 billion through payment fraud in 2025, up 4% year on year, according to UK Finance's Annual Fraud Report 2026. APP fraud - where victims are persuaded to transfer money themselves - rose 19% to £576.4 million across 248,070 cases. Banks reimbursed £354.3 million to APP victims, around 61% of losses.

Within APP fraud, investment scams are the dominant loss category by value: up 40% year on year to £221.5 million, representing 38% of all APP losses from just 14,893 cases. That case-to-loss ratio reflects how effective long-form trust-building scams have become relative to the high-volume, lower-value purchase scams that account for 71% of APP cases but a far smaller share of total losses. Business losses from APP fraud were £75.6 million across the year.

The telecoms number brokers should focus on

Two-thirds of APP fraud in 2025 originated online. The telecoms channel - phone calls - accounted for 17% of cases but caused 28% of losses by value.

That gap is not incidental. Phone-based fraud extracts larger sums per incident because it enables the kind of sustained, real-time social engineering that moves serious money. A purchase scam online typically involves one impulsive transaction. A phone call from a convincing caller claiming to be a bank, HMRC or a firm's own IT support - particularly one deploying AI-assisted voice or detailed personal knowledge - can sustain a conversation long enough to authorise a transfer that a written request would never have achieved.

Investment scam losses at £221.5 million, up 40%, are the clearest evidence of that dynamic at scale: a relatively small number of highly effective social engineering conversations producing the largest average losses of any APP fraud category.

The insurance question the data raises

For brokers advising commercial clients on cyber and crime cover, the telecoms loss pattern raises a specific policy wording question that UK Finance's data makes harder to defer.

Most crime policies include a social engineering or fraudulent instruction insuring agreement that responds when an employee is deceived into authorising a payment. The critical variable is whether that insuring agreement requires a network intrusion - a hack, a system compromise, malware - as a precondition for coverage, or whether it responds to social engineering alone: a convincing caller, a spoofed number, a voice that sounds right, a story that holds together until the money has moved.

Policies that require a network intrusion element to trigger social engineering cover will not respond to a well-executed phone scam. The caller never touched the client's systems. There was no intrusion. The employee authorised the transfer. UK Finance's data shows that phone-originated fraud, precisely because it bypasses technical defences entirely and works directly on the person, produces losses nearly double its proportional share of cases. That is the pattern that exposes the gap.

A client whose finance team transferred £150,000 to a fraudster posing as their supplier's accounts department, following a call that provided correct invoice numbers and a plausible payment reason, has a large and real loss. Whether their crime or cyber policy responds depends entirely on how the social engineering insuring clause is worded - and in many cases it was written before AI voice tools made impersonation convincingly seamless and before phone-based investment fraud reached £221.5 million in a single year.

Neil D'Mello, client director at cyber insurance specialist Everywhen, said the question businesses should be asking is no longer whether something sounds like a scam, but whether it should be independently verified regardless of how convincing it seems. He said brokers specifically should understand how cyber-related tools are embedded in their own advice processes, and ensure appropriate oversight is in place. "Clients will continue to look to their broker for guidance in navigating cyber risk," he said, noting that resilience depends on people and processes as well as insurance.

What brokers should be doing at the next renewal

The UK Finance data supports three specific questions worth asking of any commercial client's crime and cyber programme before a claim makes them unavoidable.

The first is whether the social engineering insuring agreement responds without a network intrusion requirement. If it does not, a client whose employees have payment authority and regular contact with external parties - suppliers, customers, professional advisers - carries an uninsured exposure that phone-based fraud is specifically designed to exploit.

The second is whether the policy limit and sublimit for social engineering reflects the actual transfer authority held by the people most likely to receive a convincing call. Business losses from APP fraud averaged in the tens of thousands per case in 2025, but investment and impersonation scams targeting senior finance staff or business owners can produce single losses well above those averages.

The third is whether the client has a documented verification process - a call-back procedure using independently verified numbers, a dual-authorisation requirement above a defined threshold - that reduces the probability of a successful phone social engineering attack and, where cover is conditional on reasonable precautions, ensures the claim will not be declined on those grounds.

The 159 service - operated by Stop Scams UK and covering banks representing more than 99% of UK retail current accounts - is the most specific single tool the regulatory response has produced for phone fraud. Whether business clients know it exists, and whether their staff have a documented instruction to use it when a payment request arrives unexpectedly by phone, is a question a broker is better placed than anyone to ask and answer before the next authorised push payment leaves the client's account.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!