AI and Payments Fraud: A CFO's Guide to the Threats and the Defense

Category:Risk management, AP Automation
Updated:2026-09-09
Author:David Luther
ai-fraud-payments-hero.png

Artificial intelligence is a double-edged sword in payments fraud. The same technology that sharpens automation, analytics, and fraud detection also lets criminals manufacture convincing deepfakes, write flawless phishing at scale, and fabricate identities that pass verification. For a CFO, that means the fraud problem has changed shape.

The direction of travel is not subtle. According to the Deloitte Center for Financial Services' 2024 analysis, generative AI could push fraud losses in the United States to $40 billion by 2027, up from $12.3 billion in 2023, under an aggressive-adoption scenario. The exposure is already broad. The Association for Financial Professionals' 2026 Payments Fraud and Control Survey found that 76% of organizations faced attempted or actual payments fraud in 2025. Behind those percentages sits a criminal economy of serious size. Nasdaq Verafin's 2026 Global Financial Crime Report estimates global illicit financial activity at $4.4 trillion.

The AFP survey's most telling number describes the defense. Only 17% of organizations use AI to fight payments fraud, while attackers picked it up the moment it got cheap. That distance between the two adoption curves is where a finance team's real exposure sits.

The CFO's guide to AI payments fraud

Deepfakes, vendor impersonation, and synthetic identity are hitting AP now. Get the full breakdown of the threats — and the controls that stop them.

Download the whitepaper
AI Payments Fraud whitepaper cover

Key Takeaways

  • AI makes the old categories of payments fraud faster, cheaper, and more convincing. Deepfakes, phishing, invoice fraud, and synthetic identities are familiar cons with the friction removed.

  • Business email compromise remains the most common attack, and AI makes the fraudulent emails nearly indistinguishable from legitimate ones, so controls have to move from spotting bad grammar to verifying instructions out-of-band.

  • Accounts Payable is ground zero because it's where money leaves the company; card programs are a growing second front as spend shifts to electronic rails.

  • The most durable defense is layered across process, people, and technology, and no single layer is sufficient on its own.

  • The framework matters more than any tool. Verify high-risk instructions through a second channel, enforce segregation of duties, and use AI on defense to match AI on offense.

  • Automation cuts both ways, so an AP process without strong verification can auto-pay a fraudulent request faster than a manual one would.

What makes AI-enabled payments fraud different?

AI-enabled payments fraud is different because it collapses the time, cost, and skill a scam used to require. What once took a crook weeks of research and hand-crafting now takes hours, and it arrives polished. The three multipliers are speed, scale, and personalization, and together they change the risk calculus for every finance team.

A fraudster who used to send a hundred generic phishing emails and hope for a click can now send a hundred thousand, each tailored to the recipient's role, company, and recent activity scraped from public sources. Generative AI enables fraud at scale, targeting many victims simultaneously with the same or fewer resources. What comes back is a batch of scams that feel legitimate because they carry the details you expect to see, delivered at machine speed by systems that don't sleep.

That's the through-line. Every threat here is a familiar con with the friction removed. Understanding the mechanism is what lets a finance team put the right control in the right place. The full anatomy of AP fraud schemes maps how these cons work at the process level.

How are deepfakes used in payments fraud?

Deepfakes are used in payments fraud to defeat the oldest control there is, which is trusting what you see and hear. Generative AI can fabricate video and audio that convincingly mimics a real executive, so "verify the request in person" becomes a step a fraudster can fake.

In January 2024, a finance employee at the engineering firm Arup was duped into sending HK$200 million, about $25.6 million, across 15 separate transactions after joining a video call with what appeared to be the company's CFO and several colleagues, all of them AI-generated deepfakes, as reported by CNN. The employee had initially suspected a phishing email. The video call is what resolved the doubt, because the faces and voices matched colleagues he recognized. Nobody on the call was real.

That is the threat in its purest form, and it scales down as easily as up. A fraudster can clone a controller's voice from a few seconds of audio and call an AP clerk to approve a bogus payment or change a vendor's bank details.

When video and voice can be faked, identity has to be confirmed through a channel the attacker doesn't control. A callback to a known number, a code word for high-value requests, or an authentication step outside the original channel is what stands up when the face on the screen no longer proves anything.

Write down, today, the rule that no wire or bank-detail change gets approved on the strength of a video call or voicemail alone. That single policy closes the exact gap the Arup scam exploited.

How does AI amplify phishing and business email compromise?

AI amplifies phishing and business email compromise by erasing the tells that used to give scams away. The broken grammar and generic greetings of old-school phishing are gone, replaced by large language models that draft polished, personalized messages mirroring a real sender's tone and referencing real projects and colleagues.

Business email compromise is the attack that matters most here, because it's already the most common. According to the AFP's 2026 Payments Fraud and Control Survey, BEC affected 74% of organizations in 2025, up from 63% the year before. AI makes the attack both more convincing and more scalable, since a model can generate a unique, correctly detailed phishing email for every AP clerk across a hundred companies, each referencing the right vendor names and invoice numbers.

According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, business email compromise drove $3.046 billion in reported losses, with the average complaint topping $122,000. Reported cybercrime losses across all categories reached $20.9 billion in 2025, up 26% year over year.

The con extends past email. Voice deepfakes carry it into "vishing," where an AI-generated voice matching your CFO calls the finance team to push through a payment or a bank-detail change. Large companies fall too. In the biggest documented case of its kind, a Lithuanian man ran a forged-invoice scheme from 2013 to 2015 against two US technology companies; the Department of Justice announced in December 2019 that he was sentenced to five years for stealing more than $120 million. DOJ identified the victims only as a multinational technology company and a multinational online social media company, and press reporting named them as Google and Facebook.

The scheme predates generative AI, which is exactly what makes it instructive. What took a determined criminal years of patient forgery then is now a weekend's work for anyone with a language model. Vendor email compromise is the newer variant, and it hides inside a supplier thread your team already trusts.

What does AI-era invoice fraud look like?

AI-era invoice fraud looks legitimate, which is precisely the problem. Generative AI can forge vendor invoices with authentic logos, correct addresses, and line items that match your buying patterns, plus supporting documents like contracts and delivery receipts to clear secondary checks.

The danger concentrates where automation runs unattended. If invoices under a threshold flow through straight-through processing, a fraudster who studies your patterns can craft a fake invoice just under that line, referencing a real purchase order, so it slips through. This is adversarial automation, meaning criminals using AI to outwit your AP automation.

According to the AFP's 2025 survey, 45% of companies encountered fake vendor or invoice scams in 2024, up 11 percentage points from the prior year. In the 2026 edition, checks are still the most-targeted payment method, reported by 58% of organizations. Even the newest attack techniques ride the oldest rails.

Verification at the points that matter is what answers this, meaning vendor onboarding, invoice approval, and any change to banking details. Three-way matching catches invoices that don't tie back to a real order and receipt, and automated invoice processing earns its keep as a fraud control as much as an efficiency gain.

What is synthetic identity fraud, and why should finance care?

Synthetic identity fraud is the creation of a fake persona stitched together from real and fabricated data, and finance should care because those personas have moved beyond consumer lenders into corporate AP, procurement, and card programs. Writing for the Federal Reserve Bank of Boston in April 2025, Mike Timoney cited figures from the anti-fraud platform FiVerity showing that losses from synthetic identity fraud crossed $35 billion in 2023, and argued that generative AI is accelerating the problem.

Here is how it reaches corporate finance. A fabricated vendor arrives with an AI-generated website, a plausible owner's profile photo, and a chatbot that answers when your team calls to verify. It clears onboarding, enters your supplier master file, and invoices against work nobody ordered, until the real business whose data was partially borrowed comes asking questions.

AI is the accelerant, since it can comb breached data to assemble viable identities, generate passable photos, and interact with verification systems to learn which fakes slip through. Timoney's analysis makes the mechanism plain. Generative tools let a fraudster mass-produce candidate identities and then find out empirically which ones clear verification.

For finance, the exposure lives anywhere identity verification gates money, including new-vendor onboarding, corporate card issuance, and payroll setup. The signs to watch for are the ones AI still gets wrong, like multiple vendors sharing one bank account, a digital footprint that's too thin or too perfect, or small inconsistencies across official documents. Disciplined vendor due diligence is the front-line control, and it does most of its work at onboarding, before a fake supplier ever submits an invoice.

Where are AP and card programs most exposed?

Accounts Payable and corporate card programs are the most exposed functions because they're where money leaves the company. AP has always guarded against duplicate invoices and bogus vendors, but AI-enhanced attacks raise the difficulty, and the data shows AP is being targeted directly.

The pressure is concrete. The two techniques with the sharpest recent growth in the AFP surveys, vendor impersonation and business email compromise, are precisely the two aimed at Accounts Payable. That is not a coincidence. Attackers optimize, and AP is where the money is. The common entry points are predictable:

  • Vendor master-file changes, where a fraudster impersonates a supplier to redirect banking details to an account they control.

  • Invoice processing, where a good-enough fake clears an automated check or a rushed approval under deadline pressure.

  • New-vendor onboarding, where a fabricated supplier enters the system clean and invoices against work nobody ordered.

Card programs are the second front, and a growing one. As spend shifts to electronic rails, fraudsters follow the money. AI bots can test thousands of stolen card numbers at machine speed and study approval patterns to find issuers with weaker detection, while synthetic identities open new corporate cards outright. Virtual cards cut both ways here, since a unique, single-use number is a strong control when the request process is protected, but a compromised request can still issue a card to a fraudster. The control mechanics live in card controls and spend policies.

Detection quality varies by issuer, so it belongs on the evaluation checklist alongside rebates and controls. Choosing a virtual card provider sets out the questions worth asking, and a side-by-side comparison of corporate card programs shows how widely spend controls and fraud detection actually differ.

AI-era fraud vectors at a glance

Each vector below changed in a different way, and each answers to a different control.

Fraud vector

How it worked before AI

How AI changes it

Primary control

Deepfake impersonation

Rare; required real footage or a skilled mimic

Cheap, convincing video and voice clones of executives on demand

Out-of-band verification (callback, code word) for high-value requests

Phishing and BEC

Mass, generic, often full of tells

Polished, personalized, correctly detailed at massive scale

Verify payment and bank-change instructions through a second channel

Invoice and vendor fraud

Hand-forged invoices, easier to spot

Authentic-looking invoices and documents matched to your patterns

Three-way matching and validated vendor banking

Synthetic identity

Slow to build; targeted lenders

Fabricated vendors and identities that pass thin verification

Rigorous KYC and vendor due diligence at onboarding

Card fraud

Manual testing of stolen numbers

Bots testing thousands of numbers and learning detection patterns

Single-use virtual cards and real-time transaction monitoring

Agentic attacks

Every step needed a human operator

Software runs the whole sequence, including against your own AI agents

Human approval gates on payment-capable agents; agent identity standards

What happens when the attacker is a machine?

When the attacker is a machine, the whole sequence runs at software speed with a human touching only a handful of decision points. Every threat described so far assumes a person drives the scam, and that assumption may be the first to expire. In November 2025, Anthropic disclosed that a state-sponsored group had manipulated its Claude models into running an intrusion campaign against roughly 30 organizations, including financial institutions, with the AI performing an estimated 80% to 90% of the work and humans stepping in at only a handful of decision points. The target there was espionage, not payments, but the capability transfers directly. Reconnaissance, pretext writing, and follow-up all become software.

The second half of this is closer to home, because your own AI agents are a new door. Palo Alto Networks' Unit 42 has demonstrated indirect prompt injection against payment-capable AI agents, where instructions hidden in a web page or document redirect the agent into executing a transaction with no human check. If your finance function is piloting agents that can touch money, the control question is whether anything that agent reads can issue it instructions. The card networks are already building for this, with Visa's Trusted Agent Protocol and Google's Agent Payments Protocol both aiming to distinguish a legitimate AI agent from a malicious one at the moment of payment.

For a CFO, three things follow from that, and none of them require a new platform:

  • Inventory the agents that can move money. Any automation with payment rights belongs on the same risk register as a person holding that authority.

  • Keep a human approval gate on payment execution, particularly for new payees and bank-detail changes, regardless of how reliable the agent has been.

  • Treat anything an agent reads as untrusted input, the same way you already treat an inbound invoice.

The defense has to evolve at the same pace as the attack. The organizing idea is simple to state and harder to live, which is to fight AI with AI and never let a single control carry the whole load.

How should a CFO frame AI fraud as enterprise risk?

A CFO should frame AI fraud as a financial and strategic risk, not an IT problem to be delegated. The modern risk portfolio now includes scenarios that sounded absurd five years ago, like an AI-generated voice scam of the CEO, and the frameworks meant to catch them often assume a human is behind every request and that certain checks can't be faked. Those assumptions need revisiting.

The U.S. Treasury warned in March 2024 that existing risk-management frameworks may not adequately cover emerging AI threats. Two years on, the regulatory picture has moved in both directions at once. In April 2026 the Federal Reserve, OCC, and FDIC rescinded their long-standing model-risk guidance, replacing it with voluntary guidance that explicitly places generative and agentic AI out of scope. Nacha moved the other way, phasing in risk-based ACH fraud-monitoring requirements through 2026.

Nobody is going to hand you a finished AI-fraud standard, so the assessment is yours to build. That points at a few moves.

  • Bring finance, security, and legal together so AI fraud scenarios live in the risk assessment and the incident-response plan, with a clear protocol for who acts if a deepfake scam hits.

  • Treat AI-based detection as a CFO budget decision, because the tools that catch these attacks need money and executive backing.

  • Weigh the reputational stakes. A headline-making fraud can shake supplier, customer, and investor confidence well beyond the dollar loss, and organizations that prepare and respond transparently tend to fare better than those caught flat-footed.

The CFO's guide to AI payments fraud

Deepfakes, vendor impersonation, and synthetic identity are hitting AP now. Get the full breakdown of the threats — and the controls that stop them.

Download the whitepaper
AI Payments Fraud whitepaper cover

How do you build an AI-era fraud defense?

You build an AI-era fraud defense in three layers: process, people, and technology. No single layer holds on its own. Attackers have to get through all three, and the discipline is in confirming each one is actually strong instead of assuming it. Each layer below includes where it stops working.

Process: Make instructions hard to fake

Process controls are the cheapest and often the most effective layer. Require multi-step verification for any change to payment instructions, especially bank-detail changes, using a callback to a number you already have on file rather than one supplied in the request. Enforce segregation of duties so the person who sets up a vendor isn't the one who approves its payments. Pressure-test the whole thing with drills, including a simulated executive email to see who clicks, then fix what the drill exposes. The point is to retire controls designed for a pre-AI era and write policies that name the new scenarios explicitly, down to "we never authorize wires on a video call without confirmation through a known number."

Defending against payment fraud starts with these process controls, and for check-based exposure, positive pay remains a reliable catch for altered and counterfeit checks.

People: Train for a world where the polished message is the fake

Your team can be the weakest link or the strongest defense, and training is what tips the balance, but only if it evolves. Staff need to be as skeptical of a flawless email as a sloppy one, to double-check any unusual request regardless of who appears to send it, and to verify identity through a second channel. Because so many scams weaponize urgency, the culture has to make it safe to slow down and confirm a payment without fear of missing a deadline. AP and treasury deserve specialized attention as high-value targets, along with a regular briefing on new tactics drawn from FBI and industry reporting.

Technology: Use AI on defense to match AI on offense

Technology is where you turn AI's other edge to your advantage. Modern AP and payments platforms embed machine-learning models that flag invoices deviating from normal patterns, detect duplicate or altered banking details, and score anomalies for review before a payment releases. On the card side, real-time monitoring catches unusual spend as it happens, and the card networks themselves lean heavily on AI. Mastercard reported in 2024 that its Decision Intelligence system scans roughly one trillion data points to score a single transaction.

Layer in authentication that a voice clone can't defeat, such as verification callbacks to numbers on record and phishing-resistant multifactor authentication on email accounts, since many BEC attacks begin with an email takeover. And keep the simple rules, like holding any payment above a threshold or to a new bank account for human review. Virtual cards and automation close the credential gap that most of these attacks depend on.

Which controls stop AI-era payment fraud, and who owns them?

The controls that do the most work are out-of-band callbacks, segregation of duties, validated vendor banking, three-way matching, and single-use virtual cards, and each one needs a single named owner. A control without an owner is a policy nobody runs.

Control

What it stops

Who owns it

Out-of-band callback to a number already on file

Deepfake video and voice-clone approvals, and BEC bank-change requests

Treasury, with AP

Segregation of duties between vendor setup and payment approval

One compromised account pushing a payment end to end

Controller

Validated banking on vendor master-file changes

Vendor impersonation that redirects payments

AP manager

Three-way matching against the PO and the receipt

Forged invoices for goods nobody ordered

AP manager

Vendor due diligence at onboarding

Fabricated and synthetic suppliers entering the master file

Procurement, with finance

Phishing-resistant MFA on finance email

The account takeover that precedes most BEC

IT security, funded by finance

Anomaly detection on invoices and card spend

Good-enough fakes that clear a rushed approval

Controller, with the platform owner

Single-use virtual card numbers

Reusable credentials and automated card testing

Card program administrator

Human approval gate on payment-capable AI agents

Prompt-injected or unsupervised agent transactions

CFO, with IT

Where to spend first

You don't need every tool, and you can't eliminate the risk, so spend where the return is highest. Out-of-band verification of high-value and bank-change requests is the highest-return control most organizations can adopt, and it costs almost nothing. Segregation of duties comes next, and it costs a policy rewrite instead of a purchase.

Technology earns its place when your volume outruns what people can check by hand, which is the point where AI-based detection stops being optional. If your AP is largely manual, fix the process and people layers first. When it's largely automated, the technology layer isn't a luxury, because automation without verification just pays fraud faster.

How Corpay helps finance teams control payment fraud

The strongest position against AI-era fraud is to pull payments into one controlled, auditable system, because scattered rails and manual handoffs are exactly the gaps these attacks exploit. That's the problem Corpay is built to close, and it's where the process, people, and technology layers above come together in practice.

Corpay AP Automation brings invoice capture, three-way matching, and approval workflows into one place. Anomaly detection and duplicate-invoice checks flag what a rushed human approval would miss, and managed supplier enrollment validates banking at the onboarding and bank-change steps where fraud concentrates.

Corpay Virtual Cards replace static account credentials with single-use numbers locked to one payment, so a fraudster has no reusable credential to steal. They carry the spend controls and real-time visibility that make a card program defensible. And because the whole flow is one system, the audit trail becomes a byproduct of how payments happen.

Corpay serves more than 800,000 businesses, is Mastercard's number-one commercial B2B issuer, and connects to a network of over 4 million accepting vendors. That scale is what lets validated vendor banking work as an automatic control instead of a manual chore.

Frequently Asked Questions

What is AI-enabled payments fraud?

AI-enabled payments fraud is the use of artificial intelligence to make traditional payment scams faster, cheaper, and more convincing. It includes deepfake impersonation of executives, AI-written phishing and business email compromise, forged invoices matched to your buying patterns, and synthetic identities that pass verification. The categories are familiar; AI removes the friction that used to limit them.

How does AI make business email compromise worse?

AI removes the tells that used to expose BEC. Large language models write polished, personalized emails that mimic a real sender's tone and reference genuine projects, vendors, and invoice numbers, and they can generate a unique version for every target at scale. Because the message looks legitimate, the defense has to shift from spotting bad writing to verifying payment instructions through a separate channel.

Are deepfakes a real threat to finance teams?

Yes. The clearest example is the January 2024 attack on the engineering firm Arup, where a finance employee authorized 15 transactions after a video call in which the CFO and several colleagues were AI-generated. Voice clones can also target AP staff by phone to approve payments or change bank details. The countermeasure is confirming high-value requests through a channel the attacker doesn't control, such as a callback to a known number.

How can a company prevent AI-driven payment fraud?

Build defense in three layers. Process controls like out-of-band verification of bank changes and segregation of duties are the cheapest and most effective. People controls that train staff to distrust even polished requests, and to verify through a second channel, close the human gap. Technology controls like AI-based anomaly detection, single-use virtual cards, and real-time monitoring match AI on offense with AI on defense, and Corpay provides that layer through its AP automation and commercial card programs. No single layer is sufficient alone.

Why is AP a primary target for fraud?

Accounts Payable is where money leaves the company, so it's the natural target for anyone trying to divert funds. Common entry points are vendor master-file changes that redirect banking details and invoices engineered to clear automated checks or rushed approvals. The techniques aimed at AP, chiefly business email compromise and vendor impersonation, are also the ones growing fastest in the AFP's annual fraud surveys.

Does payment automation increase or reduce fraud risk?

It can do either, depending on the controls around it. Automation without strong verification can auto-pay a fraudulent request faster than a manual process would. Automation with three-way matching, validated vendor banking, anomaly detection, and single-use virtual cards reduces risk by catching what humans miss and removing the static credentials fraud depends on. Corpay combines those controls in one AP and card system, so the verification runs on the same rail as the payment instead of in a separate tool. The verification layer is what decides which outcome you get.

Headshot.JPG

David Luther

Product Marketing Program Manager
David Luther, MBA is a product marketing program manager with years of experience in commercial banking, finance, and technology sectors, with research and writing appearing in financial publications.
Risk management
AP Automation

Smarter payments. Stronger growth. Keep business moving.

Corpay powers payments for 800,000+ businesses worldwide. Let’s build what’s next for yours.

By submitting your information through this form, you agree to receive a telephone call or email from a Corpay representative. Your information will be used in accordance with our Privacy Policy.