Is Your Invoice a Deepfake? Securing Your Accounts Payable Process Against Voice and Email Cloning

It’s a statistic that sends a shiver down the back of every small business owner who hears it: according to the FBI’s 2025 Internet Crime Report, business email compromise cost US businesses more than $3 billion last year, making it one of the most financially damaging cybercrimes on record — ahead of ransomware, ahead of data breaches, ahead of almost everything else on the list.

For accounts payable teams at businesses across South Bend, Goshen, and Elkhart, that statistic is quietly becoming more relevant every quarter. AI has made these attacks significantly harder to detect than the clumsy, typo-riddled scam emails everyone learned to spot a decade ago. The question for AP teams is no longer whether they can identify a suspicious request by eye. It’s whether the processes around payments make fraud difficult regardless of how convincing it looks on the screen.

This post covers why AP teams specifically are in the crosshairs, what AI-enhanced fraud actually looks like in practice, why the checks your team was trained on no longer work reliably, and how to build a payment process around the risk instead of around instinct alone.

Why AP teams are in the crosshairs

Accounts payable sits at the intersection of trust and timing. AP teams process invoices, manage supplier details, and execute payments, often under pressure to keep operations running smoothly and vendors paid on schedule. For attackers, that combination is close to ideal.

Most successful fraud doesn’t involve breaking into systems at all. The FBI’s Internet Crime Complaint Center has consistently found that business email compromise attacks rely on impersonation — posing as a trusted executive, supplier, or internal colleague to redirect payments or update bank details before anyone notices something’s off.

AI has made that impersonation dramatically more scalable. Where it once required real skill and time to craft a convincing request, tools are now widely available that automate the research, writing, and contextual tailoring that make fraud blend seamlessly into normal AP workflows. By mid-2024, an estimated 40% of business email compromise phishing emails were already AI-generated, with that share expected to keep growing.

What AI-enhanced fraud looks like in practice

Emails that blend into normal workflow

Traditional phishing relied on volume and imperfection — you’d send a thousand emails hoping ten people didn’t notice the bad grammar. AI has changed that entirely. Modern business email compromise emails are grammatically correct and written in the specific tone of the executive or supplier being impersonated. They reference active projects, current invoice numbers, and upcoming payment runs, all details an attacker would previously have had to dig for manually.

For AP teams processing high volumes of routine communications every day, that level of familiarity is exactly what lowers the guard. Nothing about the email stands out as unusual, because it was specifically built not to.

Invoice and payment redirection

One of the most common AP fraud patterns involves payment redirection. Attackers may intercept a legitimate invoice exchange and quietly alter the destination account, then send a short message claiming a supplier has updated its banking details, or re-issue a real invoice with minor modifications baked in.

The surrounding content looks entirely legitimate because, in many cases, it genuinely is — it’s drawn from real correspondence the attacker already has access to. That’s what makes this pattern so hard to catch by reading alone.

Voice cloning and executive impersonation

Email isn’t the only channel being exploited anymore. AI voice-cloning tools can replicate a person’s voice from a surprisingly short audio sample — sometimes just a few seconds pulled from a public video or a voicemail greeting — making it possible to leave convincing voicemails or place calls that sound exactly like a known executive.

For AP teams accustomed to verbal approvals on high-value or urgent payments, this removes one of the few remaining verification methods that email security alone was never designed to address.

Why traditional checks no longer work

Security awareness training still matters, and investing in it remains genuinely worthwhile. But AI has changed what AP teams are up against in a way that most existing training programs haven’t caught up to yet.

Attacks no longer contain the signals that training programs once focused on: awkward phrasing, mismatched logos, odd sender addresses, generic greetings that don’t quite fit. Modern fraud emails can reference the recipient’s organization, active suppliers, and current invoice values drawn from publicly available or previously intercepted sources, which makes them read as completely unremarkable.

When a fraudulent request is indistinguishable from a legitimate one by sight, placing the burden of detection entirely on the AP team puts that burden in the wrong place. The organizations that actually reduce risk aren’t asking their staff to become more suspicious. They’re building verification processes that work independently of how convincing a message looks on the page.

Building process around the risk

The most effective defense isn’t sharper instincts. It’s removing ambiguity from high-risk actions entirely, so the outcome doesn’t depend on any one person catching something in the moment.

Out-of-band verification as standard practice

Any request to change supplier bank details or approve an urgent payment outside the normal cycle should require secondary confirmation through a known, independent channel — not a reply to the same email thread the request arrived on. Calling a supplier on a number already on file, or confirming with a colleague directly and in person, breaks the impersonation chain regardless of how convincing the original request appeared to be.

This step doesn’t require any new technology. It requires a written procedure and a team habit of actually following it, every time, including when the request claims to be urgent, especially when it claims to be urgent.

Layered access and authentication controls

Restricting access to financial systems and enforcing multi-factor authentication limits the damage a compromised account can cause even if something does slip through the first layer. If an attacker gains access to a vendor’s email, MFA requirements on the receiving end create friction that can slow or stop a fraudulent change before any money actually moves.

A culture that supports slowing down

Fraud prevention improves when staff feel genuinely safe questioning requests, including ones that appear to come from senior leadership. A team member who pauses a payment to verify it isn’t being obstructive or difficult. They’re doing exactly what good process requires, and that needs to be said out loud by leadership, not just implied.

Building that culture starts with leadership modeling the behavior themselves and making it unmistakably clear that slowing down on high-risk actions is always the right call, never something that reflects poorly on the person doing the verifying.

The FBI’s 2025 Internet Crime Report included a dedicated AI section for the first time, logging more than $893 million in AI-enabled scam losses across more than 22,000 complaints. When verification is standard practice and questioning is genuinely encouraged rather than tolerated, AI-enhanced fraud loses much of its advantage. The technology attackers use is advancing quickly, but the process controls that contain the damage don’t have to be complicated. They have to be consistent, applied every single time, without exception for anyone.

What this looks like at a typical Michiana supplier relationship

Picture a mid-sized manufacturer working with a long-standing supplier, the kind of relationship that’s run smoothly for years with a familiar contact on both ends. An email arrives, apparently from that contact, noting the supplier has switched banks and needs the next payment routed to a new account. The tone matches. The invoice number is correct. The email even references a delivery scheduled for the following week, a detail that would only be known to someone genuinely inside that relationship — except an attacker who intercepted a few weeks of correspondence has exactly that same information.

Without a verification step outside that same email thread, there’s genuinely nothing in the message itself that distinguishes it from a real update. The AP clerk processing it isn’t being careless. They’re doing exactly what the process has always asked of them, and the process is what failed, not the person. A single phone call to the supplier’s known contact number, made before the payment goes out, would have caught this in under two minutes. That’s the entire difference between a routine Tuesday and a very expensive one.

This is why we push clients toward process fixes over training alone. Training asks a person to notice something wrong in a message specifically engineered to have nothing wrong with it. A phone call to a known number sidesteps that problem entirely, because it doesn’t depend on spotting anything at all.

What a 30-minute rollout actually looks like

None of this requires an overhaul of your finance systems or a lengthy procurement process. A written out-of-band verification policy, one page long, naming a dollar threshold and a required callback step, can be drafted and signed off by leadership in a single short meeting. The harder part isn’t writing the policy. It’s making sure the whole team knows it exists, understands why it exists, and has actually seen it applied at least once before the first real test comes along.

We recommend running a brief, low-stakes practice scenario with your AP team shortly after the policy goes live — a simulated “urgent payment request” that walks through the verification steps end to end. It takes less time than most people expect, and it turns an abstract policy into muscle memory before a real attacker ever tests it for you.

Worth building into the same rollout: a short, standing list of every supplier’s verified callback number, kept somewhere your AP team can reach it quickly, separate from the email system that could theoretically be compromised. It sounds almost too simple to matter, and that’s exactly why it works. Fraud built on convincing content has no answer for a verification step that never looks at the content in the first place.

Shift the burden from people to process

The businesses that come through this unscathed aren’t the ones with the most suspicious employees. They’re the ones whose payment process doesn’t care how convincing the request looks, because the verification step happens regardless. That’s a far more reliable defense than hoping everyone stays sharp on a Friday afternoon with a dozen other things demanding their attention.

Frequently Asked Questions

Why are Accounts Payable teams targeted so often?

AP teams manage payments and supplier details directly, making them a straightforward path for attackers to move money without ever needing to breach a technical system.

Can awareness training alone stop AI-driven fraud?

No. Awareness helps, but AI-generated scams often look completely legitimate. Strong out-of-band verification processes are essential alongside any training program.

Is voice-based fraud really a realistic risk for a small business?

Yes. AI voice cloning allows attackers to impersonate executives convincingly from a short audio sample, making phone-based approvals a real vulnerability even for businesses that don’t consider themselves high-profile targets.

What’s an out-of-band verification threshold most businesses use?

Common thresholds are $10,000 or $25,000, though any bank detail change should require verification regardless of amount. The threshold matters less than consistently enforcing it once set.

Does this kind of fraud only target large companies?

No. AI has lowered the cost of running convincing business email compromise campaigns, which makes small and mid-sized businesses just as reachable a target as larger ones, often with fewer defenses in place to catch it.


Graham’s Take

We’ve talked to more than one business owner in the South Bend area who assumed this kind of fraud only happened to companies far bigger than theirs. The economics have shifted, and it doesn’t take much AI horsepower anymore to make an email or a voicemail sound exactly right. The good news is the fix is almost entirely process, not technology, and it’s genuinely one of the fastest wins we help clients put in place.

Free 12-Point IT & Cybersecurity Checkup

30 seconds to book. No pitch. No obligation. You keep the plain-language report either way.