Skip to main content
Get a quote
Compliance & Risk

When Fake Emails, Voices and Invoices Look Real

Rana8 June 20267 min read
The New Fraud Risk for Businesses: When Fake Emails, Voices and Invoices Look Real
Key takeaways
  • AI-powered impersonation has turned fraud from a cybersecurity problem into a financial control problem, with convincing fake emails, cloned voices and realistic invoices.
  • Invoice fraud and authorised push payment fraud often rely on social engineering rather than hacking, manipulating people instead of breaking into systems.
  • Strong internal controls — segregation of duties, payment approval thresholds, dual authorisation for bank detail changes and clear escalation rules — are among the best defences.
  • Always verify any change in supplier bank details through a separate, trusted communication channel rather than replying to the original email.
  • Technology should support controls, not replace them; a culture where staff feel safe to question urgent or unusual requests is essential.

Business fraud has always existed, but the way it happens is changing quickly. In the past, many scams were easier to spot. Emails were badly written, sender addresses looked suspicious, and fake invoices often had obvious mistakes. Today, fraud is becoming more convincing.

Criminals can now use artificial intelligence to write professional emails, imitate communication styles, create fake documents, clone voices, and produce deepfake video or audio content. This makes impersonation fraud harder to detect, especially when businesses rely heavily on email approvals, remote working, online payments, and fast decision-making.

For companies, this is no longer only a cybersecurity issue. It is a financial control issue.

AI-Driven Impersonation and Executive Fraud

The European Payments Council's 2025 Payments Threats and Fraud Trends Report warned that fraudsters are using AI to create highly convincing phishing messages, SMS scams, and even voice or video deepfakes. The report specifically noted that these tools can help attackers impersonate executives, bank employees, or trusted contacts with much greater realism. The practical risk for businesses is clear: staff may be persuaded to approve payments, change bank details, disclose information, or bypass normal procedures because the request appears legitimate.

Europol has also highlighted the growing role of AI in organised crime. Its 2025 Serious and Organised Crime Threat Assessment noted that AI-powered voice cloning and live video deepfakes can enable new forms of fraud, extortion, and identity theft. This is particularly concerning for businesses because trust is often built around familiar names, voices, and relationships.

Invoice Fraud and Social Engineering

Invoice fraud is one of the most relevant risks for companies. A fraudster may intercept communication between a business and a supplier, then send updated bank details before payment is made. The invoice may look real, the email may appear to come from the supplier, and the amount may match an expected transaction. If internal controls are weak, the business may only discover the fraud after funds have already been transferred.

This type of fraud is dangerous because it does not always require hacking into complex systems. Often, it relies on social engineering. The criminal manipulates people, not just technology.

Authorised Push Payment Fraud

Authorised push payment fraud is another important example. This occurs when a victim is tricked into sending money to a fraudster. UK Finance's Annual Fraud Report 2025 reported that authorised push payment fraud losses in the UK were just over £450 million in 2024, although overall losses and cases had fallen compared with the previous year. The fact that losses remain so high shows how serious the issue continues to be, even where banks and financial institutions are investing heavily in fraud prevention.

For businesses, the lesson is not only that fraud is increasing or becoming more advanced. The lesson is that traditional controls may no longer be enough.

A payment request may appear to come from the managing director. A supplier email may look normal. A phone call may sound familiar. A PDF invoice may contain the correct branding. A message may refer to real projects, real clients, and real amounts. In this environment, businesses cannot rely only on instinct.

They need process.

Internal Controls and Verification

A deepfake invoice and spoofed email caught by a verification check

Strong internal controls are one of the best protections against fraud. This includes proper segregation of duties, payment approval thresholds, supplier verification procedures, dual authorisation for bank detail changes, and clear escalation rules for urgent or unusual requests. If you are unsure whether your current procedures would withstand a convincing impersonation attempt, an accounting health check can help surface the gaps before they are exploited.

One practical control is to verify any change in supplier bank details through a separate communication channel. If new bank details are received by email, the business should not reply directly to that email. It should contact the supplier using a trusted phone number or contact already held on file. This simple step can prevent serious losses.

Another important control is dual approval for payments above a certain value. No single person should be able to create, approve, and release significant payments without review. This is especially important for SMEs, where teams may be small and informal approval habits can develop over time.

The table below summarises how common fraud techniques map to the practical controls that help defend against them.

Fraud technique Practical control
Changed supplier bank details by email Verify the change through a separate, trusted channel held on file
Impersonated executive or supplier payment request Segregation of duties and dual authorisation above a set threshold
Urgent, confidential or "avoid consequences" pressure Treat urgency as a warning sign; clear escalation rules
Intercepted invoice matching an expected amount Supplier verification procedures and approval thresholds
Fraudulent or incorrect payment slipping through Regular reconciliation and review of bank payments and balances

Culture, Training, and Urgency

Businesses should also be cautious with urgent requests. Fraudsters often create pressure by saying a payment is urgent, confidential, delayed, or required to avoid consequences. Staff should be trained to recognise urgency as a warning sign rather than a reason to bypass controls.

This is where culture matters. Employees should feel comfortable questioning unusual requests, even if they appear to come from senior management. A good control environment does not punish staff for checking. It encourages them to verify.

Technology can also help. Email security tools, payment verification systems, accounting software controls, bank alerts, and fraud detection features can reduce exposure. However, technology should support controls, not replace them. A business can still lose money if staff are trained to override warnings or if approval procedures are unclear.

Public Information and Financial Review

The rise of AI-driven fraud also means businesses should review their use of public information. Criminals can use details from websites, social media, LinkedIn posts, company announcements, and public filings to make scams more believable. The more a fraudster knows about a company's staff, suppliers, projects, and communication style, the easier it becomes to create a convincing impersonation.

This does not mean businesses should stop communicating publicly. It means they should understand how public information can be misused and ensure internal procedures are strong enough to withstand convincing requests.

Financial reporting also plays a role. Regular review of bank payments, supplier balances, unusual transactions, and reconciliation differences can help identify issues earlier. If reconciliations are delayed, fraudulent or incorrect payments may remain unnoticed for longer. This is one area where having reliable accounting, tax and advisory support keeps the numbers current enough to spot anomalies quickly.

Governance and the Cost of Fraud

For directors, fraud prevention should be treated as part of governance. The question is not whether staff are trustworthy. The question is whether the business has controls that protect both the company and its employees from manipulation.

A well-designed process protects everyone. It gives staff a clear reason to verify requests, reduces pressure on individuals, and creates a documented trail of approvals.

The cost of fraud can be more than the amount stolen. It can include disruption, legal costs, insurance issues, reputational damage, supplier disputes, management time, and weakened trust inside the business. For smaller companies, even one fraudulent payment can create serious cash flow pressure.

Fraud is becoming more sophisticated, but many of the best defences remain practical. Verify changes. Separate duties. Approve payments properly. Train staff. Review transactions. Keep supplier records updated. Question urgency. Document processes.

Businesses do not need to become experts in every fraud technique. They do need to build a control environment where fake requests are less likely to succeed.

In a world where emails, voices, invoices, and even video calls can be manipulated, trust alone is no longer enough.

Businesses need verification.

If you would like help reviewing your payment and supplier controls, speak to an advisor before the next convincing request lands in your inbox.

Frequently asked questions

01Why is AI-driven fraud harder to detect than traditional scams?

In the past, scams were often easy to spot because emails were badly written, sender addresses looked suspicious, and fake invoices had obvious mistakes. Criminals can now use artificial intelligence to write professional emails, imitate communication styles, create fake documents, clone voices and produce deepfake video or audio, making impersonation far more convincing.

02What is the most practical control against supplier bank detail fraud?

Verify any change in supplier bank details through a separate communication channel. If new bank details arrive by email, do not reply directly to that email — contact the supplier using a trusted phone number or contact already held on file. This simple step can prevent serious losses.

03Why should urgent payment requests be treated with caution?

Fraudsters often create pressure by claiming a payment is urgent, confidential, delayed, or required to avoid consequences. Staff should be trained to recognise urgency as a warning sign rather than a reason to bypass controls, and should feel comfortable questioning unusual requests even when they appear to come from senior management.

04Is fraud prevention only an IT or cybersecurity responsibility?

No. For directors, fraud prevention should be treated as part of governance and financial control. The question is not whether staff are trustworthy, but whether the business has controls that protect both the company and its employees from manipulation. Regular financial review and reconciliation also help identify issues earlier.

Back to Insights

Always.

Accounting, tax, audit and corporate services from a licensed Malta audit firm — delivered through one secure portal.