The rise of AI fraud and why Direct Debit is still resilient

22.05.2026

9 mins

Table of contents

The rise of AI fraud and why Direct Debit is still resilient 

Last updated: 21st May 2026

 

A Direct Debit scam made headlines in February 2026, when the National Trading Standards (NTS) reported that AI-generated voice clones were being used to simulate consent and set up Direct Debits – without victims ever realising.

 

“Criminals are using AI to trick legitimate systems into processing fraudulent payments. This is no longer just a nuisance – it’s a coordinated, sophisticated operation targeting some of the most situationally vulnerable consumers in society.” – Louise Baxter MBE, Head of the National Trading Standards Scams Team

 

At first glance, stories like this raise questions about the security of Direct Debit. If fraudsters can exploit the system – do consumers and businesses need to worry?

While AI is increasing the scale and sophistication of fraud attempts, Direct Debit remains one of the most protected payment methods available – largely because of the safeguards built into it.

In this article, we explore how AI is reshaping Direct Debit fraud and why, despite the emerging threats, the model is more resilient than you might think.

We cover:

  • The Direct Debit phone scam happening today – how AI voice cloning is being used to commit Direct Debit fraud – and what the warning signs look like
  • The role of the Direct Debit Guarantee and why this matters for Direct Debit fraud protection
  • What businesses can do to reduce exposure and protect their customers, as AI fraud gets more convincing than ever

 

 

A new kind of threat: AI voice cloning and unauthorised Direct Debits

 

Over a third (35%) of UK businesses were targeted by AI-related fraud in early 2025 (Experian)

 

In February 2026, National Trading Standards’ findings marked an escalation in payment fraud tactics. Criminals were using AI-generated voice clones to simulate customer consent for Direct Debits – and they’d been doing it at scale.

The operation worked in stages:

  1. A ‘lifestyle survey’ phone call: the victim answered questions about their daily life, health and finances, without realising the real purpose was data harvesting. 
  2. That personal and financial information was used to construct an AI-generated voice clone that mimicked the victim’s voice convincingly enough to authorise payment agreements with banks and financial providers.

For many victims, often older adults, the fraud went undetected at first. 

The payments appeared on statements, but without any memory of agreeing to them, many didn’t connect the dots quickly.

“Voice cloning takes scam calls to a sinister new level, making it even harder for legitimate businesses and consumers to distinguish real interactions from fraudulent ones. Trading Standards teams across the UK are working tirelessly to disrupt these operations, but we need the public to stay alert.” – John Herriman, Chief Executive, Chartered Trading Standards Institute (CTSI)

 

 

AI fraud is growing fast and older adults are most at risk

The NTS findings don’t sit in isolation. They form part of a broader pattern of AI-enabled financial fraud, where advances in voice synthesis and data harvesting are making scams more scalable and convincing.

A key factor of the scam was behavioural. Older people were more likely to engage in a seemingly innocent ‘lifestyle’ survey over the phone. It worked because it mirrored legitimate market research, making it easy for fraudsters to gather the personal data they needed.

For businesses collecting Direct Debits – especially those serving older customers in sectors such as health and leisure, care, utilities or local services – this matters. Understanding who is being targeted and how the scams operate is the first step in protecting both your customers and your business.

When stories like this break, the instinct is often to question the payment method itself. Is Direct Debit safe? Should businesses be considering alternatives?

In practice, the answer is reassuring. Direct Debit, governed by Bacs Payment Schemes Limited and backed by the Direct Debit Guarantee, has consumer protections that are genuinely robust – safeguards that many alternative payment methods can’t match. 

What these developments expose isn’t a weakness in Direct Debit itself, but a shift in how fraudsters are trying to bypass the front-end of customer authorisation.

 

 

Direct Debit has real structural protections

 

The Direct Debit Guarantee

Every UK Direct Debit is backed by the Direct Debit Guarantee, which gives consumers the right to a full and immediate refund from their bank if a payment is taken in error or without proper authorisation. This applies regardless of whether the business collecting acted in good faith.

This is very different to  bank transfers, which are much harder to reverse.

 

Advance notice: a fraud-detection window built into the process

The Bacs Scheme Rules require businesses to give customers advance notice before any Direct Debit is collected – a minimum of 10 working days under standard rules. 

For consumers who are alert to their finances, this is a natural fraud-detection moment. An unexpected advance notice for a Direct Debit they don’t recognise is a flag and an opportunity to act before money leaves their account.

 

Mandate validation: the rules are getting stricter

Updated Bacs rules now require not just sort code and account number verification, but account name matching. This tightens the validation that sits at the start of every new Direct Debit setup, making it harder for fraudulently obtained details to pass through undetected.

 

 

What can businesses do to protect themselves and their customers?

1. Work with a specialist Direct Debit provider

A generalist provider may offer Direct Debit as one of many services. A specialist – one whose entire focus is DD compliance, validation and ongoing collections like London & Zurich – brings a different level of scrutiny and an alert eye for irregularities. 

We’re on top of scheme rule changes, and more reachable when something doesn’t look right.

 

2. Apply rigorous mandate validation

Don’t treat the new mandate setup as a formality. Ensure your process includes strong account validation, including name matching under the updated Bacs rules, and that unusual or unexpected new mandates are flagged before collections begin.

 

3. Communicate clearly and consistently with customers

Your advance notice communications should be recognisable, clear and consistent. Customers who know what your communications look like are better placed to spot something anomalous. Make it easy for them to contact you if something doesn’t look right.

 

4. Train your team on fraud patterns

Ensure anyone at your business who is handling payment setup, customer service or dispute management understands how these fraud schemes operate. Knowing what a suspicious setup request looks like, and having a clear escalation path, can prevent a problem before it becomes a claim.

 

5. Manage indemnity claims promptly and properly

Under the Direct Debit Guarantee, customers can raise indemnity claims through their bank. If your business receives one, respond promptly and with your full records of mandate authorisation and advance notice. Good documentation is your best defence against both fraud and false claims.

Strengthening the human layer: customer awareness and behaviour

As fraud tactics evolve, customer awareness becomes a critical line of defence. Businesses can guide their customers on how to recognise and respond to suspicious activity, with helpful advice, such as:

  • Be cautious of unexpected surveys. What appears to be harmless ‘market research’ may be an attempt to gather personal data or voice samples for fraud.
    • Pause before acting on urgent requests.Customers should tread carefully when faced with any request for immediate payment or sensitive information, even if the caller sounds convincing or familiar.
  • Verify through trusted channels. If something feels unusual, the safest response is to end the call and contact the real organisation directly using a known, verified number.

Clear, repeated messaging from business to customer in these areas can reduce the chances of people falling prey to scams.

 

 

Direct Debit fraud: your questions answered

Can people be scammed by Direct Debit?

In some cases, people can be scammed via a Direct Debit payment and it’s important to understand how. Legitimate Direct Debits can only be set up with customer authorisation. The fraud risk comes when criminals obtain or simulate that authorisation illegally, for example, through voice cloning, identity theft or deceptive sign-up processes. 

Can a Direct Debit be set up fraudulently?

Direct Debit fraud can be attempted and the NTS evidence shows it has happened in some instances via AI voice cloning and stolen personal data.

However, the Bacs Scheme Rules set strict validation requirements for new mandates, and updated 2024 rules strengthened account name verification. A specialist provider applying rigorous checks significantly reduces the risk of Direct Debit fraud.

How does Direct Debit fraud occur?

The most common methods of Direct Debit fraud involve identity theft – where stolen personal and banking details are used to set up mandates in someone’s name – and, increasingly, AI-assisted authorisation fraud.

 

 

A payments partner that takes Direct Debit fraud seriously

At London & Zurich, Direct Debit is what we do best. That means we stay ahead of scheme rule changes, apply rigorous mandate validation and bring 30 years of specialist knowledge to every client’s payment operation.

We also pick up the phone. If something doesn’t look right – a setup request that seems unusual, a claim you’ve received, a customer situation you’re not sure how to handle – you can always speak to a real person.

Fraud is evolving. The right partner makes sure your response is too.

See how we can help protect your payment operation

 

 

Sources & further reading

  1. National Trading Standards – Phone scams take sinister twist as victims’ voices cloned (February 2026)
  2. Censuswide / NTS – UK Consumer Scam Calls Research (October 2025, 2001)
  3. MRS & ESOMAR compliant. Commissioned by National Trading Standards.
  4. Yahoo Finance UK – Criminals using AI to clone voices and set up Direct Debits (February 2026)
  5. A Beginner’s Guide to Direct Debit Mandates
  6. Enhancing Payment Security with Direct Debit Payment Solutions
  7. Direct Debit security and resilience hub
  8. Direct Debit for care homes