More than one million calls have now been made to 159, the UK's fraud hotline, since it launched in 2021.
But cyber insurance specialists at Everywhen said the real question is whether businesses and their employees know what the number is for and when to use it.
The warning follows UK Finance's Annual Fraud Report 2026. Criminals stole £1.28 billion through payment fraud in 2025, up 4% year on year. Authorised push payment fraud, where victims are persuaded to send money to fraudsters they believe are genuine, rose 19% to £576.4 million across 248,070 cases, including £75.6 million in business losses.
UK Finance's data showed 17% of APP fraud cases in 2025 came through telecommunications channels. Those cases accounted for 28% of all APP fraud losses by value, a disproportionate share relative to volume. Investment scams caused the largest share of APP fraud losses overall at £221.5 million, up 40% year on year. Purchase scams remained the most common by case volume.
Neil D'Mello, client director at Everywhen, said the growing number of calls to 159 shows how important the service has become. He said the real question businesses should ask is whether their employees would know when to use it. A scam call doesn't necessarily sound like a scam anymore, he said, since fraudsters can be professional, knowledgeable and reassuring. The warning sign may only come when that trust turns into pressure to act immediately.
"If somebody is telling you there isn't time to verify who they are, that's exactly when you should stop, hang up and call 159," D'Mello said.
The 159 service is run by Stop Scams UK in partnership with the Global Cyber Alliance. It works on a similar principle to 101 for the police and 111 for the NHS. Callers dial 159, select their bank, and are connected safely. The service now covers banks representing more than 99% of UK retail current accounts.
Everywhen said the service's value for businesses lies less in the number itself and more in the behaviour it encourages: stop the conversation, remove the pressure, verify independently. The company said that principle applies equally to unexpected requests that appear to come from suppliers, IT providers, customers or senior colleagues, not just calls claiming to be from a bank.
D'Mello said developments such as AI-assisted communications and voice cloning add another dimension to the threat. He said businesses should focus on verification rather than recognition, since a familiar voice, professional manner or apparent knowledge of an organisation should no longer be treated as proof a caller is genuine.
The question is no longer whether something sounds like a scam, he said, but whether it should be independently verified regardless of how convincing it seems.
D'Mello said brokers specifically should understand how cyber-related information, alerts and tools are used within their own advice and client service processes, and ensure appropriate oversight is in place. Clients will continue to look to their broker for guidance in navigating cyber risk, he said.
Cyber insurance provides an important line of defence when an incident occurs, but resilience also depends on people and processes, with employees needing the confidence to stop and challenge an unexpected request regardless of how convincing the person making it seems.
Telecoms-originated fraud accounts for nearly double its share of losses relative to its share of cases, suggesting phone-based social engineering is more effective at extracting larger sums once a scam call lands, compared with the higher-volume but typically lower-value scams that start online.
For brokers advising clients on cyber and crime cover, that data supports a simple, low-cost step: making sure staff know a specific number and a specific behaviour, stop, verify, call back, as a genuine complement to more expensive technical and insurance-based defences.