Salta al contenuto principale

How to Stop Deepfake Invoice Fraud: An AP/AR Prevention Guide for Small Businesses

8 minuti di letturaMike ThriftMike Thrift
How to Stop Deepfake Invoice Fraud: An AP/AR Prevention Guide for Small Businesses

In January 2024, a finance employee at Arup, a London-based engineering firm, joined a video call with people he recognized: his CFO and several colleagues. They discussed a confidential transaction and asked him to process it. He did — 15 separate wire transfers totaling $25.6 million over the following days. Every face on that call was fake. Every voice was cloned. The "colleagues" were AI-generated deepfakes built entirely from publicly available video and audio of real Arup executives.

That single incident reshaped how finance teams think about fraud. For decades, accounts payable and accounts receivable fraud meant spotting a misspelled domain name or an oddly worded email. Now the fraudster can sound exactly like your CEO, look exactly like your CFO on a video call, and know enough real details about your company to pass a casual gut check. If you run a small business, you don't have Arup's finance department or its incident response team — which makes you a more attractive target, not a less likely one.

Why Small Businesses Are Now the Preferred Target

Attackers used to reserve deepfakes for high-value corporate targets because the tools were expensive and slow. That's no longer true. Voice cloning services can now produce a convincing replica of someone's voice from as little as three seconds of audio — a snippet easily lifted from a podcast interview, a conference talk, or a company's own YouTube channel. Document-editing tools can take a real invoice or receipt and alter the bank details, aging the paper trail so it "looks weathered and photorealistic," without leaving obvious digital fingerprints.

The economics favor volume over precision. A scammer no longer needs to spend weeks researching a single Fortune 500 target. They can generate hundreds of tailored phishing emails, fake vendor onboarding packets, and synthetic voice messages in an afternoon, then blast them at small businesses that have less staff, less scrutiny, and less time to double-check a "routine" payment request. Business email compromise — the broader category deepfake fraud sits inside — generated an estimated $2.77 billion in reported losses across more than 21,000 incidents in a single recent year, and security researchers have tracked deepfake-enabled fraud attempts rising by well over 1,000% in just the last few years. Small businesses rarely make the headlines when they lose $8,000 to a fake vendor, but in aggregate, they're absorbing a growing share of the damage.

The Playbook Fraudsters Are Actually Using

Understanding the mechanics makes the defense obvious. Here's what's showing up in real cases right now.

1. The synthetic vendor

Fraudsters construct an entire fake vendor identity — a professional-looking website, a fabricated W-9, even fake tax documents, all AI-generated in minutes. They email your accounts payable inbox posing as a new supplier or a long-time vendor with "updated" banking details. If your master vendor file isn't tightly controlled, that fake entry sits right next to your legitimate suppliers, waiting for the next invoice run.

2. The voice-cloned executive

A bookkeeper or AP clerk gets a phone call — not an email — from someone who sounds exactly like the owner or a senior manager, urgently requesting a wire transfer to close a deal before day's end. Voice cloning has made "I'd recognize that voice anywhere" worthless as a security control. Some scammers go further, setting up entire fake call centers where the "person" on the other end of the phone is a scripted voice bot, indistinguishable from a human in a short call.

3. The doctored receipt or invoice

On the accounts receivable side, employees submit expense reports with AI-edited receipts — altered totals, fabricated vendor names, or entirely invented purchases that look convincingly real, complete with realistic creases, smudges, and receipt-paper texture generated by image models.

4. The deepfake video call

The Arup case is the extreme version, but the same tactic scales down. A scammer doesn't need a full boardroom of deepfakes — a single fabricated video snippet of a business partner or client, sent to confirm a payment change, can be enough to override an employee's hesitation.

The Callback Habit That Stops Almost All of It

Here's the good news: nearly every one of these attacks depends on the same weakness — a payment decision made using contact information supplied by the person asking for the money. Break that dependency and most of the fraud collapses, regardless of how convincing the video or voice is.

The fix is a habit, not a piece of software: before you change payment details or send money based on a new instruction, verify it through a channel you already trust — never through contact information included in the request itself.

In practice, that means:

  • Never call back the number in the email or text. If a "vendor" emails new banking details, look up that vendor's phone number from your own records — an old invoice, your accounting system, their official website typed in fresh — not from anything in the message you just received.
  • Treat "urgent" as a red flag, not a reason to skip verification. Fraud attempts are almost always time-pressured on purpose, because urgency short-circuits the instinct to double-check.
  • Use a shared, out-of-band verification method with regular vendors and partners. Some businesses agree on a simple passphrase or a secondary confirmation email address with key vendors specifically for payment-instruction changes.
  • Require two people for any change to banking details or any new wire transfer above a set threshold. A second set of eyes, with no context on the "urgent" framing the fraudster is pushing, is one of the cheapest and most effective controls available.
  • Ask a question only the real person would know off-script. Scripted voice bots and even live deepfake callers tend to break down when asked about something specific and unpublicized — a recent internal meeting, an inside joke, a detail that isn't on the company website or LinkedIn.

None of this requires new software. It requires making the callback the default, not the exception — even when the voice on the phone sounds exactly like your business partner of ten years.

Cleaning Up Your Vendor File Is Cheaper Than You Think

A surprising amount of fraud exposure comes down to vendor-file hygiene. Many small businesses accumulate vendor records for one-off purchases, contractors used once, or suppliers they haven't ordered from in years — and every stale entry is another place a fraudulent "update" can hide. A periodic review is worth the hour it takes:

  • Scan for vendors sharing a bank account or routing number — a common sign of a synthetic identity or an internal fraud ring.
  • Flag vendors with a P.O. box instead of a street address, especially newer entries.
  • Remove or archive vendors you haven't transacted with in the last 12–18 months.
  • Confirm that every active vendor's banking details match what's on file in your original onboarding paperwork, not a later "update" email.

This is also where good bookkeeping habits pay for themselves twice over. A business that reconciles its accounts regularly and keeps a clear, auditable trail of every vendor change notices a fraudulent diversion within days, not months — long before the money is unrecoverable. Plain-text accounting, where every transaction and every vendor change lives in a version-controlled ledger you can diff and review, makes "who changed this vendor's bank details, and when" a five-second question instead of a forensic investigation.

Training Still Beats Technology

Security vendors will happily sell you AI-powered deepfake detectors, and some of that technology is genuinely useful for larger organizations processing high volumes of payments. But for most small businesses, the single highest-leverage investment is still training the two or three people who touch your money.

That training doesn't need to be elaborate. It needs to cover exactly two things: what these scams actually look and sound like today (not the crude "Nigerian prince" email of a decade ago), and the specific verification habit — the callback, the second approver, the out-of-band check — that your business commits to using every single time, no exceptions, regardless of how legitimate a request seems or how senior the person appears to be asking for it. The employee who authorized Arup's $25 million loss wasn't careless. He was following what felt like a completely normal internal video call. The gap wasn't awareness that deepfakes exist — it was a verification step that didn't survive contact with a convincing fake.

Keep Your Finances Organized From Day One

Fraud prevention and good bookkeeping are the same discipline wearing different hats — both come down to knowing exactly what happened to your money, when, and why. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data, with a version-controlled ledger that makes every vendor change and every transaction easy to review and audit. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Condividi questo articolo