It’s a statistic that should make every business owner, manager, and accounts payable professional take notice.
According to the FBI’s 2025 Internet Crime Report, business email compromise (BEC) scams cost U.S. businesses more than $3 billion last year alone. That makes BEC one of the most financially damaging forms of cybercrime on record.
With artificial intelligence making these attacks more convincing than ever, the question is no longer whether your AP team can spot a suspicious request. Instead, businesses must ask whether their payment processes are strong enough to prevent fraud, even when a request appears completely legitimate.
Why AP Teams Are in the Crosshairs
Accounts payable teams operate at the intersection of trust, urgency, and financial responsibility. They process invoices, manage supplier records, and authorize payments while keeping business operations moving smoothly.
For cybercriminals, that makes AP departments an attractive target.
Most successful fraud schemes don’t require hacking into systems. The FBI’s Internet Crime Complaint Center (IC3) consistently reports that BEC attacks rely on impersonation. Attackers pose as executives, suppliers, or trusted colleagues to redirect payments or alter banking information before anyone realizes what has happened.
Artificial intelligence has made these attacks significantly easier to execute at scale. Tasks that once required extensive research and careful writing can now be automated. AI tools can quickly gather information, mimic communication styles, and craft messages that fit seamlessly into normal AP workflows.
By mid-2024, researchers estimated that approximately 40% of BEC phishing emails were AI-generated, and that number continues to grow.
What AI-Enhanced Fraud Looks Like in Practice
Emails that Blend into Normal Workflow
Traditional phishing campaigns relied on volume and obvious mistakes. AI has changed the game.
Today’s BEC emails are often grammatically flawless and written in the exact tone and style of the person being impersonated. They may reference active projects, current invoice numbers, supplier relationships, and upcoming payment schedules.
For AP teams handling hundreds of routine communications, this level of familiarity can make fraudulent messages almost indistinguishable from legitimate requests.
Invoice and Payment Redirection
One of the most common forms of AP fraud involves redirecting payments.
Attackers may gain visibility into a legitimate invoice conversation and quietly modify payment details. They then send an updated invoice or a message claiming the supplier has changed banking information.
Because much of the surrounding content comes directly from genuine correspondence, the request often appears completely legitimate.
Voice Cloning and Executive Impersonation
Email is no longer the only communication channel attackers exploit.
Modern AI voice-cloning tools can replicate a person’s voice using only a short audio sample. Criminals can use these tools to leave convincing voicemails or place calls that sound exactly like a company executive.
For organizations that rely on verbal approvals for urgent or high-value payments, this removes one of the traditional safeguards that email security alone cannot protect.
Why Traditional Checks No Longer Work
Security awareness training remains important, but AI has dramatically changed the threat landscape.
Many of the warning signs employees were taught to look for—poor grammar, incorrect logos, suspicious sender addresses, and generic greetings—are disappearing.
Today’s fraud attempts can reference your company, your suppliers, and even current invoice amounts using information gathered from public sources or previous communications.
When a fraudulent request looks identical to a legitimate one, relying solely on employees to identify scams places too much responsibility on individuals.
The organizations that successfully reduce risk focus less on spotting fraud and more on creating processes that make fraud difficult to execute regardless of how convincing it appears.
Building Process Around the Risk
The strongest defense against AI-enhanced fraud isn’t sharper instincts—it’s eliminating uncertainty from high-risk financial actions.
Out-of-Band Verification as Standard
Any request to update supplier banking information or approve an unusual payment should require verification through a separate, trusted channel.
That means calling a supplier using a known phone number already on file or confirming requests directly with a colleague rather than replying to the same email thread.
This simple process breaks the attack chain, regardless of how convincing the original message appears. It doesn’t require new technology—just a documented procedure and consistent execution.
Layered Access and Authentication Controls
Restricting access to financial systems and enforcing multi-factor authentication helps minimize the damage a compromised account can cause.
Even if an attacker gains access to a supplier’s email account, strong authentication requirements can create enough friction to prevent fraudulent changes from being completed.
A Culture That Supports Slowing Down
Effective fraud prevention depends on creating an environment where employees feel comfortable verifying requests, even when they come from senior leadership.
An AP team member who pauses a payment to confirm details is not creating a bottleneck—they are following a sound security process.
Leadership plays a critical role by reinforcing that taking extra time to verify high-risk requests is always the correct decision.
The FBI’s 2025 Internet Crime Report included a dedicated section on AI-enabled fraud for the first time, documenting more than $893 million in losses across over 22,000 complaints.
When verification becomes standard practice and questioning unusual requests is encouraged, AI-enhanced fraud loses much of its effectiveness.
Attackers may continue to improve their technology, but the controls needed to stop them remain straightforward. The key is applying those controls consistently.
Shift the Burden from People to Process
If you're concerned about AI-enhanced fraud targeting your finance team or your clients, now is the time to review your controls.
Strong processes, independent verification, and a culture that encourages employees to slow down and validate requests can dramatically reduce risk.
Contact us today to schedule a consultation and identify where your most critical gaps may exist before attackers find them first.
Article used with permission from The Technology Press.