16/06/2026
They're the kind of stats that make any small business owner or finance team sit up straight.
According to the FBI’s 2025 Internet Crime Report, business email compromise (BEC) cost US businesses more than $3 billion last year alone. Here in Australia, the average cost of a cyber incident across all Australian businesses rose 50% to $80,850 in the 2024–25 financial year, with the increase mostly driven by BEC. That puts it right up there as one of the most financially damaging cyber threats we’re seeing.
And the uncomfortable reality is that these attacks are getting harder to spot.
AI has changed the game. The question for accounts payable teams isn’t just “can we spot a dodgy email?” anymore, but “do our processes actually stop fraud, even when it looks completely legitimate?”
Why AP Teams Are in the Firing Line
Accounts payable sits right in the middle of trust and urgency.
Your team is processing invoices, updating supplier details, and pushing payments through, often under pressure to keep things running smoothly. That’s exactly what attackers are counting on.
Most of these fraud incidents don’t come from someone hacking your systems. They come from impersonating a trusted contact.
That could be:
A senior exec asking for an urgent payment
A supplier updating their bank details
A colleague following up on an invoice
AI has made this far more scalable. What used to take time and effort can now be automated: researching your business, mimicking writing styles, and crafting messages that blend seamlessly into everyday workflows.
By mid-2024, around 40% of BEC phishing emails were already AI-generated. And it’s only heading one way.
What This Actually Looks Like Day to Day
Emails that feel completely “normal”
This isn’t the old-school phishing with typos and dodgy formatting.
These emails are clean, well-written, and often sound exactly like the person they’re impersonating. They reference:
Real projects
Active suppliers
Current invoice numbers
Upcoming payment runs
When your team is processing dozens (or hundreds) of emails, that familiarity is what lowers the guard.
Payment redirection scams
One of the most common plays we see is simple and effective.
An attacker gets visibility of a legitimate invoice chain, then steps in at the right moment to:
Change bank details
Resend an invoice with subtle edits
Send a “quick update” about payment info
Because it’s based on real correspondence, it looks completely genuine.
Voice cloning and exec impersonation
It’s not just email anymore.
AI tools can now replicate someone’s voice with very little source audio. That means:
Convincing voicemails
Phone calls that sound legitimate
For teams that rely on verbal approvals for urgent payments, that’s a real concern.
Why the Old Checks Aren’t Enough
Training still matters. It always will.
But the signals people have been trained to look for are disappearing:
No spelling mistakes
No weird formatting
No obvious red flags
Modern attacks can reference your organisation, your suppliers, and your real data.
At that point, asking someone in AP to “just be more careful” isn’t fair or effective.
The businesses that are getting this right aren’t relying on gut feel. They’re building processes that work regardless of how convincing something looks.
Building Process Around the Risk
The biggest shift is in moving from awareness to control.
Make out-of-band verification non-negotiable
If there’s a request to:
Change bank details
Approve an unusual or urgent payment
It should always be verified through a separate, trusted channel.
That could be:
Calling a supplier on a known number
Speaking directly with an internal approver
Never rely on replying to the same email thread.
This doesn’t require fancy tech. It just requires a clear process and consistency.
Lock down access and authentication
If something does get through, you want to limit the blast radius.
That means:
Restricting who can change financial data
Enforcing MFA everywhere it matters
Segmenting access to systems
If an attacker gains email access, these controls can be the difference between a near miss and a costly mistake.
Create a culture where it’s OK to slow down
This one comes back to leadership.
If your team feels pressured to “just get it done”, mistakes will happen.
We need to flip that:
It should be normal to question requests
It should be encouraged to pause payments
It should feel safe to push back, even on senior people
Delaying a payment to verify it is exactly what good looks like.
Shift the Burden from People to Process
The FBI’s latest report also highlighted over $893 million in AI-enabled scam losses, across more than 22,000 complaints.
That’s not a small problem. And it’s not slowing down.
But the good news is that you don’t need complex solutions to reduce risk.
What works is:
Clear processes
Consistent verification
A team that feels supported to follow them
When you get that right, even the most convincing attack loses its edge.
If you’re worried about how exposed your finance process might be, or just want a second set of eyes over it, we’re always happy to have a practical, no-nonsense conversation about where the real risks are.
No scare tactics. Just clarity.