Fraud Matters
Fraud Matters is the podcast from the Fraud Advisory Panel that cuts through the complexity of fraud to help business owners, directors, and senior managers understand what they're really up against — and what to do about it.
Hosted by Guy Ruddle, each episode brings together leading legal experts, investigators, and practitioners to explore the fraud threats that affect businesses of every size. From supply chain fraud and corporate impersonation to insider threats and emerging digital risks, Fraud Matters takes you beyond the theory and into the real world, where fraud is varied, costly, and often closer to home than you'd think.
Whether you're a founder, a finance director, or a senior manager, this podcast will help you spot the warning signs, ask the right questions, and build the kind of culture and processes that make fraud harder to hide.
Prevention is always better than cure. Fraud Matters gives you the knowledge to start.
New episodes monthly. Subscribe now and never miss a conversation that could protect your business.
Fraud Matters
Impersonation: Spotting the signs
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode, we take a look at corporate impersonation: an insidious form of fraud. Today’s technology has lowered the barriers to entry for corporate imposters, and their efforts can be worryingly convincing. Guy and our guests discuss how corporate impersonation might manifest, what damage these threat actors can do, and how businesses protect themselves from impersonators – and being impersonated.
Guests:
- Alex Rothwell, CEO of the NHS Counter Fraud Authority
- Avigyan Das, Senior Managing Director at FTI Consulting
Host: Guy Ruddle
Producer: Ed Adams
Series Lead: Mark Rowland
Episode recorded: 21 July 2026
[Teaser audio] Avi Das: With the advent of technology, fraud hasn't changed, but what it has done is expedited the whole process, and there is so much information online to impersonate someone.
[Teaser audio] Alex Rothwell: If you're doing interviews, we are definitely seeing imposters. Is the person you're interviewing for a role, the person who actually turns up on day one? Are they who they say they are?
Guy Ruddle: Hello and welcome to another episode of Fraud Matters, the podcast exploring what it's really like to be affected by fraud, and how to make sure it doesn't happen to you and your business. I'm Guy Ruddle, and today we're talking about corporate impersonation, an insidious form of fraud that with today's technology is easier than ever to do, and worryingly convincing. So how do you spot that the executive on your team's call doesn't really exist or that it's not your bank that's really talking to you? Well, joining me to talk about this topic are two fraud experts. Let's first meet Alex Rothwell, he's CEO of the NHS Counter Fraud Authority with a 30 year career investigating fraud and financial crime for the Metropolitan Police and the City of London Police Service. Alex, welcome to Fraud Matters.
AR: Thank you. Appreciate it.
GR: So what is the NHS Counter Fraud Authority?
AR: So I've been doing this fantastic job now for nearly five years. We're an independent arms length body. We're funded by the Department of Health and Social Care, and we exist to tackle fraud, bribery, and corruption in the National Health Service in England. If we think of it as a business, it's a £200 billion-turnover business. It's the sixth largest employer in the world. Pretty well, everybody in the UK is a customer, but sadly we do have considerable fraud risk and we estimate that we lose about £1.4 billion a year to fraud and corruption in the health service.
GR: In that job, but also with the City of London police and with the MET and everything, you must have seen everything?
AR: I've certainly seen pretty well all types of fraud that I think you could come across, but there you go. Things still surprise you.
GR: Avi Das is senior managing director at FTI Consulting and an expert in digital forensics. Avi, welcome to the podcast.
AD: Thank you.
GR: How did you get into this area?
AD: Probably by accident. As you probably can guess, I'm born and raised in India. I came to the UK in 2004. I wanted to do a degree in something different than computer science. That was a trend at that time. So I got into a university called University of Staffordshire which was apparently the first university who was doing masters in forensic computing. I had no idea what forensic computing meant back in 2004, got into forensic computing and then found out quite cool stuff about how do you investigate fraud? How do you investigate crime using technology?
GR: What sort of clients do you work with?
AD: So I work primarily with large corporates across the globe. Some of my clients are from financial services, some from energy sectors, some from pharma, but I do also have a lot of law firm clients as well. So magic circle law firms that I work with.
GR: Right then gentlemen, let's get stuck into this topic. How common, Alex, do you think corporate impersonation is? It strikes me as something which is a bit harder to do than phishing, but probably just as, if not more profitable?
AR: Yeah you could argue that most fraud in some form or other, involves some form of impersonation. I think perhaps what we might typically think about is a kind of mandate fraud, invoice fraud. We certainly as the NHS, we're a business like everybody else and we fall victim and we do a lot of prevention in that space, but I also see it as being a little bit broader than just that type of activity. For us, we think about it as people pretending to be somebody, which is the type of example we're talking about. Are you pretending to have something? And for us that might be something like qualifications or experience. Are you pretending to be entitled to something? And that's quite an important thing for us in the NHS because people access our services every single day and not everybody is entitled to free healthcare. Or are you actually pretending to have some form of authority? So I tend to put it in those four categories, and as I say all of that adds up to substantial loss. We know that fraud is the most prevalent crime in the UK and you are more likely to be the victim of fraud than any other type of crime full stop.
GR: Who tends to be the perpetrators is this an internal thing or an external thing?
AD: I think you would be very surprised. I've been doing this for quite a few years and I would probably say a large volume, a large percentage of this comes from internal and then obviously there would be other threat actors, which comes from outside, probably from cyber attacks, et cetera. But quite a few of them in my career I've seen in terms of people trying to be a vendor or people trying to be a third party provider, a disgruntled employee. We have seen so many of these cases. Anti bribery corruption is a huge area, right? Which comes from internal organisation rather than from external.
AR: I think that's a really good point because it just describes just how comprehensive that threat picture is. If you are running a business and you are mapping out where your risks lie, yes, there's international. Global crime networks that generate on an industrial scale, opportunities to commit fraud. But sometimes that opportunity can actually sit within your own organisation or at least facilitate it. That's something, we've sadly seen examples of as well. So I think it's a really good point.
GR: Like what?
AR: Let's say for example, you have people working in a finance department. We had a case involving sums of money that had accumulated over the years from payments that have been made, which hadn't been claimed. It actually amounted to quite a substantial amount of money and somebody within a finance department was aware that there was very little governance in relation to these amounts. Then they had found a way to extract money from those accounts by creating false payments, false claims from patients, and had then diverted the money to themselves and part of their wider network. But again, if you think about that from an impersonation point of view, that involved creating fake claims from patients. Now, that scenario I've described is quite specific to healthcare, but I'm pretty sure every business has sums of money that erode to clients for various things that are sitting in accounts. I'd asked the question, what sort of controls have you got in place to manage the risk of those being misappropriated?
AD: I think regulators are looking for those as well. They need one of the senior stakeholders to own that, right? That's what they're trying to see. Have you taken a reasonable approach to mitigate that risk or not, right? . That's what the regulators are looking to see. With the advent of technology, the fraud hasn't changed, but what it has done is expedited the whole process, right? It became much easier. You talk about some of the case studies, which is, there was a big consultancy business called Arup in Hong Kong, right? In 2024, we have seen that a finance employee has lost about $25 million, just from impersonation. They had created a video call with an impersonated image, with multiple heads of the organisation. So it appears like they set up a video call with five senior stakeholders on the call, calling your finance department and asking them to transfer funds. You wouldn't believe 10 years ago, if someone is setting up a legitimate call being set up by senior stakeholders and asking a finance employee to transfer it. $25 million have been transferred on 15 different transactions. The money's gone.
GR: So I understand that in your world you have this concept of social engineering as a sort of way of describing how fraud happens. Can you explain to me what that actually means?
AR: Virtually all of our transactions in life are based on trust in some form. Whether it's somebody you know, or whether it's a position of authority that you trust. There's that famous thing, isn't it? That people are wearing a fluorescent tabard. People have been proven to listen more or take instructions from people just because they're wearing a fluorescent jacket in a car park because we expect them to be giving instructions or asking us to do something. So this concept of social engineering plays on that, on that feeling of trust that we have. It's convincing you to take a course of action which you certainly wouldn't do if you knew what was actually sitting behind it. I think for me, that's what it looks like across the whole fraud landscape.
AD: Yeah, it's just psychological nudge, right? Which you probably wouldn't do things if you are thinking through the box. So they would leverage, for example, authority. A CEO calls someone and tells them "I'm the CEO, can you do this?" So leveraging authority, leveraging urgency. "We have got an urgent payment to make. There's a very sensitive investigation going on. Don't talk about this to any of your employees." So there are typical trends that you can follow and there is so much information that is available online to impersonate someone. If I pretend to be some company's CEO or head of finance or CFO, I could find so much information about that organisation, A through their website, B through LinkedIn profiles, C through social media. I probably, if I wanted to do that, I could potentially scan through all the social networks that are available. I could see where he's travelling, where his office is, what colour car he drives. So much information and actually organisations pay a lot of money to the marketing team to make those people available to the world. There is a legitimate reason for it, but also there is a fine balance between privacy and how much you're putting it out as well.
AR: I suspect that most of the people listening to this podcast don't consider themselves to be vulnerable people. But one of our greatest vulnerabilities is time. And that's what we see time and again with fraud. That sense of creating a sense of urgency. We see it in online shopping and things, only two left, you need to buy now, discount applicable today, only that sort of thing. Fraudsters use all the same sales techniques to convince you to take a course of action that you wouldn't have ordinarily taken.
AD: And to impersonate a voice, it only takes three seconds of an audio sample that I could create someone's voice with. There is so much free technology available that you could literally impersonate someone's voice. Video is still fairly common, but you could potentially find out if it's a fake video or not. If you're speaking to someone over a call or something, there are things that you could do. How can you tell when you are doing a video impersonation? Normally you would see the person who is on the other side of the call sitting still. Generally, if you move your head or you move your body, it doesn't do very well. So you can tell whether someone is real or not. If there is a difference in light, that avatar sometimes doesn't work very well. So that's one thing. The other thing is when you move your hand in front of the face, sometimes the avatar doesn't do that very well. So these are the small cues that you can use. If you are seeing someone who is on the other side of a team's call, but your gut feeling says something is wrong because it's out of pattern, you can check the breathing, whether they're breathing or not. If you're asking some questions about how they are reacting. If it's very mechanical, then your gut feeling would be that it's very robotic. The best thing to do, what normally a lot of banks do and a lot of corporate does, you say, "okay, hang up. I'll give you a call back and we can talk through this." That's a way that you can verify.
AR: One thing that we're seeing that's as we say, quite high-end targeting, but we're seeing similar methodology used in recruitment. So, if you're doing online interviews we are definitely seeing imposters taking interviews.
AD: It's a huge business in India.
AR: It is, absolutely. It's a significant and growing risk for businesses—is the person you're interviewing for a role the person who actually turns up on day one?
GR: Specifically on faking someone's voice, video fake and all that sort of stuff. My instinct is that human beings have an instinct. They might not articulate it or it might just be at the back of their mind that this is, "am I really watching the real thing here, or is it a little bit vague?" But it'd be very hard to say, excuse me, boss, I'm not sure that's you. I don't know how you ever get round that?
AR: But it's not hard if that's your policy and you've explained the reasons why. Almost all of the money that has been lost to fraud in the NHS to mandate fraud in recent years, and we've significantly reduced it, our losses are very low now as a result of much tighter controls, but almost all of the losses has been as a result of junior staff being responsible for making significant payments. Then that sort of power imbalance where the fraudster is impersonating a CEO doesn't have to be a CEO, either, it can be a senior person. We always talk about sort of CEO fraud. It can be somebody from the accounts department. But if you've got that policy in place and everybody knows why, and we understand why, and the senior leadership are backing that policy, I want you to challenge, I want you to do that. I want you to put those challenges in place. It works, and I guarantee you, it reduces your fraud risk.
GR: Corporate impersonators, are they all really smart or is it sometimes, actually not the sharpest tools in the box?
AD: There is a saying that you don't have to fool a hundred people, you just have to fool one person at the right time. So I don't think it's smart, but sometimes, we don't think rationally, right? So that's the issue. If we are all thinking rationally in a clear brain, a lot of the time, we could properly avoid those sort of scenarios. But no matter what you do, fraud is going to happen. The best we can do is to mitigate as much as possible. Then if there is a structure, if there is a policy, if there is a procedure, if there is a workflow, and we can follow that workflow, that's the best we can do.
GR: The reason I ask is because people listening might go away just terrified and deeply depressed by this. Is there a sort of more positive way of looking at it?
AR: This is about doing good business in a modern age, but dealing with something that's been happening for centuries. There's roaming graffiti about fraud. People say that the wine's been watered down in this sort of thing. It's existed forever. There'll always be people. We have a saying, there will always be fraud, but you have to accept that's the first hurdle to get over. That you will be targeted, but you don't need to have a sleepless night because all fraud is preventable. If you think about it in advance and put in place the measures to stop it from happening, then you can be happy that you've got system integrity and system integrity equals good business.
GR: How can organisations, hundreds of thousands of smaller or medium sized businesses or charities or whatever, protect themselves against this sort of thing, do you think?
AR: It sounds complex, but it's really about assessing your risks and mapping them out. Now we have professional risk assessors who are highly experienced in managing fraud. We're operating in a big corporate environment. But I get your point. If you're running a small business you might not consider yourself to be an expert risk assessor. Years ago there used to be something called Hayes Manual, which was designed for people to fix cars and someone would literally take apart a car and then put it back together again. It was a really helpful manual. In a way, I see fraud control a bit like that. Take apart your process and think about it as an end-to-end process. Where do your vulnerabilities lie? Who's responsible for signing off on invoices? Do you have a policy that says if it's over a thousand pounds, then somebody, a named person needs to sign off on that, or there needs to be a particular process? A lot of the decisions you have to make are about friction. We could probably eliminate fraud if we put in so many controls it was almost impossible, then we wouldn't be able to do business. So for me, it's about breaking down that process. We'd call it a risk assessment. You don't need to call it that, but it's about where do my vulnerabilities align in this process? And what can I put in place just to protect ourselves based on the knowledge we have of where the risks lie? And yes, you're absolutely right. There is now substantial risk from video and audio, but a lot of fraud. There's so much rich picking still just in basic social engineering that as yet we're not seeing that quite at the scale that we may do in future.
AD: Yeah, and I fully agree. Like all the points that you mentioned, one of the things that we have advised organisations to do is a kind of structural payment control. So make sure your payment methodologies are structured right. Some organisations use 48 hours payment methodologies. So if you push a payment, it would hold the money for 24 hours and then you push the money out. Segregation of duties that you mentioned, right? The people who are actually approving are not the ones who are actually making the payment. There's multiple layers of approvals that need doing. You should have a basic incident response plan, which is basically if fraud happens, what are you supposed to do? You should have some sort of technology baseline. So, like some of the technology could help in identifying the patterns that you are seeing. Governance oversight is a big thing that someone from the leadership needs to take ownership of rather than putting it on the accounts team or putting it on some other teams. A pre-agreed relationship with an expert would help so that they can guide you through. A lot of organisations I've seen, like they look into their insurance policy as well to ensure that the insurance policy is covered like AI related fraud, Deepfake related fraud. Because a lot of insurance covers fraud in general, but they would not cover AI related fraud. So that's an important consideration for the business in today's world, I would say.
GR: It's not just money here, right? It's reputation and everything that's at risk and that's kind of as important as anything else, isn't it?
AD: The reason this goes unreported the majority of the time is because of the reputational risk. So there are a few types of risk which are reputational risks. What would your client think, what would your consumer think? Would there be more oversight from regulators as well? Because if you declare, there would be more scrutiny from the regulators as well. Their insurance could go up. So there is a multi-layered risk that they think of, but it's also important that if you declare those, if you come out and if you say this fraud has happened, this could be used as an intelligent source as well, so other organisations could be aware. So you are actually helping the regulators in a way.
GR: Let's assume that the worst has happened and Europe again, not necessarily the world's biggest business, but you are a business that's been the victim of some form of corporate impersonation. What'd you do now?
AD: I think the first thing is to do the immediate financial containment. So you need to contact your bank and you need to freeze the account. You need to segregate the accounts that have been defrauded. That's the first thing which is what Alex was mentioning, and I was saying about structural payment control. To ensure that if this happens, do we have measures to stop this or to segregate these things? The evidence preservation is another thing that we always advise. So it's in a form of legal hold, for example don't delete anything, don't touch anything. Leave it for the specialist team to look into. A lot of advisory firms like ourselves and others, specialise in doing those right? How do you look into the logs? How do you open up your phone, laptop, et cetera, and identify what is the source of fraud? That's a critical thing, structured notification. So you need to ensure the law enforcement or the regulators are aware of this. Fraud has happened. A lot of these things come from a cross-functional command. So what it means is your legal team, accounts team, your crisis communication team and your forensics teams need to work together for a lot of things. Sometimes in a small business all those teams do not exist, but use as many teams as necessary to contain that. The most important thing is the root cause analysis. Why this has happened, and can we look into the gaps to ensure that this does not happen in future. But the biggest thing is the training, right? The team has to be aware that this is a regular occurrence and the gov management need to back this so they, the team can challenge it in the future if this type of fraud will happen. So the training and more training awareness to the business is critical.
GR: We've talked a lot about people impersonating other people to get into our organisation and do things, but what about when our organisation, it's quite often, I guess, charities as a classic case, other people are impersonating our whole organisation. Does that happen a lot? What can we as organisations do to stop it happening?
AD: We can use some of the technologies that are available. Organisations use domain providers. They could ask the domain provider to keep monitoring. So if there are similar domains being created around the similar names, they could flag those up. I think, one of the things that someone was mentioning, like googling your organisation more and more, and a lot of compliance teams do that. So I think it's important to find out what information is out there about your organisation in public media. Have a check, but it's very common, I would say, using technology. You can clone your account, you can clone other websites very easily. You don't have to even pay for those services that are available. So I think keeping your eyes open, seeing what people are saying, et cetera, is critically important.
AR: I completely agree with that. From our point of view, the NHS brand is used quite regularly. You may have had text messages on your phone, particularly during COVID for example, it was very prevalent. But we also see things like benefit fraud or people claiming for things with fake documentation that suggest they've got an illness or something which didn't originate from us. Whilst it might not appear to be a direct loss, look, we're stewards of public money here and this is about fairness as well. So, part of that is about making sure that the systems we use, we communicate clearly to our customers and clients how we go about our business. But it's also about having verification methodology and sound documentation that you've thought through what that looks like and can't easily be manipulated or forged. But this is where technology is creating bigger risks now. It's much easier to create a fake invoice or to create identification that looks quite good. There's lots of opportunities out there to combat that. Lots of emerging technology now as well that we're seeing on the market, which can help make your business more robust in that space.
GR: Well, I think we found a way of ending that on a positive note. Thank you both so much for coming and talking about this subject. I don't think we'll ever get right to the bottom of it, but I hope we've shined a light on it to a certain extent. So thank you both very much for being here, and thank you for listening to this episode of Fraud Matters. In the next episode, we'll be looking at recruitment. If you've enjoyed this podcast, be sure to subscribe on your favourite app so you'll never miss any of our future episodes. Of course, you can go back and listen to previous episodes that you might have missed and please leave us a rating or a review to help us find a wider audience. For more information about the frauds discussed on this podcast and how to deal with them, the Business Fraud Alliance has a stack of resources, so be sure to visit businessfraudalliance.com and links to some of those resources will be in the show notes of this episode. Thank you again for listening and see you next time.