Is Your Invoice a Deepfake? Securing Accounts Payable Against AI Fraud
It is a statistic that should concern every small and medium-sized business: according to the FBI’s 2025 Internet Crime Report, business email compromise (BEC) cost US businesses over $3 billion last year.
AI has made these attacks significantly harder to detect. The question for Accounts Payable (AP) teams is no longer whether they can spot a suspicious request, but whether their payment processes are robust enough to stop fraud regardless of how convincing it appears.
Why Accounts Payable is the Primary Target
Accounts payable sits right at the intersection of trust and timing. AP teams manage supplier details, process invoices, and execute payments, often under pressure to keep business operations running smoothly. For cybercriminals, this combination is the ideal target.
Most successful fraud attempts do not involve hacking into systems. Instead, the FBI’s Internet Crime Complaint Center (IC3) consistently finds that BEC attacks rely on impersonation. Attackers pose as trusted executives, suppliers, or colleagues to redirect payments before anyone notices.
How AI-Enhanced Fraud Operates
AI has made impersonation dramatically more scalable and realistic.
- Flawless Phishing Emails: Traditional phishing relied on volume and imperfection, but AI has changed that. Modern BEC emails are grammatically perfect, match the specific tone of the impersonated executive, and reference active projects or current invoice numbers. In fact, by mid-2024, an estimated 40% of BEC phishing emails were AI-generated.
- Invoice and Payment Redirection: Attackers often intercept a legitimate email exchange and quietly alter the destination bank account. They may send a short message claiming a supplier has updated their banking details, using real correspondence to make the request look entirely legitimate.
- Voice Cloning: Email is not the only channel being exploited. AI voice-cloning tools can replicate a person’s voice from a brief audio sample. This allows attackers to leave convincing voicemails or place live calls that sound exactly like a known executive, bypassing traditional verbal approvals.
Why Traditional Checks Are Failing
Security awareness training remains important, but it is no longer enough on its own. Attacks no longer feature the obvious red flags that training used to highlight, such as awkward phrasing or mismatched logos. The FBI’s 2025 Internet Crime Report logged more than $893 million in AI-enabled scam losses across over 22,000 complaints, proving how effective these new tactics are.
3 Steps to Secure Your Payment Process
The most effective defence is removing ambiguity from high-risk actions.
1. Enforce Out-of-Band Verification
Any request to change supplier bank details or approve an urgent payment must require secondary confirmation through an independent channel. Calling a supplier on a known, pre-existing phone number breaks the impersonation chain, regardless of how convincing the email was.
2. Implement Layered Access Controls
Restricting access to financial systems and enforcing multi-factor authentication (MFA) limits the damage a compromised account can cause.
3. Build a “Slow Down” Culture
Fraud prevention improves when staff feel safe questioning requests, even from senior leadership. A team member who pauses a payment to verify it is doing exactly what good process requires.
💡 Concerned about AI-enhanced fraud targeting your finance team? Our Cybersecurity services can help you review your current controls and implement secure, deepfake-proof payment workflows.
Article used with permission from The Technology Press.

Comments are closed