Fraud is getting in through your inbox. Here is how to shut the door
The amount stolen through hacked email and social media accounts has risen by 417% in a year, according to figures published this week by City of London Police.
Losses climbed to £6.3 million in 2025/26, up from £1.2 million the year before, with reports up 34%. Account hacking remains the most reported cyber-crime in the UK. The figures were released earlier this week to mark the start of Cybersecurity Awareness Month.
Chief Superintendent Amanda Wolf described the problem simply: “What starts with one compromised account can quickly impact family, friends and colleagues as fraudsters exploit trusted relationships.”
That last phrase is the one scaffolding businesses should sit with, because trusted relationships are exactly what this industry runs on. A request to change bank details does not arrive from a stranger. It arrives from a supplier you have worked with for years, from an email address you recognise, in a thread you have been part of all week.
Why scaffolding is exposed
NASC published new guidance earlier this year, CG28 Fraud Awareness and Prevention for Scaffolding Contractors and Suppliers, setting out where the risks sit across the supply chain.
Its first message is the one that tends to surprise people: fraud can affect every part of the scaffolding supply chain and the damage is not only financial, it can create safety risks and reputational damage too.
That makes sense once you think about what a scaffolding business handles; supplier payments and bank details, agency timesheets and site attendances, operative qualifications and card checks, equipment going out and coming back, a motor fleet on the road every day.
Five messages from CG28
The guidance whittles down to five main points:
- Fraud can affect every part of the scaffolding supply chain and can lead to financial loss, safety risks and reputational damage.
- Verify before you trust. Always check supplier details, payment requests, qualifications and bank account changes independently.
- Strong controls prevent fraud. Use approved suppliers, purchase orders, segregation of duties and regular audits.
- Cyber awareness is essential. Protect systems with strong passwords, multi-factor authentication, software updates and staff training.
- Report concerns early. Encourage a culture of vigilance, investigate suspicious activity promptly and report serious fraud to the appropriate authorities.
A practical checklist
CG28 translates into things you can do this week:
- Verify all bank detail changes by phone, using trusted contact details rather than the ones in the email.
- Use two-person approval for new suppliers and high-value payments.
- Match purchase orders, delivery notes and invoices before paying.
- Reconcile timesheets, site attendance, inductions and agency invoices.
- Use dashcams, vehicle trackers, photographs and bump cards to defend suspicious motor fleet claims.
- Record equipment issue and return and audit stock regularly.
- Train staff to challenge urgent or unusual payment requests.
- Consider fidelity guarantee and cyber insurance as additional protection, while keeping prevention controls in place.
- Report suspected fraud promptly to your bank, the police or Report Fraud at reportfraud.police.uk
CG28 Fraud Awareness and Prevention for Scaffolding Contractors and Suppliers is free to NASC members and available to purchase for non-members here: https://nasc.org.uk/product/cg28-26-fraud-awareness-and-prevention-for-scaffolding-contractors-digital-download-pdf-format.html