Introduction
A longtime vendor emails your accounts payable team about updated banking details for an upcoming payment. The message comes from the right address, references the correct invoice number, and matches the tone of every other email from that contact. Someone in finance updates the record and processes the payment on schedule.
Three weeks later the real vendor calls to ask why they haven’t been paid.
Nothing in that sequence was a technology failure. No malware ran. No firewall was bypassed. Nobody clicked a bad link, because there wasn’t one. The email was clean, the request was plausible, and a competent employee did exactly what the process allowed them to do.
This is the shape of most business fraud now, and it’s the reason security tools alone don’t stop it.
The Numbers Point in One Direction
The FBI’s Internet Crime Complaint Center received just over a million complaints in 2025, with reported losses of $20.9 billion, up 26% from the year before. Business email compromise accounted for roughly $3 billion of that on its own.
What stands out isn’t the total. It’s the category. The overwhelming majority of those losses came from cyber-enabled fraud, meaning someone was persuaded to do something rather than a system being broken into. The money left through a normal transaction, approved by a real employee, using credentials that belonged to them.
That distinction matters when you’re building a defense against it. You can’t patch this, and no product on the market will catch all of it, because nothing technically “anomalous” is happening.
What the Fraud Is Actually Targeting
The target isn’t your network. It’s the set of rules your business uses to decide that a payment is legitimate.
Every organization has one, even if nobody wrote it down. Certain people can approve certain amounts. Some requests need a second signature and others don’t. Banking changes get handled a particular way, or they get handled however seems reasonable at the time. That informal rulebook is the actual control, and it’s usually the weakest thing in the building because it was never designed, it simply accumulated.
Fraud works by finding the seams within that accumulated rulebook. A request that arrives on a Friday afternoon when the person who’d normally check is out. An amount just below the threshold that triggers a second approval. A sender who appears senior enough that questioning them feels awkward. None of this is sophisticated, it’s just attentive.
Why It Works Best on Good Employees
It’s worth being clear about this, because the instinct after an incident is to look for the person who “made the mistake”.
The employee who processed that payment wasn’t careless. They were responsive, which is what most businesses ask of their finance teams. They were working within a process that permitted a single person to act on a written request without confirming it through another channel. Given that process, the outcome was available to anyone who asked for it convincingly enough.
The same dynamic shows up whenever speed gets prioritized over verification. A business that treats every delay as friction will eventually approve something it shouldn’t, and the person holding the mouse at that moment won’t be the reason why.
Designing an Approval Process That Holds
The good news is that the controls here are procedural, inexpensive, and within any business’s reach.
Require out-of-band verification for banking changes. Any request to change payment details gets confirmed by calling a phone number you already had on file, never one supplied in the request itself. This single rule prevents most vendor payment fraud.
Next, separate the approval from the request. The person who initiates a payment shouldn’t be the person who releases it, particularly above a threshold the business sets deliberately rather than by habit.
Remove urgency as an override. Make it explicit that no one, at any level, can shortcut verification because something is time-sensitive. Fraud depends on urgency, so removing it as a lever removes most of the pressure.
Give people permission to pause. An employee who delays a payment to verify it should be treated as having done their job well, even when the request turns out to be legitimate. If pausing carries social cost, nobody will do it.
Final Perspective
This is one of the few risks where the most effective controls cost almost nothing and require no new technology. What they require is a business deciding how payments get approved, writing it down, and holding to it when someone senior is in a hurry.
That’s a leadership decision rather than a finance one, which is exactly why it often doesn’t get made. It sits between departments, and nobody owns it until after something goes wrong.
At Secutor, we help organizations examine their approval workflows, identify where a single person can move money alone, and put verification steps in place that work under real conditions. If you’re not certain how your business would handle a convincing request to change a vendor’s bank details, that’s worth finding out before it arrives.
The strongest control here isn’t a product. It’s a process nobody feels awkward following.
Connect with an Expert for a Free Consultation
Secutor is your team of world-class problem solvers with vast expertise and experience delivering complete solutions keeping your organization protected, audit-ready, and running smoothly. Use the form below to contact us for a free consultation.

