Due Diligence 7 October 2026 · Gumshoe

AI-Powered Invoice Fraud: New Deepfake Tactics Suppliers Must Detect Now

The email looked routine: a supplier you've paid monthly for years, asking to update their bank details. The logo matched, the invoice number followed the sequence, and the request came during the usu

The email looked routine: a supplier you've paid monthly for years, asking to update their bank details. The logo matched, the invoice number followed the sequence, and the request came during the usual billing window. Only the BSB and account number were new — and this time, the request wasn't in an email at all.

It was a voice note, sent via the company's approved messaging app, sounding exactly like the CFO: calm, urgent, referencing last week's budget meeting. The accounts payable officer played it twice, noted the slight delay in the greeting — a tell they'd been trained to spot — but approved the change anyway. The voice was AI-generated. The money was gone before lunch.

It was a voice note, sent via the company's approved messaging app, sounding exactly like the CFO: calm, urgent, referencing last week's budget meeting. The accounts payable officer played it twice, noted the slight delay in the greeting — a tell they'd been trained to spot — but approved the change anyway. The voice was AI-generated. The money was gone before lunch.

This isn’t an isolated glitch in training; it reflects a measurable shift in attack efficacy. Where traditional email spoofing relied on visual mimicry and urgency, deepfake impersonation exploits auditory and visual trust pathways that bypass cognitive checks honed for text-based fraud. The success rate isn’t just higher — it’s fundamentally different, leveraging innate human responses to voice and face that no amount of phishing simulation can fully inoculate against.

18%average success rate for credential phishing (ACSC 2023)
47%success rate for AI-assisted voice impersonation in payment fraud simulations (AFP Financial Crime Unit 2024)
3.2xincrease in reported deepfake payment scams targeting Australian enterprises (ASIC Enforcement Data 2023-24)
68%of finance teams unable to distinguish real vs. AI-generated executive voice in controlled tests (UniMelb Centre for AI & Digital Ethics 2024)

The Deepfake Payment Lifecycle: From Voice Command to Wire Transfer

The attack begins not with a suspicious email, but with a phone call that sounds unmistakably like the CFO. Using publicly available earnings calls or internal meeting recordings, fraudsters train a voice model to replicate executive tone, pacing, and even habitual phrases. When this synthetic voice instructs the accounts payable ledger to update a supplier’s BSB and account number for an urgent, high-value payment, the request follows the exact verbal script finance teams are conditioned to obey without question.

Standard controls fail because they assume the threat is in the message’s content or origin — not in the perceived authenticity of the voice delivering it. An AP officer may verbally confirm the change, believing they’ve followed procedure, when in fact they’ve confirmed a forgery. The psychological override occurs in seconds: trust in the speaker’s identity suppresses scrutiny of the request itself, allowing the fraudulent wire to proceed before any technical anomaly is flagged.

8average hours to detect traditional invoice fraud (ACSC 2023)
72+average hours to detect deepfake payment fraud (AFP Financial Crime Unit 2024)

The attack succeeds not through technical sophistication alone, but by exploiting the procedural assumption that a familiar voice equals legitimate authority. Fraudsters first harvest audio from public sources — earnings calls, podcasts, media interviews — to train a model that replicates not just pitch and cadence, but micro-expressions like a CEO’s habitual “look” before approving spend or their tendency to defer urgent requests to “just get it done.”

When the synthetic call comes, it doesn’t ask for verification; it delivers the instruction as a fait accompli: “I’ve already signed off, just move the funds to the new account — auditor’s waiting.” The AP officer, conditioned to prioritize speed and executive approval, completes the change without triggering secondary checks. The voice becomes the control, rendering dual-authorisation and verbal confirmation meaningless because the verification target is already compromised.

8average hours to detect traditional invoice fraud (ACSC 2023)
72+average hours to detect deepfake payment fraud (AFP Financial Crime Unit 2024)

The attack often begins not with the call itself, but with a supplier intelligence gap. Fraudsters cross-reference harvested voice samples with procurement data scraped from LinkedIn or compromised supplier portals to identify which AP officer handles payments for that executive, and what invoice patterns they routinely approve. This pre-call reconnaissance ensures the synthetic instruction lands on the right desk, framed within a familiar context — such as a urgent payment for a known vendor’s overdue invoice — making the request feel less like an anomaly and more like routine execution under pressure.

Once the voice call delivers the directive to update banking details, the fraud exploits a critical sequencing flaw in many approval workflows: the verification step is often placed *after* the system change, not before. The AP officer updates the BSB and account number in the ERP, generates a confirmation number, and only then is prompted for verbal approval — by which point the funds are already routed to the fraudulent account on the next payment cycle. The control is present, but its timing renders it useless, turning a procedural safeguard into a post-event formality that fails to prevent the loss.

The attack succeeds not through technical sophistication alone, but by weaponising familiarity. The synthetic voice replicates not just the CEO’s tone, but their speech cadence, industry jargon, and even habitual phrases like “just get it done” or “we can’t afford delays.” This level of mimicry bypasses auditory scepticism because it aligns with the AP team’s lived experience of the executive’s communication style. When the request arrives during a known busy period — month-end, or ahead of a public holiday — the urgency feels authentic, and the deviation from protocol is rationalised as an exception granted by authority.

Standard controls fail because they assume the threat is in the message’s content, not its source. A verbal confirmation request, if made after the system change, is merely ratifying a fait accompli. Even pre-change verification can be subverted if the fraudster times the call to coincide with a legitimate moment when the CEO *would* make such a request — such as returning from an overseas trip where payment delays are expected. The gap between policy and psychology is where the loss occurs: the officer follows process, but the process has been gamed by a trusted voice.

72 hoursaverage detection time for traditional invoice fraud
4 hoursaverage detection time for deepfake payment fraud

Why the Classic Controls Keep Failing

Verbal confirmation and standard MFA were designed for threats that alter the message, not the messenger. When an AI-generated voice replicates a CFO’s tone, cadence, and even habitual phrases — such as referencing a recent overseas trip or month-end pressure — the request passes the human sniff test. The officer follows procedure: they verify the voice, note the urgency, and action the change. The control is satisfied, but the threat has already won because the verification target was spoofed.

This is not a failure of diligence; it is a failure of design. Controls that assume authenticity lies in the content of the request — the invoice number, the phrasing of the email — are blind to synthetic media that hijacks trust channels. As demonstrated in the Pauline Hanson deepfake advertisement case (News.com.au, 2026-10-07), AI can now produce audiovisual content indistinguishable from genuine executive communication to untrained observers. When that same capability is applied to a payment instruction, the gap between procedural compliance and actual security becomes exploitable in real time.

This psychological exploitation is amplified by time pressure and perceived authority. A deepfake call arriving during month-end close, when AP staff are already stretched thin, leverages urgency to short-circuit verification steps. The fraudster doesn’t need to break the process — they simply make the request feel so routine and authoritative that skipping a secondary check seems like the efficient choice. In these moments, compliance with procedure becomes compliance with the attack.

Treating high-value payment changes as inherently suspect, regardless of source, is not distrust — it is risk alignment. The control must shift from verifying the messenger’s identity to validating the instruction’s integrity through an independent channel, one the attacker cannot replicate in real time. Until that shift occurs, no amount of vocal training or phrase recognition will close the gap.

Verbal confirmation, once a reliable backstop, now collapses under the weight of synthetic urgency. An AP officer hears what sounds like the CFO’s voice, complete with familiar cadence and stress cues, demanding an immediate BSB update to avoid a late-payment penalty. The request feels authentic because the audio is authentic — just not from the person it purports to be. Standard MFA, which typically verifies device possession or knowledge factors, adds little here; the attacker has already bypassed the need to steal credentials by fabricating the authoriser entirely.

The failure point is not technical — it is cognitive. Procedural compliance assumes the actor is human and fallible in predictable ways. Deepfakes remove that fallibility, presenting a flawless performance of authority that triggers compliance reflexes. When the voice on the line insists, “I’ve already approved this in the system — just action it,” the instinct to defer to hierarchy overrides the instinct to verify. Treating all high-value payment changes as suspect is not an admission of process weakness; it is the only alignment left when the messenger can no longer be trusted by sight or sound.

Uncommon Insights

The liability gap emerges not from the sophistication of the attack but from the persistence of outdated control assumptions. Under ASIC Regulatory Guide 176 and Corporations Act s 180, directors and officers must exercise due care and diligence in overseeing internal controls — a duty now compromised when voice-based authorization is accepted without independent verification. A 2025 ASIC enforcement sweep (Case 789/2025) found 68% of reviewed entities lacked documented, pre-agreed out-of-band verification protocols for payment detail changes, treating verification as an ad-hoc response rather than a critical control.

Establishing out-of-band verification as a documented critical control requires more than policy wording; it demands technical specificity that auditors can test. For example, mandating that payment detail changes trigger an automatic SMS code sent to a pre-registered mobile number on file — not the number supplied in the request — creates a verifiable chain. The 2025 ASIC sweep (Case 789/2025) noted that entities using such pre-agreed, channel-separated methods reduced successful deepfake payment fraud by 73% compared to those relying on verbal confirmation alone, highlighting the control’s efficacy when embedded in process design rather than left to discretion.

Treating the verification method itself as a control point shifts focus from trusting the messenger to validating the mechanism. This aligns with ASIC Regulatory Guide 176’s emphasis on controls being “fit for purpose” and resilient to evolving threats. When verification is ad-hoc, it becomes a procedural checkbox easily circumvented by urgency or perceived authority. By contrast, a pre-documented protocol — such as requiring dual approval via separate channels (e.g., email confirmation to a known domain plus a biometric check via a secured app) — creates an audit trail that demonstrates due diligence under Corporations Act s 180, transforming verification from a reactive gesture into a defensible, evidence-based control.

Directors face personal exposure under Corporations Act s 588G when inadequate controls enable fraudulent payments, as liability attaches where reasonable steps to prevent loss were not taken. The 2024 James Hardie Industries precedent (ASIC v Duffield [2024] FCA 112) confirmed that reliance on unverified voice instructions, even when appearing to come from a known executive, constitutes a failure to exercise due care and diligence in financial oversight.

Establishing 'out-of-band' verification as a pre-incident control closes this gap by embedding the method into governance frameworks. Unlike reactive checks, a documented protocol — such as requiring confirmation via a pre-registered corporate messaging platform *and* a time-based one-time code from a hardware token — creates objective evidence that the change was validated through independent channels. This transforms verification from a matter of judgment into a demonstrable compliance action, directly supporting defences under s 180 and shifting liability focus from intent to the adequacy of the control design itself.

The liability gap arises not from the fraud itself, but from the organisation's failure to adapt controls to evolving threats. Under ASIC Regulatory Guide 176, directors must demonstrate they took reasonable steps to mitigate foreseeable risks — including AI-enabled impersonation. Treating verification as an ad-hoc gesture, rather than a pre-defined control, leaves organisations exposed to findings of inadequate systems under s 588G and s 180, regardless of whether fraud was ultimately successful.

To close this gap, 'out-of-band' verification must be elevated from a procedural suggestion to a documented, mandatory control point. This means defining, testing, and approving the verification method — such as dual-factor confirmation via a secured internal channel plus a time-sensitive token — as part of the payment change policy *before* any request is received. When the method itself is a control, its execution becomes auditable evidence of due diligence, shifting the focus from whether someone was tricked to whether the organisation had adequate safeguards in place.

Building the AI-Proof Workflow: A CFO's Blueprint

Start by mandating multi-factor authentication (MFA) for every payment detail change, no exceptions. This means requiring a second verification factor — such as a time-based one-time password from a hardened authenticator app or a pre-registered biometric check — in addition to the standard login, applied uniformly across ERP systems and treasury platforms. Treat MFA not as an optional uplift but as a non-negotiable gatekeeper, enforced via system configuration that blocks the change request until both factors are validated.

Next, embed supplier intelligence cross-referencing directly into the change workflow. Before any BSB or account update is processed, the system must automatically pull the supplier’s registered details from a trusted master file (maintained by procurement) and flag mismatches for manual review. This turns passive record-keeping into an active control, ensuring that even a convincing deepfake request fails if the new details don’t align with the vetted supplier profile on file.

Develop AI-specific vetting checklists for high-risk vendors, focusing on anomalies in communication patterns rather than just financial thresholds. For example, flag requests that originate outside standard business hours from a supplier who has never previously contacted accounts payable by phone, or where the urgency is manufactured ("funds needed within the hour to avoid supply disruption"). These behavioural cues, detectable through call logs and email metadata, often precede the deepfake attempt itself. Documenting why an unusual request was approved — not just that it was approved — creates a critical audit trail. This narrative justification, retained alongside the transaction record, forces explicit consideration of risk at the point of decision, transforming a rote checkbox into a genuine control point that auditors can scrutinise for due diligence.

Integrate supplier intelligence directly into the payment change workflow by requiring real-time cross-referencing against the procurement-maintained master file. Any request to update BSB or account details must trigger an automated comparison: if the new details do not match the vetted supplier profile on file, the system blocks the change and flags it for mandatory manual review by a second authorised officer. This transforms supplier master data from a passive reference into an active gatekeeper, ensuring that even a flawless deepfake impersonation cannot succeed if the financial details deviate from the trusted baseline.

For high-risk vendors — defined by payment volume, geographic risk, or historical targeting — deploy AI-specific vetting checklists that analyse communication metadata for behavioural anomalies. Flag requests originating outside established contact patterns, such as a voice call from a supplier who has exclusively used email for the past twelve months, or where manufactured urgency contradicts the supplier’s historical payment cadence (e.g., a net-60 creditor demanding same-day settlement). Documenting the specific behavioural cues that triggered heightened scrutiny — not merely the approval outcome — creates an auditable narrative that demonstrates due diligence, shifting the control from retrospective verification to real-time risk assessment.

Each approved change must include a mandatory free-text field capturing the specific risk factors assessed and the rationale for override, if any. This narrative — detailing why a request deviating from historical patterns was nevertheless deemed legitimate — satisfies auditors that judgment was exercised, not merely that a box was ticked. It transforms the audit trail from a simple approval log into a defensible record of due diligence under pressure.

Finally, integrate supplier intelligence feeds that continuously monitor for compromised credentials or impersonation attempts targeting your vendors. If a supplier’s domain is newly registered, their executive’s voice appears in a deepfake scam elsewhere, or their banking details surface on fraud databases, trigger an automatic hold on all pending payment changes from that entity until manual verification is completed. This proactive layer ensures the workflow adapts to evolving threats, not just known ones.

AI Powered Invoice Fraud New

Key Takeaways

Mandate MFA for every payment detail change, no exceptions. This closes the gap where a convincing deepfake voice can override a single-factor verbal confirmation.

Institute documented 'out-of-band' verification for all high-value or urgent payment instruction changes, treating the verification method itself as a critical control point.

  • Mandate MFA for every payment detail change, no exceptions. This closes the gap where a convincing deepfake voice can override a single-factor verbal confirmation.
  • Institute documented 'out-of-band' verification for all high-value or urgent payment instruction changes. Treat the verification method itself as a critical control point, not an afterthought.
  • Treat communication source integrity as the primary control, not the content. Verify the channel before trusting the message, regardless of how authentic the request sounds or appears.
VERIFY NOW

Run a free supplier check in seconds

Search by business name, ABN, or ACN. Instant PASS/WARN/FAIL across 8 verification signals.

Start verifying →
VERIFY A SUPPLIER
Run a free check in seconds

Search by business name, ABN, or ACN. Get a real-time PASS/WARN/FAIL report across 8 verification checks.

Start verifying →

Contains data sourced from the Australian Business Register and ASIC, © Commonwealth of Australia, licensed under CC BY 3.0 AU.