UPDATED AUG 2026

Everyone on the call was a deepfake.

And the employee who approved the wire never even knew. That one call cost the company $25.6 million. The same AI now forges the invoices, clones the voices, and builds the fake vendors aimed at your payments. The report covers all of it, and gives you five controls that stop the money before it leaves.

Updated Double-edged Guide.png

This report comes from Corpay, which moves $145B a year with a 640K+ vendors on the virtual card network that helps eliminate AI fraud.

WHAT CHANGED

The ways you catch fraud have already stopped working.

AI made the fakes cheap, convincing, and easy to aim at everyone in your AP at once. The checks your team runs were built for a slower, sloppier attacker. Three of them are below.

THE CALL

You get on a call to confirm.

The old rule was simple: if a request is big, verify it by voice or video. A cloned voice needs a few seconds of audio, and a face can be faked on a live call. The call confirms nothing now.

The report gives you the one check a faked call can't pass, so you see the next one coming.

THE EMAIL

You train your team to spot the typos.

Broken grammar and generic greetings are gone. AI writes clean notes that name real people and reference real projects. A flawless message now deserves the same suspicion as a sloppy one.

The report gives you what to train on instead of typos, so a flawless message never gets a pass.

THE DETAIL

You trust a request that knows the details.

A note arrives about a conference you actually attended, with an invoice attached "as discussed." That detail proves the attacker studied you. It does not prove the request is real.

The report gives you the check that beats a studied fake, so detail stops passing for proof.

This guide gives your controller and AP lead five controls to put into the payment process, and who's accountable for each.

Read the report
The adoption gap

Attackers adopted the tools first.

A polished request proves nothing. Your process has to verify the account, the person, and the authority to pay.

0%

of financial-crime professionals report more AI-driven attacks over the past two years.1

The adoption gap

0%

of organizations use AI for fraud mitigation.2

The PAYMENT PATH

One bank-detail change can redirect every payment after it.

A valid invoice can pay the wrong account after one supplier record changes. The weakness is not the invoice. It is the master file.

Stage 01

Vendor onboarding

The Attack

An AP clerk receives a complete supplier packet: a believable website, a real registration, and generated ownership documents filling every gap a reviewer might check.

Your AP clerk calls to verify. A cloned voice answers.

The Control

Verify bank details against a source outside the supplier packet, and check when the domain and the registration first appeared.

Route every new supplier through a separate approval.

Why it matters

Once AP approves a synthetic vendor, every invoice after it starts with trust the vendor never earned. Losses passed $35 billion in 2023. The Federal Reserve Bank of Boston now gives the corporate version its own name [10]. That figure covers the whole category and traces to FiVerity rather than to Federal Reserve research.

INSIDE THE GUIDE

You're one approval away from paying a fraudster.

CFOs get the ownership decisions. Controllers and AP leaders get the checks, escalation points, and vendor-verification steps to assign.

Deepfakes and voice cloning.

The $25.6M deepfake call, the copycat that hit months later, and why scrutinizing the call harder won't save you.

Invoice forgery and synthetic vendors.

Invoices matched to your buying patterns, and fake suppliers that answer the phone.

Agentic attacks, in both directions.

Attacks that run themselves, and the new exposure when your own agents hold payment rights.

Accounts payable in detail.

All five points on the payment path, plus check fraud and the corporate card angle.

What regulators did and did not do.

Treasury, the withdrawn model-risk guidance, Nacha, FinCEN, and the insurance language to read first.

The five controls, in depth.

Process, people, and technology, with how to test that each one holds under deadline.

Send me the report

One email. The full guide arrives as a PDF you can forward to your controller.

Before you download

Who is the report for?

What will I get?

Is it a product brochure?

How current is the research?

Research & references

Every claim is traceable.

Key figures and cases link directly to their evidence. Open the full bibliography for every reference used in the report.

31
references
August 2026
research cutoff

Claims and source dates reflect the report's August 2026 research cutoff. External pages may change after publication.

  1. [1] Nasdaq Verafin (with Celent and Oliver Wyman), 2026 Global Financial Crime Report, March 2026

  2. [2] Association for Financial Professionals, 2026 Payments Fraud and Control Survey Report (underwritten by Truist), April 2026

  3. [3] Association for Financial Professionals, 2025 Payments Fraud and Control Survey Report (underwritten by Truist), April 2025 (vendor-impersonation figure)

  4. [4] Deloitte Center for Financial Services, Generative AI is expected to magnify the risk of deepfakes and other fraud in banking, June 2024

  5. [5] FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report, April 2026

  6. [6] Heather Chen and Kathleen Magramo, "Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee," CNN Business, May 16, 2024

  7. [7] Entrust, 2026 Identity Fraud Report (deepfakes behind roughly 1 in 5 biometric fraud attempts), November 2025

  8. [8] U.S. Attorney's Office, Southern District of New York, "Lithuanian Man Sentenced To 5 Years In Prison For Theft Of Over $120 Million In Fraudulent Business Email Compromise Scheme," December 2019 (Rimasauskas case; the release describes the victims only as two U.S.-based Internet companies and does not name them)

  9. [9] Sara Ashley O'Brien, "'Shark Tank' judge Barbara Corcoran gets her $400,000 back from scammers," CNN Business, March 2, 2020

  10. [10] Mike Timoney, "Gen AI Is Ramping Up the Threat of Synthetic Identity Fraud," Federal Reserve Bank of Boston, April 17, 2025 (source of the synthetic identity loss figure cited above, which the article attributes to the anti-fraud collaboration platform FiVerity rather than to Federal Reserve research; confirmed in a browser 2026-07-28)

  11. [11] U.S. Department of the Treasury, Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector, March 27, 2024 (Treasury's announcement and summary of the report; the report PDF itself is no longer served on treasury.gov as of July 2026)

  12. [12] Mastercard Newsroom, "Mastercard Supercharges Consumer Protection with Gen AI" (Decision Intelligence, one trillion data points per transaction), February 2024

  13. [13] Anthropic, "Disrupting the first reported AI-orchestrated cyber espionage campaign" (AI executed an estimated 80 to 90 percent of an intrusion campaign against ~30 organizations, including financial institutions), November 13, 2025

  14. [14] Visa, "Visa Introduces Trusted Agent Protocol" (authentication framework for AI agents transacting at checkout), October 14, 2025

  15. [15] Office of the Comptroller of the Currency (with the Federal Reserve and FDIC), "Model Risk Management: Revised Guidance," OCC Bulletin 2026-13 (rescinds SR 11-7 / OCC Bulletin 2011-12; non-compliance will not result in supervisory criticism; generative and agentic AI out of scope), April 17, 2026

  16. [16] Nacha, "Risk Management Topics — Fraud Monitoring" (Phase 1 effective March 20, 2026; Phase 2 effective June 19, 2026; risk-based fraud monitoring on ACH credit origination)

  17. [17] The Clearing House, "Real Time Payments" (RTP settlement is final and irrevocable), accessed July 2026

  18. [18] Federal Reserve Financial Services, "FedNow Service Raises Transaction Limit to $10 Million," September 16, 2025 (effective November 2025)

    https://www.frbservices.org/news/fed360/issues/091625/fednow-service-10-million-transaction-limit

  19. [19] Singapore Police Force, via Mothership, "Finance director in S'pore transfers S$670,000 to scammers who used deepfake to impersonate company's executives" (finance director authorized roughly US$499K after a deepfaked executive video call, March 2025; funds subsequently traced and withheld through Singapore–Hong Kong cooperation), April 2025

  20. [20] Federal Reserve Financial Services, "Risk of Synthetic Business Fraud" (Fed360), November 4, 2025 (fabricated companies, fraudulent EINs, fake web presence, false invoices to legitimate companies)

    https://www.frbservices.org/news/fed360/issues/110425/fraud-mitigation-synthetic-business-fraud

  21. [21] Anthropic, "Claude Fable 5 and Claude Mythos 5," June 9, 2026 (Fable 5 broadly available with dual-use safety classifiers; Mythos 5 the same model with safeguards removed, restricted to approved organizations)

  22. [22] UK AI Security Institute, "How far behind the frontier are leading open-weight models on cyber?," July 17, 2026 (open-weight models trail the closed frontier on cyber capability by four to seven months, narrowing from six to ten a year earlier; most capable open-weight model at testing was GLM-5.2)

  23. [23] Unit 42 (Palo Alto Networks), "Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild," 2026 (attacker instructions hidden in web content drive payment-capable AI agents to act, including executing transactions without human confirmation)

  24. [24] Google, "Google donates Agent Payments Protocol to FIDO Alliance," April 28, 2026 (AP2 agent-payment identity standard, co-developed Verifiable Intent with Mastercard; newer versions support "Human Not Present" autonomous payments)

  25. [25] Coalition for Content Provenance and Authenticity (C2PA), "Content Credentials" (open standard verifying the origin and edit history of digital files; scope is discrete content, not live video streams), accessed July 2026

  26. [26] Aon, "From Phishing to Deepfakes: Social Engineering Risks are Intensifying for Professional Service Firms," April 2026 (social-engineering coverage often carries sublimits out of step with routine payment values; deepfake voice/video now used to "confirm" fraudulent transfer instructions)

  27. [27] Coalition, "Coalition Adds Deepfake Response Endorsement," December 2025 (covers deepfake forensics, takedown, and crisis-communications support, not funds-transfer indemnity)

  28. [28] Visa, "Visa Threat Intelligence Platform," July 2, 2026 (connects cyber events to payment-fraud outcomes; monitors for compromised credentials and upstream cyber activity)

  29. [29] Mastercard, "Mastercard Expands Virtual Card Platform with New Security Controls," July 23, 2026 (issuer-enforced spend, transaction, and validity controls at card creation; reports virtual-card fraud rates under one-fifth of non-virtual)

  30. [30] FinCEN, "Section 314(b) Fact Sheet," June 12, 2026 (expands the information-sharing safe harbor to cover suspected fraud, enabling real-time sharing of fraud indicators between institutions)

  31. [31] "4 check fraud trends in 2026," FinTech Global, April 2026 (generative tools lower the skill needed to produce counterfeit or altered checks, so-called "check cooking")

Who Published this

Control more of what your business spends.

Corpay moves $145B+ a year for 800,000+ businesses. Cards, invoices, and cross-border, on rails Corpay owns and operates. The controls in this report are the ones our own payables teams run.

  • $145B+

    Corpay annual payments volume

  • 800,000+

    businesses

  • 640,000+

    vendors on the virtual card network

  • $800M+

    rebates paid to customers a year

  • ~93%

    client retention

  • #1

    commercial card issuer in America