Articles
From BEC to Deepfakes, Payments Fraud Is Only Getting More Sophisticated
- By AFP Staff
- Published: 7/22/2026

You’re sitting in a meeting when your phone buzzes. It’s an email from your boss marked “urgent.” They’re asking you to authorize an immediate payment. It sounds like them. It’s perfectly worded and formatted — very convincing.
Except … your boss is sitting right next to you.
This is a true story, as told by Chris Ward, Head of Enterprise Payments at Truist, during AFP's companion webinar for the 2026 AFP Payments Fraud and Control Survey, underwritten by Truist.
The results of the survey, which gathered data from more than 400 respondents across various industries and company sizes, emphasize that anyone or any organization can be targeted. Vigilance and human judgment are paramount to combating payments fraud at a time when fraud attacks are only becoming more sophisticated.
Business email compromise remains a major concern in 2026
Business email compromise (BEC) was cited by 70% of AFP survey respondents as the top avenue of attempted or actual fraud. The 2025 FBI Internet Crime Report (IC3) backs that up: BEC ranks second in total financial losses in the U.S., accounting for roughly $30 billion annually.
As the tools available to the public have become more sophisticated (e.g., LLMs such as ChatGPT and Claude), so too have the fraudsters. “One of the things that used to tip you off was a grammatical error or a spelling error,” said Ward. “Now you can run that through whatever LLM, clean it up and send a beautifully worded email.”
The impersonation attempts coming through email, text and even phone calls are increasingly polished — and convincing. “You can't just rely on catching something that doesn't look like a business email compromise because you were counting on something being spelled wrong,” said Ward.
As a result, procedure, not perception, has become the best defense.
Fraud is increasing, but prevention is improving
Sumit Advani, a former treasurer with experience at a buy-now-pay-later company, offered a firsthand example of how creative and organized fraudsters can be. His company began seeing a pattern where consumers would apply for loans using burner phones, make the first payment (~25% of the total), then disappear.
The purchases were almost always for items that could be resold immediately, for example, concert tickets — “things you could get right away and then sell right away for a significant return,” said Advani. “We'd find out later that they were fraud.”
Their fix was to partner with a service that analyzed phone numbers, flagging how long a number had been in existence, and if it was likely a burner. That step became part of the loan approval process.
Why checks are (still) being used despite being fraudsters’ favorite target
Checks are still the payment method most often targeted by fraud — and 87% of survey respondents are still using them. The reasons are often outside the organization's control: State and local governments require checks for certain tax payments; small vendors often prefer checks, either for simplicity or because they're reluctant to share banking details; and rural businesses and individual contractors frequently have no other option.
A great example of how this payment rail can go awry came from the pandemic. One of Ward’s clients stopped processing client refunds, and when they returned to the office, “they had trays and trays and trays of returned checks,” he said. “It was just a nightmare.”
For organizations that want to start chipping away at check volume, Ward offered some simple advice: change your vendor setup form. “You don't even have to change the system,” he said. “You just take the check option off the form.” For the occasional vendor who requires payment by check, you can handle it as an exception — but stop making it the default.
Most organizations aren't sure if they've been hit by a deepfake
Only 6% of survey respondents reported a confirmed deepfake-related incident, but 40% said they were unsure whether it had happened to them — a finding the panelists flagged as significant.
Advani shared a firsthand account of a case where someone deepfaked a wire payment request via Slack. The incident prompted a significant overhaul of verification procedures. New vendors were required to appear on a recorded video call — Google Meet or Zoom — to verbally confirm their banking details and make sure everything was legitimate before processing the payment. That recording was then kept on file so there was a record in case anything went wrong later.
“You have to have controls around your technology and IT teams,” said Advani. “There are things we can do on our end as operators as well. One is to make sure you know who's on the other end. If you see your boss on the other end, and they're in a chateau, and it's snowing and you know it's summertime in New York, you should get the idea that it's probably not them.”
He also shared a practical, low-tech tip for dealing with suspicious links: copy the URL, paste it into an AI tool and ask whether it's legitimate. Advani recently did this with a link ending in “vu.” The AI tool flagged it as likely fake because there are not many companies that exist in that country.
What is important to note in regard to deepfakes is that the technology used to replicate voices, faces and communication styles is rapidly advancing. The defensive move isn't to out-tech the fraudster; rather, it's to build procedures that require verification through channels and methods that are harder to fake, such as an independent call to a known number, a recorded video session or a physical confirmation.
AI’s role in fraud defense is promising but requires guardrails
The panelists were broadly optimistic about AI's potential — 38% of survey respondents are considering using it — with one crucial caveat: Don't upload your fraud procedures to a public LLM.
"When you're using an LLM and you put your fraud procedures into one that's in the public, your information is now in the public for the LLM to remember," said Ward. "You do not want your fraud procedures to be out in the open domain where any fraudster now knows how you are protecting yourselves."
It’s a matter of convenience for most. You want a quick audit of your controls, so you paste them into a public LLM and ask for feedback. The problem is that public AI tools retain and learn from that input; there's no guarantee your proprietary procedures stay private.
Advani offered a workaround: instead of feeding the AI your procedures, ask it what you're missing: "These are the controls I have in place — what is new? What is different?" Use AI as a gap-analysis tool rather than a document processor.
The broader point Ward made regarding AI use is this: AI doesn't replace controls; it augments them. It can enhance detection speed and scale, but like any tool, it can also give you bad answers when used incorrectly. The controls you apply to AI-assisted processes need to be just as thorough as those applied everywhere else.
Human judgment is your best defense
The number of respondents who have experienced actual or attempted payments fraud has held steady at more than 75% for years. And recovery remains a challenge, with only 30% of victims recouping more than 75% of stolen funds, and 20% recouping nothing at all.
There are a number of technologies that can help mitigate the effects of payments fraud, but it’s the small, deliberate procedural decisions made by people who are paying attention that serve as the best defense.
Download the 2026 AFP Payments Fraud and Control Survey Report to learn how organizations are currently experiencing payments fraud trends and are responding to increasingly sophisticated schemes.
Copyright © 2026 Association for Financial Professionals, Inc.
All rights reserved.
