It is a statistic that should concern every business handling supplier payments.
According to the FBI’s 2025 Internet Crime Report, business email compromise (BEC) scams cost organisations more than $3 billion last year, making it one of the most financially damaging forms of cybercrime globally. What has changed is the sophistication behind these attacks. Artificial intelligence is allowing cybercriminals to create highly convincing emails, cloned voices, and realistic impersonations that are becoming increasingly difficult to spot. For finance and accounts payable teams, the challenge is no longer simply identifying suspicious messages. The real issue is whether payment processes are secure enough to prevent fraud, even when a request appears genuine.Why Accounts Payable Teams Are Being Targeted
Accounts payable teams operate in an environment built on trust, urgency, and routine. They manage supplier relationships, process invoices, and approve payments that keep day-to-day operations moving. For attackers, that creates an ideal opportunity. Most successful financial fraud does not begin with a technical breach. In many cases, it starts with impersonation. Cybercriminals pose as suppliers, senior executives, or trusted colleagues to redirect payments or request banking detail changes before anyone realises something is wrong. AI has dramatically increased the scale and effectiveness of these attacks. Tasks that once required time, research, and technical skill can now be automated using AI-powered tools capable of generating convincing content within seconds. By mid-2024, security researchers estimated that nearly 40% of business phishing emails were already AI-generated, with adoption continuing to rise rapidly.What AI-Driven AP Fraud Looks Like
Emails That Blend into Everyday Workflows
Traditional phishing attempts were often easy to identify due to poor grammar, unusual formatting, or generic messaging. That is no longer the case. Modern AI-generated fraud emails are polished, context-aware, and written in a tone that closely matches the person being impersonated. They can reference ongoing projects, supplier conversations, invoice numbers, and payment schedules, making them appear entirely legitimate. For busy finance teams processing large volumes of requests each day, these subtle details can make fraudulent communication extremely difficult to distinguish from genuine correspondence.Invoice and Payment Redirection Fraud
One of the most common attacks targeting AP teams involves changing payment details during an active invoice process. Attackers may intercept an existing email chain and alter bank account information before re-sending a legitimate invoice with only minor modifications. In other cases, they impersonate suppliers and request urgent banking updates ahead of an upcoming payment run. Because the surrounding communication is often copied directly from real conversations, the fraud can easily go unnoticed until funds have already been transferred.Voice Cloning and Executive Impersonation
Email is no longer the only attack vector businesses need to consider. AI voice-cloning technology can now replicate a person’s voice using only a short audio sample taken from online meetings, social media clips, or publicly available content. This allows attackers to leave convincing voicemail messages or place calls that appear to come directly from senior leadership. For organisations that still rely on verbal approvals for urgent or high-value transactions, voice cloning removes what many businesses once considered a trusted layer of verification.Why Traditional Security Checks Are No Longer Enough
Security awareness training remains important and continues to play a valuable role in reducing risk. However, AI-driven fraud has fundamentally changed what employees are dealing with. Many of the warning signs staff were trained to identify simply no longer exist. Today’s attacks often contain accurate branding, realistic language, valid supplier references, and contextual information gathered from publicly available sources or previous breaches. When fraudulent requests become indistinguishable from legitimate communication, relying solely on employees to identify scams places too much responsibility on individuals. The organisations reducing risk most effectively are shifting their focus away from instinct and towards process.Building Stronger Protection Around Financial Processes
Make Independent Verification Standard Practice
Any request involving supplier banking changes, urgent payment approvals, or unusual financial activity should require secondary verification through an independent communication channel. That could involve contacting a supplier using a trusted phone number already on file or confirming requests directly with a colleague outside the original email thread. Simple process controls like this remain one of the most effective ways to break the impersonation chain.Strengthen Access Controls and Authentication
Restricting access to finance systems and enforcing multi-factor authentication adds important barriers that can limit the impact of compromised accounts. Even when attackers gain access to a supplier mailbox or internal account, layered security controls can help prevent unauthorised payment changes from progressing unnoticed.Create a Culture Where Staff Feel Comfortable Slowing Down
One of the biggest contributors to successful fraud is urgency. Attackers rely on pressure to bypass normal verification processes. Businesses should actively encourage finance teams to pause, question unusual requests, and verify high-risk transactions, regardless of who appears to be making the request. Employees who take time to confirm payment instructions are protecting the organisation, not delaying operations. That culture starts with leadership reinforcing that security checks should never be bypassed for convenience.AI Is Changing Fraud, but Good Process Still Works
The FBI’s 2025 report included a dedicated section on AI-enabled fraud for the first time, recording more than $893 million in reported losses linked to AI-assisted scams. While the technology behind these attacks is evolving quickly, the core protection strategies remain consistent. Clear verification procedures, layered access controls, and strong operational discipline continue to be highly effective in reducing financial risk. The businesses most resilient to AI-driven fraud are not necessarily those with the most advanced technology. They are the organisations with processes designed to withstand human error, pressure, and impersonation attempts.Shift the Burden from People to Process
AI-enhanced fraud is becoming more convincing, more scalable, and more difficult to detect. That is why businesses can no longer rely solely on employees spotting suspicious emails or unusual requests. Strong process controls must become the foundation of financial security. At ITM Tech, we help organisations strengthen cyber security, improve operational resilience, and reduce exposure to evolving threats targeting finance and business operations. If you are concerned about AI-driven fraud affecting your organisation, our team can help review your current controls and identify areas where additional protection may be needed.
Concerned About AI-Driven Financial Fraud?
AI-powered scams are evolving rapidly, and finance teams are increasingly being targeted through sophisticated impersonation attacks, payment diversion fraud, and business email compromise schemes. At ITM Tech, we help organisations strengthen cyber security, improve operational resilience, and reduce exposure to emerging threats affecting finance and business operations. If you would like guidance on securing your accounts payable processes, reviewing verification controls, or improving protection against AI-driven fraud, contact our team today for a confidential discussion. Visit https://itmtech.ie/ or get in touch to learn how we can help protect your business.FAQs
Why are accounts payable teams frequently targeted by cybercriminals?
Accounts payable teams manage invoices, supplier details, and financial transactions, making them a direct pathway for attackers attempting to redirect payments or commit financial fraud.Can employee awareness training alone prevent AI-driven fraud?
No. Awareness training remains important, but modern AI-generated scams can appear highly convincing. Businesses also need strong verification procedures and layered security controls.Is AI voice cloning a genuine business risk?
Yes. AI voice-cloning technology allows attackers to imitate executives or trusted contacts convincingly, which can undermine traditional phone-based approval processes.
