Cyber security

What is Friday afternoon fraud, and how do you stop it?

It is payment diversion fraud, timed for late on a Friday when a property completion is due and everyone wants to be out the door. The attacker has usually been reading the email thread for weeks. The control that stops it is a verbal check against a phone number you already held, never one taken from the email.

Friday afternoon fraud is payment diversion fraud with the timing chosen deliberately. A completion is due, funds are about to move, it is late in the week, and the person reading the email is tired and has one foot out the door. An email arrives saying the bank details have changed. The money goes to the attacker.

The name is not a coincidence. Conveyancing has a predictable rhythm, large sums, a fixed deadline, and a moment every week when everybody is in a hurry.

Why does it work so well?

Because by the time the email arrives, the attacker is not guessing.

They have usually been reading the thread for weeks, from inside a mailbox at one end of it or the other. They know the property, the price, the names, the tone people use with each other. They know the completion date. They know that at 2:47pm on a Friday, a request that fits the story gets processed rather than questioned.

That is a very different thing from the phishing email everyone pictures. There is no spelling mistake, no odd address, no urgency that feels invented. The urgency is real, because the deadline is real.

How do they get into the email thread?

Almost always a password.

Someone signs into a page that looks exactly like the Microsoft login they use every day, having followed a link in a message about an expired password or a shared document. The password goes straight to the attacker. If multi-factor authentication is not switched on, that is the entire attack.

The next step is a mailbox rule. Incoming messages containing certain words get moved to a folder nobody looks at, or marked as read, or forwarded outside the business. The account owner carries on with their day and sees nothing unusual, because the interesting mail is being filtered out before they reach it.

Two things follow from that. First, multi-factor authentication on every account is the control that prevents most of this, which is also why it is now a hard requirement in Cyber Essentials. Second, somebody needs to be watching for mailbox rules being created, because that is the moment a compromise becomes visible if anybody is looking.

What actually stops the fraud?

One control does most of the work, and it is not technical.

Bank details never change by email. Ever. If they appear to have changed, somebody rings the other side on a number they already held, from the file or from the firm’s website, never a number in the email or the letterhead attached to it. They speak to a person they can identify, and they read the details back rather than asking for confirmation of details that were sent to them.

That last distinction matters more than it looks. "Can you confirm the account ends 4471" invites a yes. "What are the account details" makes the other person produce them.

Around that:

  • A written rule that says the call happens every time, including the times when it feels unnecessary.
  • Sending your own bank details once, at the start, and telling the client in writing that they will never change.
  • A hard stop on any request that arrives with new details and a reason to hurry.
  • Multi-factor authentication and mailbox rule monitoring on both sides of the transaction, so the compromise is less likely in the first place.
  • Making it clearly acceptable for a junior member of staff to hold up a completion over this. That is a management decision, not an IT one.

Why is the culture the hard part?

Because the control works precisely when it is most inconvenient.

Everyone agrees with the policy on a Tuesday morning. The test is a Friday at ten to four with the client ringing to ask why the money has not moved, the other firm not picking up, and a fee earner who can see the details in front of them and cannot see why anyone is being difficult.

That is the moment the process either holds or does not, and holding it is a matter of training, then training again, and then backing up whoever holds the line when somebody complains. If the person who slows a completion down gets grief for it, you have taught your team what you actually want.

I have seen this go wrong too many times, and it is never because a firm did not know about it. It is because the process existed on paper and nobody had rehearsed the awkward version of it.

What should a firm do this week?

  1. Ask, out loud, in a room: what do we actually do when bank details change? Compare the answers. They will not match.
  2. Check multi-factor authentication is on for every single account, including the ones that were exempted for convenience.
  3. Check whether anybody would notice a forwarding rule being created on a mailbox today.
  4. Agree the wording of the call back, so it is the same every time and nobody has to improvise.
  5. Tell the team plainly that stopping a payment to make a phone call is always the right answer, and that nobody will be criticised for it.

None of that needs a budget. Points two and three need somebody with access to your Microsoft tenant, and if that is us or somebody else, it is an afternoon.

Where we come into it

We look after law firms, where a single diverted payment would be the worst week the business has had, so the email security, the authentication and the monitoring on that side are part of what we do rather than an add on. What that looks like for a practice is on the law firms page. What is included at each level is on the pricing page, and the technical detail is on the cyber security page.

If you want somebody to check what would happen in your firm on a Friday afternoon, get in touch and ask. It is a short conversation.

Questions

The questions people ask us about this

Who carries the loss if the money goes to the wrong account?

It depends on the facts and it is fought over case by case, which is exactly why nobody wants to be in that argument. Assume it will be expensive, slow and public regardless of how it ends.

We are not lawyers and this is not legal advice. Your professional indemnity insurer and your regulator are the people to talk to about where liability sits.

Is a warning line in our email footer enough?

No. If an attacker is inside the thread, they can remove it. Footer warnings are worth having because they set an expectation with clients, and they are not a control.

How did they get into the email in the first place?

Usually a password entered on a convincing fake login page, then a mailbox rule that hides the evidence. Multi-factor authentication on every account is the single control that does most to prevent it.

Read next

Cyber Essentials

We certified last year. Will we pass Cyber Essentials renewal?

Probably not, not without some work first. Assessment accounts created on or after 27 April 2026 are marked against Requirements for IT Infrastructure v3.3, and multi-factor authentication is now mandatory on every cloud service that offers it. Miss it on one service and you fail the whole assessment.

Read this

All posts

Next step

Talk to Tom, not a call queue

Ring the number below and you get Tom, the owner. No hold music, and no ticket reference before anyone has heard the problem. If we’re not the right fit, we’ll tell you that too.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.