Business email compromise (BEC) cost US businesses more than $3 billion last year, according to the FBI’s 2025 Internet Crime Report. If you think Australian businesses are insulated from that figure, think again — the ACSC’s Annual Cyber Threat Report consistently flags BEC as one of the most financially damaging threats facing local organisations, and AI has made it significantly harder to spot.
For accounts payable (AP) teams, the question is no longer whether staff can identify a suspicious request. It’s whether your payment processes make fraud difficult regardless of how convincing the request looks.
Why AP Teams Are in the Crosshairs
AP sits at the intersection of trust and time pressure. Your team processes invoices, manages supplier banking details, and approves payments — often at pace, with minimal friction by design. For an attacker, that’s an ideal target.
The FBI’s Internet Crime Complaint Center has consistently found that BEC attacks rely on impersonation — posing as a trusted executive, supplier, or internal colleague to redirect funds or update bank details before anyone notices. AI has made that impersonation dramatically more scalable. By mid-2024, an estimated 40% of BEC phishing emails were already AI-generated, and that share is growing.
What AI-Enhanced Fraud Looks Like in Practice
Emails That Blend Into Normal Workflow
Traditional phishing relied on volume and obvious mistakes. Modern BEC emails are grammatically perfect and written in the specific tone of whoever is being impersonated. They reference active projects, current invoice numbers, and upcoming payment runs. For AP staff processing high volumes of routine communications, that level of familiarity is exactly what lowers the guard.
Invoice and Payment Redirection
One of the most common patterns involves quietly altering the destination account on a legitimate invoice exchange, then sending a short follow-up claiming the supplier has updated their banking details. The surrounding content looks legitimate because, in many cases, it’s drawn from real correspondence.
Voice Cloning and Executive Impersonation
Email isn’t the only channel being exploited. AI voice-cloning tools can replicate someone’s voice from a short audio sample — enough to leave a convincing voicemail or place a call that sounds like your CFO. For AP teams accustomed to verbal approvals on high-value payments, this removes one of the few remaining verification methods that email security alone cannot address.
Why Traditional Checks No Longer Hold Up
Security awareness training still matters and is worth investing in. But AI has changed what AP teams are up against. Modern fraud emails no longer contain the signals training programs once focused on: awkward phrasing, mismatched logos, or generic greetings. When a fraudulent request is indistinguishable from a legitimate one, placing the burden of detection entirely on your AP team is the wrong approach.
Organisations that reduce risk aren’t asking staff to be more suspicious. They’re building verification processes that work independently of how a message looks.
Building Process Controls That Actually Work
Out-of-Band Verification as Standard Practice
Any request to change supplier banking details or approve an urgent payment outside the normal cycle should require secondary confirmation through a known, independent channel — not a reply to the same email thread. Call the supplier on a number already on file, or confirm directly with a colleague. This breaks the impersonation chain regardless of how convincing the original request appeared.
This doesn’t require sophisticated technology. It requires a written procedure and a team culture that follows it consistently.
Layered Access and Authentication Controls
Restricting access to financial systems and enforcing multi-factor authentication — Microsoft Entra ID makes this straightforward for M365 environments — limits the damage a compromised account can cause. If an attacker gains access to a supplier’s email, MFA requirements on your end create friction that can stop a fraudulent change before any money moves. Microsoft Defender can also flag anomalous sign-in behaviour and suspicious email patterns as an additional layer.
A Culture That Supports Slowing Down
Fraud prevention improves when staff feel safe questioning requests — including from senior leadership. A team member who pauses a payment to verify it isn’t being obstructive. They’re doing exactly what good process requires. Leadership needs to model that behaviour and make clear that slowing down on high-risk actions is always the right call, not an inconvenience.
Shift the Burden From People to Process
The FBI’s 2025 Internet Crime Report logged more than $893 million in AI-enabled scam losses across more than 22,000 complaints — and that’s just what was reported. When verification is standard and questioning is encouraged, AI-enhanced fraud loses much of its advantage.
The technology attackers use is advancing quickly. The process controls that contain the damage don’t have to be complicated — they just have to be consistent.
If you’d like to review your current AP controls and identify where the gaps are, get in touch with the team at IT TechNinjas or learn more about our Safe to Scale programme.