- The FBI's own public service announcement on business email compromise counts 55,499,915,582 dollars of exposed losses across 305,033 incidents between October 2013 and December 2023, and never once mentions artificial intelligence.
- That absence is the finding. The mechanism did not change. What changed is the cost of writing convincing English and the speed of researching who your suppliers are.
- FinCEN's November 2024 alert on deepfake media describes something narrower than the headlines suggest: fraudulent identity documents used to get past verification at financial institutions, not fake voices calling small shops.
- Since 9 October 2025, euro area payment providers have to check that a payee name matches the IBAN before a transfer goes through, free of charge, which removes the single most common form of this attack in the eurozone.
- Every effective control is boring and none of them are technical. A callback to a number you already had beats any detection tool you can buy.
- The invoice you are most likely to pay is not the sophisticated one. It is a modest charge for a service you could plausibly have signed up for and cannot quite remember.
Fifty five billion dollars. That is the exposed loss figure the FBI's Internet Crime Complaint Center attaches to business email compromise in its public service announcement on the scam, precisely 55,499,915,582 dollars across 305,033 reported incidents between October 2013 and December 2023. Read the document looking for the words artificial intelligence and you will not find them.
Hold onto that, because the fraud industry has spent two years selling small businesses a story about AI powered attacks and a detection product to match. The story is not exactly wrong. It is aimed at the wrong part of the problem, and the part it aims at is the part you can already fix for nothing.
What did AI actually change about invoice fraud?
Two things, and neither of them is the bit people worry about.
The first is language. The classic tell of a fraudulent supplier email was that it read slightly wrong: a preposition out of place, a formality that no real accounts department uses, a signature block that did not quite match the house style. Every one of those tells was a proxy for the attacker not being a native speaker of your language or your industry. That proxy is gone. It cost nothing to remove and it was the single most widely taught detection heuristic in small business training.
The second is research. Working out who supplies a small shop used to take effort: someone had to read your site, find a delivery partner mentioned in a review, guess at your accounting cycle. A model with a browser does that in a minute, which means the attack that used to be worth running only against companies with a finance department is now worth running against a florist. Volume economics changed, not capability.
What did not change is everything that matters mechanically. The money still leaves by a bank transfer that you authorise. The instruction still arrives by email. The fraud still turns on a change of payment details that nobody verified out of band. A model wrote a better letter. It did not invent a new way to take your money.
Is the deepfake voice call the real threat to a small shop?
Almost certainly not, and it is worth being precise about why, because the official record here is narrower than the coverage of it. FinCEN issued an alert on fraud schemes involving deepfake media in November 2024, numbered FIN-2024-Alert004. What it describes is an increase in suspicious activity reports about deepfake media used to produce fraudulent identity documents that get past identity verification at financial institutions. The targets in that alert are banks, casinos, insurers and money services businesses.
That is a real and serious problem. It is also a problem about opening accounts, not about paying invoices. The alert's own framing is that bad actors are exploiting the technology to defraud American businesses and consumers, in Director Andrea Gacki's words, and the mechanism documented is document forgery at onboarding.
Voice cloning against a business phone line is a genuine risk and we have written up the practical checks for it separately in the piece on what a business phone check has to do now that voices can be cloned. For a shop with one or two people, though, it is the wrong thing to spend your attention on. The fraud that empties a small business account arrives as a PDF.
Where does the money actually leave?
There are only a handful of exits and they are worth laying out side by side, because the control that works differs completely by exit. This is the table we would pin above a desk.
| Attack | What arrives | Why it works | The control that actually stops it |
|---|---|---|---|
| Supplier bank detail change | An email from a real supplier's lookalike domain | You already owe them money | Callback to the number on last year's invoice |
| Fake invoice for a plausible service | A modest charge for hosting, listings or SEO | The amount is below your thinking threshold | Purchase order matching, even a spreadsheet one |
| Compromised real supplier mailbox | A genuine email thread with altered bank details | Everything checks out, because it is real | Payee name and account verification at the bank |
| Chief executive style urgent request | A message from you, to your bookkeeper | Authority plus time pressure | A standing rule that nobody pays on a first request |
| Marketplace payout redirection | A platform notice asking you to reconfirm bank details | Platforms do sometimes ask this | Log in by typing the address, never by the link |
| Overpayment and refund request | An overpaid order and a plea to refund the excess | The original payment reverses later | Wait for funds to clear before refunding anything |
Read the last column top to bottom. Not one of those controls involves buying anything, and not one of them detects an AI. They all work by moving the decision off the channel the attacker controls, which is the entire theory of defence here and has been since long before any of this was generated.
Does verification of payee fix this?
In the euro area, it fixes a large slice of it, and the change is recent enough that many sellers have not noticed. Since 9 October 2025, under rules the European Commission describes in its note on how the new instant euro payment rules work, payment providers in the eurozone have to verify that the name of the recipient matches the IBAN you typed, they have to do it before the payment goes through, and they have to do it free of charge.
The reason that matters so much for invoice fraud is structural. The classic attack changes an account number while keeping the supplier's name in the email. A name to account check catches exactly that, because the fraudster's account is not in your supplier's name. The Commission's own text says a mismatch means the payment will not go through.
The check is only as good as the name you type. If you copy the payee name out of the fraudulent invoice as well as the account number, you have verified the fraudster against themselves. Type the supplier name from your own records.
Outside the eurozone the picture varies. The United Kingdom has run a comparable name checking service for years and several other markets have their own. If you sell across borders, and the practicalities of that are covered in our notes on what changes when an order crosses a border, the useful move is to find out for each currency you pay in whether your bank offers the check at all.
What should a one person business actually do?
Four things, and they take an afternoon in total. The FTC's alert telling small businesses to pay their bills rather than scammers, published in May 2026, lands in the same place from the consumer protection side: verify invoices carefully, have a clear procedure for approving purchases, and search an unfamiliar company's name alongside the word scam before you pay it.
- Write down your suppliers and their bank details today, while nothing is wrong. A page in a notebook is enough. Every callback you will ever make depends on having a number that predates the attack.
- Make a rule that bank detail changes are never accepted by email. Not verified by email. Not accepted at all. The supplier calls you on a number you already had, or the change does not happen.
- Match every invoice to something you ordered. The FTC alert lists the recurring fakes: tech support, domain registration, listing services. All of them work because you cannot immediately remember whether you signed up for that.
- Set a delay on any first payment to a new payee. Twenty four hours removes urgency, which is the only real weapon in this whole category.
What does the FBI actually recommend, translated?
The IC3 announcement ends with a list of defensive steps, and the list is written for an organisation with staff. Every item still maps onto a business of one, sometimes more cleanly than it maps onto a company of two hundred. Here is the translation.
Verify account changes through a second channel
This is the whole defence in one line and it is first for a reason. Second channel means a channel the attacker does not control. Replying to the email is not a second channel. Calling the number in the email signature is not a second channel. The supplier's mobile number in your phone from eighteen months ago is.
Watch for domain misspellings and check the full sender address
The advice specifically mentions enabling full email extension viewing, which sounds like an IT department task and is actually a phone setting. Most mobile mail apps show a display name and hide the address behind it, which is precisely the field a fraudster controls freely. Turning that off takes thirty seconds and undoes the cheapest trick in the category.
Use a unique password per service, and turn on two factor authentication
Reused credentials are how the compromised real mailbox scenario in the table above happens, and that is the version of this attack nobody can spot by reading carefully, because the email genuinely is from your supplier. If your own mailbox is the one that gets taken, your customers become the targets and the reputational bill is worse than the financial one. We covered the adjacent question of what an assistant with mailbox access can reach in the piece on what you actually grant when an AI assistant gets your inbox.
Monitor the account for irregularities
For a small business this means one thing in practice: look at the outgoing payments once a week rather than at month end. Recall windows close in hours. A weekly glance catches at day six what a monthly reconciliation catches at day thirty, and only one of those is early enough to matter.
Why does a good bookkeeping habit beat a detection tool?
Because the tool has to be right about intent and the habit only has to be right about process. A filter that reads incoming mail and scores it for fraud risk is guessing at whether a human being meant to defraud you. A purchase order that has to exist before an invoice can be paid does not guess at anything. It asks a question with a factual answer: did we order this.
Small businesses skip that step because it feels like corporate theatre when there is one of you. It is not. The lightest possible version is a spreadsheet with a date, a supplier and an amount, filled in when you order rather than when you are asked to pay, and it turns a judgement call into a lookup. Our walkthrough of what AI bookkeeping can and cannot take over for a one person business covers where automation genuinely helps with that record, which is mostly in the extraction rather than the deciding.
There is a role for machine reading here and it is worth naming, because it is the opposite of what gets sold. The valuable job is not detecting fraud. It is extracting the payee name, the account number and the amount from every invoice you receive and comparing them to what you have on file for that supplier. That is a matching problem with a right answer, which is the sort of work these systems are reliable at, and any mismatch simply gets a human look.
What if you have already paid one?
Speed is the only variable that matters here, and the window is measured in hours rather than in days. Call your bank before you do anything else, including before you finish reading this, because a recall request has a real chance while the funds are still sitting in the receiving account and almost none once they have moved on. The IC3 announcement notes the pattern of funds being routed onward through third party processors and international intermediaries, which is the machinery that closes that window.
Then report it to the police and to the national fraud reporting body for your country, a step people skip because it feels pointless. It is not pointless: recall requests through official channels have a materially better hit rate than a customer calling their branch, and the reporting is how the 55 billion dollar figure exists at all. After that, tell the supplier whose identity was used, because their mailbox may be the compromised one and you will not be the only customer receiving these.
Finally, look at what the attacker knew. If they had your order number, someone has seen a real invoice, and the question of which mailbox is leaking is more urgent than the money you just lost. The same reasoning applies to the evidence you keep for payment disputes generally, which we set out in the piece on assembling the evidence for a chargeback dispute.
The uncomfortable summary
The AI story about invoice fraud is mostly a marketing story. The technology made the emails better written and the target research cheaper, and it did not touch a single one of the controls that work. A shop that keeps a supplier list, refuses bank changes by email and waits a day before paying a new payee is roughly as safe today as it was in 2019, which is a genuinely reassuring thing to be able to say about anything in this field.
What has moved is who gets targeted. The economics that once made small merchants uninteresting have flipped, so the honest version of the advice is not that the attacks are cleverer. It is that they are now pointed at you. If you are thinking about the wider question of what you hand to any vendor or tool with access to your accounts, the practical checklist sits in our notes on the due diligence questions to ask before buying an AI tool, and the security posture we hold ourselves to is set out on our own security page.