At a Glance:
- Payment fraud remains a widespread business challenge, with 76% of organizations reporting attempted or actual payments fraud in 2025.
- Common scams include business email compromise (BEC), vendor impersonation, account takeover and check fraud.
- AI-generated voice cloning and deepfakes are making impersonation schemes more convincing.
- Verifying payment requests through a trusted channel can help reduce fraud risk.
- Strong payment controls, employee awareness, and account monitoring can help businesses protect themselves from financial loss.
Payment fraud continues to evolve, with criminals using a combination of social engineering, business email compromise (BEC), and emerging AI tools to make fraudulent requests appear more credible and harder to detect. Meanwhile, the speed of modern payments may leave little time to catch a fraudulent transaction before funds are gone.
As fraud tactics become more sophisticated, businesses are feeling the impact – regardless of their size, location, or industry. In fact, more than three-quarters (76%) of organizations reported attempted or actual payments fraud in 2025, highlighting just how common these threats have become[1].
The good news is that businesses can help reduce their risk by understanding the latest threats and building strong payment verification practices into their daily operations.
What Is Payment Fraud?
Payment fraud occurs when criminals use deception, stolen information, or unauthorized access to initiate or redirect a financial transaction for their own gain.
Fraud can affect businesses of all sizes and can occur through checks, ACH payments, wire transfers, payment cards, digital payment platforms, and other payment channels.
While tactics continue to evolve, many attacks share a common goal: convincing an employee, business owner, or authorized user to approve a payment that benefits a criminal rather than the person or business they're meant for.
“Fraudsters don't need to hack into your systems if they can convince someone to send the money for them,” said Josh Del Valle, PNC’s Head of Enterprise Fraud. “That's why we're seeing more attacks built around trust, urgency, and human behavior.”
What Are the Most Common Payment Fraud Scams?
Understanding the most common fraud tactics may help businesses recognize warning signs before money leaves an account.
Business Email Compromise (BEC)
Business email compromise occurs when criminals pose as executives, vendors, employees, or trusted partners to request payments, gift cards, sensitive information, or changes to payment instructions.
These scams often rely on realistic email addresses, convincing language, and urgent requests designed to pressure employees into acting quickly. BEC remains one of the most common forms of payments fraud affecting organizations today.
“Most payment fraud doesn't start with a broken security system,” Del Valle said. “It starts with a seemingly routine email. That's what makes business email compromise so effective and so dangerous.”
Vendor Impersonation
In a vendor impersonation scam, a fraudster pretends to be a supplier and requests that future payments be sent to a new bank account. If the change goes undetected, legitimate payments may be routed directly to criminals.
Account Takeover
Fraudsters may gain access to online banking, email accounts, or payment platforms through stolen passwords, phishing attempts, or compromised credentials. Once inside an account, criminals can initiate transactions, alter payment instructions, or access sensitive business information.
Check Fraud and Mail Theft
Despite the growth of digital payments, checks remain a frequent target for criminals. Check washing, counterfeit checks and forged endorsements continue to create losses for businesses and consumers. Mail theft also remains a concern with the U.S. Department of the Treasury’s Financial Crimes Enforcement Network identifying more than $688 million in suspicious activity related to mail theft-related check fraud during a six-month review period[2].
Businesses that continue to use checks may benefit from fraud mitigation tools such as Positive Pay, which can help identify suspicious check activity before payment is processed.
How Are Criminals Using AI and Deepfakes?
Artificial intelligence is creating new opportunities for criminals to impersonate trusted individuals.
AI-generated voice cloning and deepfake technologies can be used to mimic executives, vendors, or business partners with increasing accuracy. In some cases, employees may receive a phone call, voicemail, or video message that appears to come from someone they know and trust.
“What's changing is how convincing the scams have become,” Del Valle said. “A payment request might look like it came from your CEO. It might sound like a trusted vendor. That's why independent verification matters more than ever.”
What Should You Do Before Sending a Payment?
One of the most effective defenses against payment fraud is verification.
Before approving a payment, consider these best practices:
- Verify payment requests through a trusted communication channel.
- Confirm changes to vendor payment information by calling a known contact.
- Require dual approval for significant transactions.
- Review unusual or unexpected payment requests carefully.
- Enable multi-factor authentication on financial accounts and business systems.
- Monitor accounts regularly for suspicious activity.
- Train employees to recognize fraud attempts and escalation procedures.
To help strengthen ACH payment security, businesses may consider tools that can filter or block unauthorized ACH debits and reduce account exposure by allowing ACH credits to be received without sharing actual bank account numbers. PNC offers these capabilities through ACH Debit Authorization solutions and Universal Payment Identification Code®.
Pause Before You Pay
Many fraud schemes rely on creating a sense of urgency.
Whether a message claims a payment is overdue, a shipment is being delayed, or an executive needs an immediate transfer, criminals often try to rush decision-making and discourage verification.
“One of the best fraud controls is surprisingly simple: pause before you pay,” Del Valle said. “If someone is pressuring you to act immediately, that's exactly when you should take a closer look.”
How Can Small Businesses Reduce Fraud Risk?
Some small business owners believe fraudsters are focused primarily on large corporations. In reality, businesses of all sizes can be targets.
“Small businesses often think they're too small to be targeted,” Del Valle explained. “In reality, fraudsters are looking for opportunity, not company size. Every business should assume it's a potential target and implement effective controls to reduce the risk of fraud and scams.”
Small businesses can help strengthen their defenses by:
- establishing payment approval procedures;
- limiting account access to authorized users;
- segregating financial duties when possible;
- using multifactor authentication (not solely on passwords);
- setting up alerts to identify unusual transactions;
- conducting regular employee awareness training; and
- working with their financial institution to evaluate available fraud-prevention tools.
The Bottom Line
Payment fraud is constantly evolving, but most successful scams still rely on one thing: convincing someone to trust the wrong request.
By combining employee awareness, strong verification procedures, layered security controls, and routine account monitoring, businesses may reduce their exposure and help protect their finances from increasingly sophisticated fraud attempts.
“Digital payments make doing business easier, and they're here to stay,” Del Valle said. “The goal isn't to slow your business down. It's to build simple verification habits that help you move quickly and safely.”
Help Protect Your Business from Payment Fraud
Fraud tactics continue to evolve, but the right controls can help reduce your risk. Explore PNC's fraud mitigation tools and treasury management solutions to learn how your business may benefit from services designed to help detect and prevent unauthorized transactions.