of payment fraud attacks use invoices, W-9s, or bank details—documents that appear legitimate and are difficult to verify across high volumes.
As attacks become more complete and convincing, socially engineered fraud is projected to exceed $40 billion annually by 2027.
Generative AI is accelerating that shift. Emails, invoices, financial documents, and entire vendor conversations can now be produced instantly. What once required effort and coordination is now fast, scalable, and highly convincing. The result is payment fraud that enters finance workflows looking complete, approved, and ready to be processed.
Based on the analysis of 260 real-world B2B payment fraud incidents in 2025, this report reveals how attackers engineer payment requests to pass your financial controls.
Payment fraud does not break controls. It moves through them.
92% of attacks start with a trusted identity, often impersonating vendors or executives using real accounts and familiar context.
They are reinforced with documentation. Invoices, W-9s, and bank details make the request look legitimate.
Then comes validation. In 90% of cases, the fraudster’s bank account is valid, active, and in good standing.
Each step checks out.
The transaction does not.


















Protecting businesses globally against socially engineered fraud and errors.
By Eliminating Fraud and Payment Errors
Manual Process Time Reduced