Read the full sender address, and never treat an emailed change of bank details as genuine on its own. For any instruction that moves money, confirm it by telephone on a number you already hold before you act. These two habits prevent the great majority of payment fraud aimed at families and their advisers.
The rest of this article explains how the fraud works, and how to verify an instruction with confidence.
Why cross-border wealth is a target
Families with assets in more than one country move money in ways that fraudsters understand well: a distribution, a capital call, the completion of a purchase, a transfer between structures. These payments are often large, time-sensitive, and arranged by email between the family, its advisers and its trust company, whether for a distribution, a purchase, or a change to a wealth structure. That combination is precisely what an impersonator looks for.
The method does not require access to any account. The fraudster sends an email that appears to come from a trusted party, presents new or amended bank details, and relies on the pressure of a deadline. The scale is considerable. In 2024 the U.S. Federal Bureau of Investigation recorded losses of USD 2.77 billion from this one fraud. That came from 21,442 reported complaints.
How impersonation is done
Almost every attempt relies on the sender address looking right at a glance. There are three common forms, and each is visible to a reader who checks the address in full.
| Method | What it looks like | How to recognise it |
|---|---|---|
| Look-alike domain | An address on a domain that resembles the genuine one, with a letter added, a hyphen removed or a different ending | Compare the domain against the one you already hold, character by character |
| Subdomain in front | The genuine name with a word placed before it, so the real name appears not to be the final part of the address | The genuine domain is the part immediately before the final dot and the ending; anything ahead of it is controlled by the sender |
| Display name | A familiar name shown by the mail programme, concealing a different address underneath | Reveal the full address behind the name, which on a mobile device is often hidden from view |
The display name is the first thing most mail programmes show, and it proves nothing. The address after the at sign is what matters.
What a genuine firm will never do
Certain requests are fraudulent whatever the sender address appears to be. A reputable trust company will never:
- Notify a client of a change to its bank account details by email alone.
- Request a password, a one-time code, or the full details of a payment card.
- Issue an invoice or payment instruction from an address outside its own domain.
- Press a client to transfer funds before there has been an opportunity to verify the request by telephone.
Where a message does any of these, the correct response is to stop. The urgency is part of the method, not a reason to hurry.
Verifying an instruction before you act
For any instruction that moves money, apply a single check that an impersonator cannot pass. Telephone the firm, or the adviser said to have sent the request, on a number already in your possession, taken from a previous engagement or the firm's official website. Confirm the instruction in conversation. A number printed in the email itself should never be used for this purpose, as it can be substituted along with the bank details.
This discipline costs a few minutes. A payment sent to a fraudulent account is difficult to recover, and the prospect of recovery falls sharply with each day that passes before the alarm is raised.
What Signature Trust does on its side
The protection of client payments is shared between the firm and those it serves. Signature Trust publishes its official domain and contact details on its security notice, and maintains email authentication controls that make its own domain more difficult to imitate. As a trust company holding Trust Licence LT0056 under the Labuan Financial Services and Securities Act 2010, the firm treats payment security as part of its compliance function, not a matter left to chance.
None of this removes the value of the check on the client's side. The most reliable defence against a redirected payment remains a recipient who reads the address in full and confirms the instruction by telephone before any money moves.
Frequently Asked Questions
How can I tell if an email is genuinely from my trust company?
Read the full sender address, including every character after the at sign. A genuine firm sends only from its own domain, with no alternative spellings and no partner domains. The display name your mail programme shows is not evidence, because it is typed in by the sender. If the address adds a letter, drops a hyphen or ends differently from the one you know, treat the message as fraudulent until you have confirmed it by telephone.
What is business email compromise?
Business email compromise is a fraud in which someone sends an email that appears to come from a trusted party, such as a trust company, an adviser or a counterparty, and asks for a payment to be sent or redirected. The U.S. Federal Bureau of Investigation recorded losses of USD 2.77 billion from this fraud in 2024. It relies on a convincing message and tight timing rather than on breaking into any system.
Will a trust company ever change its bank details by email?
No. A genuine firm does not notify a client of a change to its bank account details by email alone, and it does not ask for passwords, one-time codes or full payment card details by email. Any message that does either should be verified by telephone, on a number already held, before any funds are moved.
What should I do before releasing a large payment?
Confirm the instruction through a second channel. Telephone the firm or your adviser on a number you already hold, from a previous engagement or the official website, and confirm the request in person. Do not rely on the number printed in the email, because it can be part of the fraud. A short verification call is inexpensive; a redirected payment rarely returns.
How do I report a suspicious email that impersonates Signature Trust?
Do not reply to it or act on it. Forward the message to the firm through the contact details published on the Signature Trust website, and delete it. If a payment has already been made or a reply already sent, telephone the firm without delay, because a transfer stopped early stands a better chance of recovery.