In this guide
A message asking a volunteer treasurer to change a supplier's bank details may arrive at the busiest moment of the week. It may use familiar language, refer to a real invoice or appear to come from an established contact. Build a verification process that works even when the message looks convincing.
The aim is not to make every member an expert at spotting fraud. It is to create a reliable pause before sensitive actions and an easy way to ask for help. The NCSC phishing guidance describes a layered approach; awareness alone is not a complete defence.
Agree a payment-change rule
A proposed rule is: “We verify new or changed bank details through a trusted, independent contact route before using them. The person who checks records how they verified the change. Payment approval follows our usual authorised process.” Have the appropriate decision-makers adopt and explain the rule.
Use a telephone number or other route already held in verified supplier records. Do not rely on a number supplied in the message asking for the change. Replying to that same email thread does not provide independent confirmation if the mailbox is compromised.
For an illustrative community shop, an invoice email announces a new bank account and asks for urgent settlement. The treasurer pauses the payment, calls the supplier using its existing contact record, and asks the established contact to confirm the change. A second authorised person then checks the recorded verification and payment details. If verification fails, the payment remains on hold and the issue is escalated.
Agree how exceptions are handled before an urgent request arrives. The process should still work if the usual approver is absent. Urgency, seniority or familiarity should not silently remove the control.
Make message checking practical
- Open important services through a saved bookmark or a known address when a message asks you to sign in.
- Be cautious with unexpected attachments, QR codes and requests to install software.
- Verify unusual requests for member lists, payroll information or account resets through an established route.
- Report unexpected sign-in prompts rather than repeatedly approving them.
- Ask for a second check when the request changes normal payment or access arrangements.
Spelling and visual appearance can offer clues, but well-written messages can still be fraudulent. A familiar display name is not proof of identity. Keep your process focused on what the sender wants you to do and how that action is authorised.
Use strong authentication and review mailbox forwarding, delegation and connected apps when investigating suspicious account activity. A changed password may be only one part of the response.
Create a reporting route people trust
Publish a simple instruction such as: “If a message seems wrong, contact the duty coordinator using the known number or report it through the agreed support route. If you already clicked or replied, tell us what happened now.” Keep the route usable if email is the affected system.
Thank people for reporting promptly. Record what happened without turning a mistake into a public example of someone's supposed carelessness. A quick report gives the co-op a better chance to contain harm, while blame can encourage delay.
The government's reporting guidance directs suspicious emails to report@phishing.gov.uk. External reporting does not replace your internal response if a payment, account or confidential record may already be affected.
Respond if money or access may be affected
- Tell the responsible lead immediately through a trusted route.
- If money was sent or payment details exposed, contact the bank promptly using its verified fraud contact route.
- Preserve the original message and a short timeline; avoid broadly forwarding sensitive material.
- Ask technical support to assess account access, active sessions and connected services where relevant.
- Use the incident first-steps guide to coordinate containment and assess any personal-data implications.
Practise with a fictional payment-change request at a committee or worker meeting. Check that somebody can find the verified supplier contact and that an absent approver does not stall the procedure indefinitely.
Use the technology health check to record the practical controls your co-op still needs to put in place.