The email looks like it came from the firm’s accountant. It mentions a recent invoice. It uses the right name, the right tone, and a sensible request to change the bank details for next month’s payment.
By the time anyone notices anything is wrong, four figures have already left the company account.
Variations of this scam have hit small businesses repeatedly over the last eighteen months — and in 2026, they are getting more sophisticated, harder to spot, and more frequent.
Why Bedford businesses are now a target
For years, the conventional wisdom held that scammers chased the largest possible payday at the biggest possible companies.
That has shifted. Small and medium-sized businesses are now the primary commercial target for email-based fraud, not collateral damage.
They tend to have fewer internal controls than large firms and process enough day-to-day invoices to make a successful fraud quietly profitable.
The trend is tracked closely by Cybernews cybersecurity experts, whose ongoing reporting on data breaches, business email compromise, and AI-driven scams catalogues exactly the patterns now hitting UK small businesses.
Bedford’s mix of independent retailers, professional service firms, restaurant operators, and the wider business community around the borough fits the profile that criminals are now actively cultivating.
The pattern matters locally because the impact stays local.
A successful business email compromise on a Bedford accountancy practice, plumbing firm, or independent restaurant doesn’t just cost the business — it can hit staff hours, supplier relationships, and customer trust in ways that recover slowly.
There’s already plenty of local business coverage on small business resilience across the borough, and cyber-fraud awareness is increasingly part of the same story.
What today’s scam emails actually look like
The era of obviously fake “Nigerian prince” emails is over.
In 2026, the scam emails arriving in Bedford inboxes are well-written, contextually accurate, and frequently generated by AI tools that draft fluent, persuasive English based on publicly available information about the targeted business.
A 2025 Dojo survey of 2,000 UK workers and executives, covered by Cybernews, found that 56% of UK workers could not reliably distinguish a real email from a phishing scam, that 85% of UK businesses were hit by phishing in 2025, and that 66% of C-suite executives — the group most often confident in their own judgement — failed to identify AI-generated scams when tested.
The table below covers the four scam email patterns most commonly reported by UK small businesses in 2026, the telltale signs that reveal them, and the practical countermeasures for each one.
| Scam pattern | What it looks like | How to spot it | What to do |
| Bank-detail change request | Email apparently from a supplier saying their bank details have changed for the next invoice | The request always arrives shortly before a known payment date; the email domain is one or two letters off the real one | Call the supplier on a number you already have on file — never the one in the email — to confirm |
| Fake invoice from a “known” supplier | An invoice attached to an email referencing a real project or product the business uses | The invoice number doesn’t match your records; the payment account is new; the wording is slightly off | Match the invoice against your accounting system before paying; flag any new account details for manual verification |
| CEO / director impersonation | A message claiming to be from the director, asking for an urgent transfer or for gift cards to be bought for clients | The “director” can’t be reached by phone; the urgency is artificial; the request bypasses normal procedure | Build a rule that no payment request from a director is actioned without a verbal confirmation, regardless of urgency |
| Microsoft 365 / Google Workspace login alert | “Suspicious activity on your account — log in to confirm” with a link to a near-perfect imitation of the real login page | The URL doesn’t match your provider’s domain; the request arrives via email rather than from inside the app | Never log in via the email link; open the app or browser directly and check the account from there |
A useful working assumption in 2026: if an email is asking you to do something with money or with credentials, and there is any time pressure involved, the request itself is the warning sign.
Slow down, verify through a second channel, and accept that scammers actively engineer urgency precisely to short-circuit that pause.
What a Bedford business should do if a scam email gets through
Spotting a scam is the first line. The second is having a clear, agreed playbook for the moments when one slips past.
The minimum useful set-up for any Bedford small business in 2026 is multi-factor authentication on every business email account, a written rule that bank details are only ever changed after a verbal confirmation with the supplier, and quarterly reminders to all staff that AI-generated phishing now sounds entirely native.
The Cybernews coverage of the Dojo research noted that organisations running ongoing awareness training saw click rates on test phishing emails drop from around 5% to as low as 1.5% — a real, measurable difference for the cost of an hour every few months.
If a scam email arrives and the business is unsure, reporting it directly to Action Fraud, the UK’s national reporting centre for fraud and cybercrime, is the right next step.
Action Fraud feeds intelligence to the National Fraud Intelligence Bureau and to local forces, including Bedfordshire Police, who can take direct action when patterns cluster across the area.
Reporting also helps other Bedford businesses, since the patterns scammers use here tend to repeat across the borough within weeks.
None of this requires a Bedford business to become a cybersecurity firm.
It requires a few sensible habits, a willingness to pause when an email pushes for urgency, and an understanding that the scam emails of 2026 don’t look like the scam emails of 2019.
The thousands at stake belong to local businesses, local staff, and local livelihoods. The good news is that the gap between a vulnerable inbox and a well-protected one is largely a matter of attention, not budget.
By Kristina Lozanova
Advertising feature with Cyber News


