Fraudsters like sole traders for structural reasons, not personal ones. You authorise your own payments, there is no second signature, nobody in accounts payable is going to query a changed bank detail, and you are usually doing three jobs at once. The scams themselves are rarely sophisticated. They run on urgency and a single moment of inattention.

What follows is the handful that actually target one-person businesses, the specific tell for each, and — the part most sole traders do not know — the legal right to be reimbursed that has applied to bank transfer fraud since October 2024.

Start here. If you have already sent money to a fraudster by bank transfer, stop reading and phone your bank now. Then read the reimbursement section below: you probably have a claim, and the clock on it is 13 months from the date the payment was sent.

You are almost certainly covered by the reimbursement rules

Since 7 October 2024 UK payment providers have been required to reimburse victims of authorised push payment fraud — the kind where you are tricked into sending the money yourself, rather than having it taken from you. This is the single most important thing on this page, because most sole traders assume the rules only protect consumers.

They do not. The rules cover consumers, charities with annual income under £1 million, and micro-enterprises. A micro-enterprise is a business employing fewer than ten people with an annual turnover and/or balance sheet total not exceeding €2 million. Virtually every sole trader in the country sits inside that definition.

The mechanics:

  • Maximum reimbursement: £85,000 per claim.
  • The payment must have been sent on or after 7 October 2024, by Faster Payments or CHAPS, within the UK.
  • You have 13 months from the date the payment was sent to make a claim.
  • Your provider may apply an excess of up to £100 per claim, deducted from what you get back. Not every provider does.
  • The cost is split 50/50 between the sending and the receiving provider, which is what gives receiving banks a reason to police the accounts fraudsters open.

The exception is gross negligence. If you ignored a specific, clear warning from your bank, or failed to act honestly and promptly once you suspected fraud, reimbursement can be refused. Ordinary carelessness is not gross negligence — the bar is genuinely high — but it is a reason to report immediately rather than spend two days hoping the money reappears.

Invoice and mandate fraud: the one that targets businesses

An email arrives, apparently from a supplier you actually use, on a thread you actually recognise, saying their bank details have changed. Sometimes the fraudster has compromised the supplier's email account, so the message is genuinely from that address. Pay it and the money is gone within minutes.

This is the scam most likely to cost a sole trader a four-figure sum in one go, and it has one reliable defence.

The rule, and it has no exceptions. Never change a supplier's payment details on the basis of an email, a letter, or a phone call you received. Verify by ringing the supplier on a number you already had — from a previous invoice, their website, or your own contacts — never a number contained in the message telling you the details changed. If they cannot be reached, the payment waits. A supplier has never once minded being called to confirm their own bank details.

Check the Confirmation of Payee result too. When you set up a new payee, your bank checks the name you typed against the name on the receiving account and tells you whether it matches. A "close match" or "no match" result on a supplier you have paid for years is not a spelling quirk to click through — it is the warning the reimbursement rules expect you to have read.

Worked example: what a redirected invoice actually costs

Illustrative figures. A sole trader electrician receives an email from a regular wholesaler on 12 May 2026 saying their account has moved to a new bank.
  • Invoice paid to the new details by Faster Payment: £4,800
  • Confirmation of Payee returned "no match" and was clicked through
  • Fraud noticed on 19 May, when the real wholesaler chases the unpaid invoice
  • Reported to the bank the same day, and to the police via the fraud reporting service
  • Reimbursement claim: £4,800, less a possible £100 excess = £4,700
  • Deadline for that claim: 12 June 2027 — 13 months from the date the payment was sent
  • The wholesaler's genuine £4,800 invoice is still owed, because paying the wrong account does not discharge the debt
That last line is the one people forget. Until the claim pays out, this sole trader is £9,600 out of pocket on a £4,800 bill. The "no match" warning is the moment the whole thing could have cost nothing.

Fake HMRC messages

Two versions circulate constantly: the friendly one offering a tax refund if you click a link, and the aggressive one saying you owe money and face arrest unless you pay immediately. Both are fake, and HMRC publishes exactly why.

  • HMRC will never notify you of a tax rebate, or ask for personal or payment information, by text message. Not sometimes. Never.
  • HMRC only emails about a rebate, or asks for personal or payment details, from an address ending hmrc.gov.uk. Anything else is forged.
  • HMRC never uses social media to offer a rebate or request personal or financial information.
  • Genuine tax matters appear in your Government Gateway account or arrive by post. If a message worries you, close it and log in to your HMRC account directly.

Reporting takes under a minute and is worth doing:

  • Suspicious emails: forward to phishing@hmrc.gov.uk, then delete.
  • Suspicious texts: forward to 60599 (charged at your network rate).
  • Fake HMRC social media accounts: email branddefence@hmrc.gov.uk.
  • Suspicious phone calls: use HMRC's online "Report a suspicious HMRC phone call" service.

The pressure to pay right now is the tell in every version. Real tax debt has a process, deadlines you can look up, and a payment plan you can ask for. Our guide to sole trader key tax dates lists the dates HMRC actually works to, which makes an invented deadline easy to spot.

Phishing for your logins

An email that looks like your bank, your payment processor, or your accounting software, asking you to confirm your details through a link. The link goes to a convincing replica that harvests whatever you type. Modern versions are good enough that spotting the fake on appearance alone is not a strategy.

Two habits remove almost all of the risk:

  • Never log in through a link in an email. Open the app, or type the address yourself. This costs ten seconds and defeats the entire category.
  • Turn on two-factor authentication everywhere it is offered — bank, email, accounting software, domain registrar. Your email account matters most, because whoever controls it can reset everything else. Prefer an authenticator app over SMS codes where you have the choice, since SIM swapping defeats text-message codes.

The overpayment reversal

A new customer overpays — £1,500 for a £500 job — apologises for the mistake, and asks you to refund the difference quickly. You send £1,000 back. Days later the original £1,500 is reversed, because it came from a stolen card or a compromised account. You are down £1,000 and the job.

The defence is patience. Refund nothing until the original payment is genuinely settled and irreversible, and treat any urgency about a refund as the warning it is. A legitimate customer who overpaid by accident will wait a week.

The other one aimed squarely at sole traders

Fake registration and renewal demands. Official-looking letters or emails demanding payment for something that sounds statutory — a business register listing, a data protection registration, a trademark renewal — usually with a deadline and a bank transfer. Some are outright frauds; others are technically real services sold at many times their worth, dressed up to look compulsory.

The check is simple: nothing genuinely statutory is ever collected by an unsolicited email demanding a bank transfer. If you register with the ICO, you do it on the ICO's own website at the ICO's own price. Our post on data protection for sole traders covers when registration is actually required.

Seven habits that stop most of it

  1. Two-factor authentication on your email first, then your bank, then everything else.
  2. Never change payment details without a phone call to a number you already had.
  3. Read the Confirmation of Payee result rather than clicking past it.
  4. Never log in via a link in a message about money.
  5. Keep business banking separate so unusual activity stands out against a predictable pattern. Our page on business banking for sole traders covers the options.
  6. Reconcile weekly, not annually. A £4,800 misdirected payment noticed in seven days is a claim; noticed in fourteen months it is outside the 13-month window. Our guide to sole trader bookkeeping covers the weekly routine.
  7. Pause when something feels off. Fraud depends entirely on you not pausing. Ring your bank, or ring us.

If it has already happened

  1. Phone your bank immediately and ask them to attempt recall of the payment. Speed is the only thing that affects whether the money is still there.
  2. Report it to the police fraud reporting service and keep the reference number.
  3. Make the reimbursement claim in writing to your payment provider, within 13 months of the payment being sent.
  4. Change the passwords on your email and banking, from a device you are confident is clean.
  5. Tell your accountant. The loss, the recovery and any excess all need recording correctly, and a recovered amount is treated differently from a written-off one.

A tidy business is a harder target than a chaotic one, mostly because you notice things faster. If you would like someone else looking at the numbers each month, get started here.