Cybercriminals are using AI to create more convincing invoice and payment scams. A fraudulent email may use the correct company logo, reference a real project, copy a familiar writing style, or even include a voicemail that sounds like a known executive.
One common tactic involves changing vendor banking information. An attacker may send what appears to be a normal invoice or reply inside an existing email conversation, but the payment details have been replaced. Another tactic is impersonating a CEO, manager, or supplier and requesting an urgent payment.
These scams work because they blend into normal business activity. The message may look polished, include accurate details, and create just enough urgency to make an employee act before verifying the request.
How to Stay Safe:
Do not rely on an email, invoice, or voice message alone when approving payments. Any request to change banking information, add a new vendor, or rush a payment should be confirmed through a separate, trusted method.
Call a known phone number already on file or speak directly with the person making the request. Do not use contact information included in the suspicious message, and do not simply reply to the same email thread.
Businesses should also require additional approval for large payments, limit who can change vendor information, enable multi-factor authentication, and regularly review access to financial systems. Taking a few extra minutes to verify a request can prevent a costly fraudulent payment.