Businesses urged to use 159 to fight payment fraud
Thu, 27th Aug 2026 (Today)
Everywhen has urged businesses to ensure staff know how to use the 159 banking verification service if they suspect fraud, as payment fraud losses in the UK reached GBP £1.28 billion.
More than one million calls have been made to 159 since the service launched, according to the insurance broker, but it questioned whether many employees would recognise the number or know when to use it. The line allows people who receive an unexpected call about financial matters to end the conversation and contact their bank through a trusted route.
Fraud losses
The intervention follows new fraud figures showing that Authorised Push Payment fraud remains a major source of losses across the UK. UK Finance reported that APP fraud losses rose 19% to GBP £576.4 million, with business losses accounting for GBP £75.6 million of that total.
Telephone-based scams made up a smaller share of cases but a larger share of losses. The figures show that 17% of APP fraud cases originated through telecommunications, yet those incidents accounted for 28% of all APP fraud losses.
That imbalance points to the higher cost of scams carried out over the phone, where fraudsters may exploit urgency, trust and apparent familiarity. Businesses face particular risk when staff receive requests that seem to come from banks, suppliers, IT providers, customers or senior colleagues.
The 159 service was introduced as a simple way for consumers and businesses to verify suspicious calls. It works in a similar way to other well-known public service numbers, allowing callers to select their bank and be connected safely. It now covers customers representing more than 99% of UK retail bank current accounts.
Building habits
Everywhen argued that the significance of the service goes beyond the number itself. The key lesson for organisations, it said, is to build habits around ending an unsolicited call, removing pressure and checking independently before acting.
That approach has become more important as fraud methods grow more convincing. Voice cloning and other forms of AI-assisted communication have made it harder for employees to rely on recognition alone when judging whether a call is genuine.
A familiar tone of voice, knowledge of company details or a professional manner may no longer offer much reassurance. Criminals can now mimic internal language, supplier relationships and bank procedures closely enough to push staff into making payments or sharing sensitive information.
Neil D'Mello, Client Director at Everywhen, said: "The growing number of calls to 159 demonstrates just how important the service has become, but the question businesses should be asking is: would your employees know when to use it? A scam call doesn't necessarily sound like a scam anymore. Fraudsters can be professional, knowledgeable and reassuring. The warning sign may only come when that trust turns into pressure to act immediately.
"If somebody is telling you there isn't time to verify who they are, that's exactly when you should stop, hang up and call 159!"
The warning reflects a broader shift in cyber and fraud prevention, with businesses being encouraged to focus less on spotting obvious warning signs and more on establishing clear verification steps. In practice, that means training staff to pause transactions, challenge unexpected instructions and use approved channels before moving money or disclosing details.
For insurance brokers and risk advisers, the issue also extends to client service and governance. Firms that discuss cyber risk with clients are increasingly expected to understand what alerts, tools and fraud prevention processes are in place, and whether there is appropriate oversight.
D'Mello said: "The question is no longer simply, 'Does this sound like a scam?' It should be, 'Should I independently verify that this is genuine?'
"Cyber scams continue to evolve in sophistication and can have significant financial and reputational consequences for clients. Brokers should understand how cyber-related information, alerts and tools are being used within their advice and client service processes, and ensure appropriate oversight is in place. This can help reduce the risk of clients falling victim to fraud, phishing, social engineering or other cyber threats."
Staff vigilance
The emphasis on internal process is notable at a time when many businesses have already tightened payment controls but still face social engineering attempts aimed at individuals. Fraudsters often target moments of distraction, staff changes or busy periods, when unusual payment requests are less likely to be questioned.
Training around 159 could provide a simple entry point for wider anti-fraud awareness, especially for employees in finance, procurement, customer service and senior support roles. Those teams are often closest to the types of requests that can lead to APP fraud losses.
D'Mello said: "Cyber insurance can provide an important line of defence when an incident occurs, but resilience also depends on people and processes. Employees should feel confident stopping and challenging an unexpected request, regardless of how convincing the person making it seems. 159 is a simple example of that principle in action. It is well worth making sure your employees are fully aware of these three very important numbers."