Publication date
Jump straight to
- What is AI-enabled financial fraud?
- How is AI changing payment fraud?
- Which common payment fraud attacks can AI strengthen?
- What new AI-enabled fraud attacks should finance teams know about?
- Which familiar fraud checks no longer work on their own?
- How can businesses prevent AI-enabled payment fraud?
- What should you do if you suspect payment fraud?
- How can a payment platform support fraud prevention?
Share this article
A supplier emails your accounts payable team to request a change to its payment details. A few minutes later, your CFO calls to confirm the request. The email looks genuine. The voice sounds familiar. The payment details appear correct. But the entire exchange could be part of a carefully planned fraud attempt.
AI has not replaced traditional payment fraud. Instead, it has made familiar attacks more convincing, more personalised and easier to scale. Fraudsters can now generate convincing emails, imitate writing styles, clone websites and create realistic videos and voice recordings with relatively little effort.
The threat affects businesses across Europe and the UK. According to a joint report from the European Central Bank and European Banking Authority, payment fraud across the European Economic Area reached €4.2 billion in 2024, up from €3.5 billion in 2023. In the UK, UK Finance reported £1.28 billion stolen through payment fraud in 2025, including £75.6 million in business losses from authorised push payment fraud.
So, how can you protect your business?
The short answer is that you need to verify the payment instruction, beneficiary and approval process through controls that do not rely on appearances.
What is AI-enabled financial fraud?
AI-enabled payment fraud occurs when fraudsters use artificial intelligence to make a fraudulent payment request more convincing, targeted or scalable.
Phishing is often the first step. It uses fake emails, websites, messages or calls to trick people into sharing information or taking an action. AI can make these attempts harder to spot by improving their wording, design and timing.
In business payments, this might involve:
- Impersonating a supplier or senior executive
- Creating a realistic fake invoice
- Stealing login details through a personalised phishing message
- Cloning a person’s voice to authorise a payment
- Combining email, phone and video messages to create a convincing false scenario
How is AI changing payment fraud?
AI gives fraudsters more ways to make a payment request look genuine:
- More convincing communication: AI tools can produce polished emails without the spelling and grammar errors that once raised suspicion. A fraudster can even imitate the tone and vocabulary of a supplier, colleague or executive.
- More personalisation: They can use information from company websites, professional networks and social media to create realistic messages. They may know the names of your suppliers, the countries you operate in or the approximate timing of a payment run.
- More scale: Fraudsters no longer need to write every message manually. AI allows them to create and adapt large numbers of targeted communications quickly.
- More channels: A payment scam may no longer start and finish with an email. The fraudster may send an email, follow up with a text message and then make a phone call using a cloned voice. They can even create a convincing login page. Each interaction reinforces the others.
Which common payment fraud attacks can AI strengthen?
AI has made several established fraud methods more difficult to detect.
|
Fraud type |
How it works |
How AI strengthens it |
|
Business email compromise (BEC) |
An attacker impersonates or compromises a trusted business contact to influence a payment or obtain sensitive data |
AI creates convincing messages and imitates a person’s writing style |
|
Payment diversion fraud |
A legitimate payment goes to a fraudulent beneficiary after someone changes the payment details |
AI creates plausible explanations for the change and imitates supplier communications |
|
Fake or altered invoices |
A fraudster submits a false invoice or changes the beneficiary details on a genuine invoice |
AI can replicate invoice formats and produce realistic supporting documents |
|
Credential phishing |
An attacker tricks an employee into sharing login details |
AI creates personalised messages that look relevant to the employee’s role |
|
Account takeover |
A fraudster gains access to an email or payment account and uses genuine conversations to continue the fraud |
AI helps identify valuable conversations and generate believable replies |
Business email compromise
Business email compromise (BEC) targets business email accounts and payment workflows. A fraudster may impersonate a supplier, CEO, CFO, colleague or lawyer and request an urgent transfer.
The European Banking Authority describes CEO fraud as a form of “manipulation of the payer”, where someone impersonates a senior executive and persuades an employee to initiate and authorise a payment.
The fraudster may use a lookalike email address, compromise a genuine account or reply to an existing email exchange. If they gain access to a supplier’s account, they can send the payment request from the real email address, making it appear legitimate.
Payment diversion fraud
Payment diversion fraud redirects a genuine payment to an account controlled by a fraudster.
For example, a fraudster may contact your accounts payable team and claim that a supplier has changed its bank details because of a merger, a new regional office or a banking issue. The request may include a convincing invoice, what appears to be the supplier’s signature and accurate information about your relationship with the supplier. The danger is that the payment itself may look completely normal. Only the beneficiary details have changed.
AI can make the request even harder to question. Fraudsters can use previous invoices or a compromised email account to copy a supplier’s tone, create convincing documents and follow up through another channel. They only need to persuade someone to accept the change.
Read our guide to payment diversion fraud.
Fake and altered invoices
Fake invoice fraud involves submitting an invoice for goods or services that your business never ordered. In other cases, fraudsters alter a genuine invoice and replace the supplier’s payment details.
AI can help fraudsters copy logos, formatting and language. It can also generate realistic follow-up messages that explain why the amount, currency or payment account has changed.
A professional-looking invoice does not confirm that the payment should go ahead. Your team needs to check the underlying purchase, supplier relationship and beneficiary.
Credential phishing and account takeover
A phishing attack may ask an employee to:
- Confirm their login details
- Review an invoice
- Track a payment
- Open a shared document
- Move a conversation to a new platform
- Approve a multi-factor authentication request
If the employee enters their details on a fraudulent website, the attacker may gain access to their email or payment platform. They can then monitor conversations, learn payment patterns and intervene at the most convincing moment.
What new AI-enabled fraud attacks should finance teams know about?
AI is giving fraudsters new ways to impersonate trusted people and persuade finance teams to approve payments. Here are some of the techniques finance teams need to know about.
Deepfake executive fraud
Deepfake fraud uses synthetic audio, video or images to impersonate a real person. AI-generated scam calls can clone a person’s voice, while deepfake video can imitate their face and mannerisms.
A fraudster might call an employee while pretending to be the CEO or CFO. They may request a confidential payment, insist on speed and tell the employee not to discuss the matter with colleagues.
In one widely reported case, an employee transferred approximately $25.6 million after joining a video meeting with people who appeared to be senior colleagues.
The lesson is not that every video call presents a threat. It is that recognition is no longer sufficient proof of identity.
AI-generated spear phishing
Spear phishing targets a specific individual or organisation. An attacker may research your company before creating a message aimed at someone in finance, procurement or senior management. The message might refer to:
- A genuine supplier
- A recent business trip
- A known contract
- A real invoice number
- A current expansion project
- A payment that your team expects to make
The more relevant or accurate a message appears, the more likely an employee is to follow it without checking it independently.
Multimodal impersonation
Multimodal fraud combines several communication methods, such as:
- An email from a lookalike executive address
- A text message asking the employee to check their inbox
- A phone call using a cloned voice
- A short video or messaging-app conversation
- An urgent request to approve the payment
Using a second communication channel does not automatically verify that a request is safe. If the attacker controls both channels, the second message simply reinforces the deception.
Vishing, smishing and quishing
Phishing no longer happens only through email. Threats can also come in the form of:
- Vishing: phone calls or voice messages
- Smishing: SMS or other text messages
- Quishing: QR codes to direct someone to a fraudulent website or malicious content
The ENISA Threat Landscape 2025 report identifies phishing as the leading initial intrusion vector, accounting for 60% of observed initial intrusions. It also highlights the growing use of QR-code phishing, phishing-as-a-service and ClickFix-style campaigns.
Which familiar fraud checks no longer work on their own?
Finance teams should remain alert to:
- Urgent or secret payment requests
- Unexpected changes to supplier details
- New beneficiaries
- Unusual currencies or payment destinations
- Requests that bypass normal approval procedures
- Slight changes to email domains or phone numbers
- Invoices that do not match a purchase order
However, some older checks no longer provide enough protection by themselves. Do not rely solely on:
- Correct spelling and grammar
- A familiar writing style
- Caller ID
- A recognisable voice
- A video call
- A supplier’s logo or invoice design
- Confirmation through the same email conversation
- A request that appears to come from a senior executive
Instead, verify the action rather than the appearance of the communication.
How can businesses prevent AI-enabled payment fraud?
No single security measure can stop every fraud attempt. The strongest approach combines people, processes and technology across the payment lifecycle.
1. Verify changes through an independent channel
If a supplier requests a change to its payment details, contact the supplier using information already held in your records.
Do not use:
- The phone number included in the new email
- A link in the message
- A new number provided on the invoice
- The contact details in an unfamiliar email signature
A known contact method gives your team a better chance of reaching the genuine supplier. You can also review our practical guide to fraud prevention for international payments.
2. Separate payment initiation and approval
No single employee should be able to create, approve and release a high-value payment without oversight.
Use a clear approval hierarchy:
- One person initiates the payment
- A second person checks the details
- An authorised approver releases the payment
Apply extra scrutiny to new beneficiaries, unusual payment amounts and requests that fall outside normal procedures. Our guide to internal controls for international payments explores how distributed teams can apply these controls across entities and offices.
3. Check the beneficiary, not just the invoice
A genuine invoice does not guarantee a genuine payment account. Before releasing a payment, confirm:
- The beneficiary name
- The account details
- The supplier entity
- The invoice number
- The payment amount
- The currency
- The purpose of the payment
- The destination country
Where available, use beneficiary verification tools to identify mismatches before funds leave your account.
4. Use multi-factor authentication that confirms the action
Multi-factor authentication adds an important layer of account protection. But not all authentication methods offer the same level of protection against phishing.
Time-based codes from authenticator apps can still be captured in real time. For example, a fraudster may trick someone into entering a Google Authenticator code on a fake website before the code expires. The fraudster can then use that code to access the account or approve an operation.
That's why iBanFirst no longer supports Google Authenticator as an authentication method. Clients who use the iBanFirst mobile app receive a separate notification for each sensitive operation. They can see exactly what they are being asked to approve, such as making a payment or updating a beneficiary’s account details, and approve or reject each operation individually.
This creates a clearer link between the authentication step and the action itself, reducing the risk of approving something unintentionally.
Never share an authentication code with another person. Treat an unexpected authentication request as a warning sign, particularly if you did not initiate the login or payment.
Read more about how iBanFirst protects your payments.
5. Set clear rules for urgent requests
Fraudsters use urgency to discourage careful checking. Create a written process for requests that involve:
- A new beneficiary
- A change to supplier details
- A large or unusual payment
- A confidential transaction
- A request from a senior executive
- A change to the usual payment timing or currency
Your process should give employees permission to pause the payment and ask questions, even when the request appears to come from a senior executive.
6. Train teams regularly
An annual security presentation cannot keep pace with changing fraud methods. Use short, regular training sessions to cover:
- Recent fraud attempts
- New phishing formats
- Deepfake and voice-cloning risks
- Supplier verification procedures
- Escalation routes
- Lessons from near misses
The goal is not to make employees identify every AI-generated message. It is to help them follow the correct process when a payment request feels unusual.
7. Track and reconcile payments quickly
Payment tracking gives your team visibility after release. Fast reconciliation can also help you identify unusual activity earlier.
If your business makes international payments across multiple entities and currencies, choose tools that give authorised users a clear view of payment status, approval history and transaction records. Learn more about tracking international payments from initiation through settlement.
What should you do if you suspect payment fraud?
Even with strong controls in place, a suspicious payment request can still reach your team. If something does not look right, pause the payment and contact your payment provider straight away. Acting quickly can help you contain the incident and, if the payment has not yet left your account, stop it before funds move.
- Stop the payment if it has not yet left the account.
- Contact your payment provider immediately and explain what happened.
- Ask whether the payment can be recalled or stopped.
- Contact the genuine supplier using an established phone number or email address.
- Preserve evidence, including emails, invoices, call records and payment details.
- Report the incident to the relevant authorities and your internal security team.
- Review the control failure and update your process.
Do not wait for complete certainty before escalating. Early action can improve the chances of containing the incident.
How can a payment platform support fraud prevention?
A payment platform cannot replace your internal controls. It can, however, add another layer of protection to your payment workflow.
With iBanFirst, businesses can combine a cutting-edge payment platform with dedicated human support. Depending on your setup, relevant controls may include:
- Beneficiary verification
- Multi-signature approvals
- Granular user permissions
- Payment tracking
- Audit trails
- Multi-currency payment accounts
- AI-assisted invoice processing
- Duplicate payment checks
These controls help reduce manual errors, make approval responsibilities clearer and give finance teams more visibility before and after a payment moves.
Read more about how iBanFirst keeps business payments secure.
Frequently asked questions
What is the difference between phishing and business email compromise?
Can you trust a voice message from your CEO?
How can you verify a supplier’s payment-detail change?
What should you do after sending money to a fraudster?
Topics

