Due Diligence 8 October 2026 · Gumshoe

Securing Procurement Against AI-Driven Identity Theft and Supply Chain Impersonation

An email arrives from your long-term logistics provider, requesting an urgent update to their bank account for an overdue payment. The sender address matches their domain, the invoice references a rec

An email arrives from your long-term logistics provider, requesting an urgent update to their bank account for an overdue payment. The sender address matches their domain, the invoice references a recent shipment, and the tone mirrors their finance manager’s usual cadence — except the voice note attached to the email, asking you to confirm the change, sounds subtly off.

This is no longer a typo in an invoice number or a lookalike domain. It’s a coordinated impersonation: AI-generated audio mimicking a trusted contact, layered over a seemingly legitimate payment request, exploiting the very familiarity that once made invoice fraud detectable. The attack doesn’t break in — it walks in wearing a mask you’ve seen a hundred times.

68%of finance teams report difficulty distinguishing AI-generated payment requests from legitimate ones
Evolution of Invoice Fraud Tactics
Fraud VectorOld MethodAI EnhancementRisk Level
Payment detail changeEmail spoofing with altered BSB/accountDeepfake audio/video request + spoofed email chainHigh
Urgent invoiceLookalike domain, urgent toneContext-aware urgency mimicking supplier’s communication patternsMedium-High
Supplier impersonationFake invoice from similar company nameReal-time language model adapting to historic email styleHigh

Imagine an accounts payable officer receiving a voicemail that sounds exactly like their long-term supplier’s finance manager, urgently requesting an immediate BSB change to avoid a supply disruption. The voice matches the cadence, the slight hesitation before numbers, even the background office hum. Simultaneously, a follow-up email arrives from the supplier’s legitimate domain, referencing the call and attaching an updated invoice with the new account details. There are no spelling errors, no mismatched logos — just a seamless, familiar interaction that never actually happened.

This is no longer about catching a typo in an email header. The attack bypasses traditional scrutiny by weaponising trust itself, using generative AI to replicate not just the appearance but the behavioural patterns of legitimate communication. Standard checks — verifying the email address, matching the invoice number to the purchase order — become irrelevant when the request arrives through a channel the team believes is secure, delivered in a voice they recognise. The fraud succeeds not because controls are absent, but because they are designed for a threat that no longer exists.

68%of finance teams report difficulty distinguishing AI-generated payment requests from legitimate ones
41%increase in AI-assisted payment fraud detected by Australian financial institutions in 2023
22 hoursaverage time to identify a deepfake-driven payment fraud incident
$185,000median loss per successful AI-enabled invoice fraud incident targeting ASX-listed entities

Beyond the Typo: Identifying AI-Enabled Impersonation Signals

The fraud no longer announces itself with a misspelled domain or a clumsy logo. Instead, it arrives as a voice note from the finance director’s known mobile number, urgently requesting an immediate payment to a new account to secure a time-sensitive government contract. The tone matches, the cadence is familiar, and the request references a genuine internal project — but the call was never made. This is the mechanics of a Man-in-the-Middle attack using deepfake audio, where the attacker doesn’t just spoof the sender but synthesises their behavioural signals to bypass trust.

Red flags now live in the subtleties: a sudden shift to an unfamiliar communication channel like WhatsApp for payment instructions, language that creates artificial urgency without precedent in the supplier relationship, or a request that ignores established approval thresholds. These aren’t errors; they are calibrated deviations designed to exploit the very patterns finance teams use to verify legitimacy. Detecting them requires moving beyond static checks to analysing the behavioural anomaly within the communication itself.

The sophistication lies in the attacker’s ability to harvest behavioural data from public sources—earnings calls, LinkedIn videos, or even compromised voicemails—to train models that replicate not just voice, but speech patterns, industry jargon, and typical decision-making latency. A deepfake request might pause before answering, mimicking human hesitation, or use a phrase the target only uses in internal strategy meetings. This isn’t impersonation; it’s behavioural mirroring at scale, designed to pass the unconscious checks finance teams perform when a familiar voice asks for a routine action.

Detection therefore shifts from verifying the source to validating the intent against known behavioural baselines. Did the CFO ever approve a six-figure payment via voice note outside business hours? Does the supplier’s finance contact ever initiate payment changes without a preceding purchase order? These contextual inconsistencies—absent in the synthetic media but present in the genuine relationship—become the new audit trail. Teams must now compare the request not to a spoofed email address, but to the established rhythm of legitimate interaction.

These behavioural discrepancies are subtle but measurable: a supplier’s accounts payable contact who has never used video call requesting payment changes via Zoom, or a finance director who consistently approves routine variations by email suddenly insisting on a voice note with time pressure. The attacker’s goal is to exploit the moment of cognitive load—end of month, pre-holiday rush—when verification steps feel like friction rather than protection.

Red flags now live in the metadata of interaction: a request arriving outside established communication windows, referencing internal project codes the supplier shouldn’t know, or mirroring language from a recent ASIC media release the target publicly commented on. Unlike a spoofed invoice with wrong banking details, these signals don’t live in the document—they live in the pattern break. Spotting them requires mapping the normal cadence of genuine supplier engagement, not just checking for typos in the email address.

Hardening the Controls: Verification Beyond the Signature

Simple email confirmation of a payment change request is no longer a control—it’s an open door. Attackers now spoof not just the supplier’s email address but their entire communication rhythm, making a reply-to-all appear legitimate while the attacker monitors the thread. Verification must break out of the compromised channel entirely.

Mandatory steps include initiating a separate, out-of-band confirmation using a pre-registered phone number from the supplier’s onboarding file—not the number in the email signature—and requiring dual approval from segregated AP and treasury teams. For high-value or atypical changes, a live video call with a known contact, using a pre-shared visual cue (like holding up a dated token), adds a layer deepfakes struggle to replicate in real time without detection.

Integrating AI threat intelligence feeds transforms verification from a reactive checklist into a proactive gatekeeper. These feeds ingest real-time signals—such as newly registered domains mimicking supplier names, anomalous login patterns on supplier portals, or dark web chatter about compromised credentials—and cross-reference them against payment change requests before approval. For example, if a request to update banking details arrives from an IP address linked to a known fraud kit, or if the supplier’s email domain shows signs of recent spoofing activity, the workflow automatically flags the transaction for enhanced scrutiny, triggering mandatory out-of-band verification regardless of the request’s apparent legitimacy.

This integration doesn’t replace human judgment but shifts the burden: instead of relying on AP staff to detect subtle inconsistencies in tone or urgency, the system surfaces elevated risk based on observable, external threat data. CFOs gain visibility into why a request was halted—not just that it was—enabling better oversight and reducing the cognitive load on teams processing high volumes. The control becomes embedded in the approval path, not bolted on as an afterthought.

Simple email confirmation fails because attackers now compromise or perfectly mimic the very channels AP teams use to verify. A reply to the spoofed email arrives from the same convincing domain, or a phone call uses voice synthesis to imitate the supplier’s finance controller. True verification requires breaking the communication chain: initiating contact through a known, independent channel—such as dialling a pre-verified number from the master supplier file or using a secure portal message—and confirming the change with a second, authorised signatory on the supplier’s side.

Embedding AI threat intelligence feeds into the payment approval workflow automates the initial risk assessment. These feeds ingest real-time signals—such as newly registered domains mimicking supplier names, anomalous login patterns on supplier portals, or dark web chatter about compromised credentials—and cross-reference them against payment change requests before approval. For example, if a request to update banking details arrives from an IP address linked to a known fraud kit, or if the supplier’s email domain shows signs of recent spoofing activity, the workflow automatically flags the transaction for enhanced scrutiny, triggering mandatory out-of-band verification regardless of the request’s apparent legitimacy.

This integration doesn’t replace human judgment but shifts the burden: instead of relying on AP staff to detect subtle inconsistencies in tone or urgency, the system surfaces elevated risk based on observable, external threat data. CFOs gain visibility into why a request was halted—not just that it was—enabling better oversight and reducing the cognitive load on teams processing high volumes. The control becomes embedded in the approval path, not bolted on as an afterthought.

Compliance and Legal Exposure Under Digital Attack

When a fraudulent payment change succeeds, the immediate loss is often dwarfed by regulatory scrutiny. ASIC expects companies to demonstrate that payment instruction verification aligns with the due diligence standards in Regulatory Guide 175 and the Corporations Act 2001, particularly sections 180 (care and diligence) and 588G (insolvent trading implications if fraud exacerbates financial distress). Simply having a policy is insufficient; evidence of consistent, documented verification against known supplier contacts is required.

Where companies falter is in treating verification as a box-ticking exercise rather than a dynamic risk assessment. A payment change request arriving via the supplier’s usual email portal might pass superficial checks, but if it lacks corroboration from a pre-registered mobile number or fails to trigger an out-of-band call to a known contact on file, it remains exposed. ASIC’s focus in recent enforcement actions has shifted from the existence of policies to the audit trail proving those policies were followed at the point of execution — specifically, whether staff deviated from protocol under pressure and whether those deviations were logged and reviewed.

This evidentiary gap is where liability crystallises. If a fraudulent payment is traced back to a verbal instruction accepted without referencing the supplier’s verified contact register — or worse, where staff were discouraged from questioning senior management’s urgency — the defence of ‘reasonable steps’ collapses. Courts increasingly look for system-enforced controls, not just manual diligence, when assessing whether directors and officers met their duty under section 180 to act with the care and diligence that a reasonable person would exercise in their position.

ASIC Regulatory Guide 274 explicitly links inadequate payment verification to breaches of the Corporations Act 2001, particularly sections 180 (care and diligence) and 588G (insolvent trading), when control failures contribute to financial loss. Recent enforcement patterns show ASIC scrutinising not just whether verification policies existed, but whether they were operationally effective — demanding evidence of real-time cross-checks against trusted supplier contact registers at the moment of payment instruction.

When a company suffers loss due to an AI-enabled impersonation that exploited a gap between policy and practice — such as accepting a payment change via deepfake audio without initiating an out-of-band call to a pre-verified number — regulators and courts treat this as a failure of due diligence. The defence shifts from 'we had a process' to 'prove the process worked when it mattered'.

Uncommon Insights

Trust scoring moves beyond static supplier lists to model the authenticity of every interaction point. Instead of treating a supplier as a single trusted entity, the system evaluates each communication channel — email domain, phone number, portal login — against a dynamic baseline of historical behaviour. A request to update bank details arriving via a newly registered domain or an unfamiliar VoIP number triggers an immediate score drop, flagging it for mandatory out-of-band verification regardless of how convincing the message appears.

This approach turns the supplier relationship into a verifiable network graph. Legitimate contacts form a tightly clustered set of known IPs, devices, and communication patterns; spoofed identities appear as isolated nodes with no historical connection to the supplier’s verified infrastructure. By mapping these relationships in real time, accounts payable teams can distinguish between a genuine process evolution and a sophisticated impersonation attempt that exploits familiar branding but lacks the underlying trust topology.

$185,000Average Loss per SME Incident
60%Detection Time Reduction Target
3Mandatory Verification Points

Trust scoring operates on continuous behavioural baselines rather than static whitelists. For example, if a supplier’s finance team has historically initiated payment change requests only via their corporate Outlook domain during Australian business hours, a sudden request arriving at 2:17 am from a Gmail address—even with perfect branding and correct invoice sequencing—would trigger an automatic score penalty. The system weights factors such as message timing, device fingerprint, and historical communication channels against the supplier’s established profile.

This dynamic assessment prevents attackers from exploiting moments of trust, such as during known contract renewals or quarterly payment cycles. By requiring out-of-band verification—like a callback to a pre-registered mobile number or a confirmation through the supplier’s authenticated portal—only when the trust score falls below a threshold, organisations maintain efficiency for low-risk transactions while applying rigorous scrutiny where it matters. The mechanism adapts as suppliers evolve their legitimate processes, reducing false positives over time without compromising security.

$185,000Average Loss per SME Incident
60%Detection Time Reduction Target
3Mandatory Verification Points

The trust score operates by continuously mapping a supplier’s verified communication ecosystem—registered domains, authorised signatory email patterns, historical invoice timing, and approved banking detail change channels—against every inbound request. Deviations trigger dynamic weighting: a payment change instruction arriving via LinkedIn message from a newly created profile, even if it mirrors past tone, incurs an immediate penalty, while a request through the supplier’s encrypted portal during their standard billing window carries minimal risk.

Securing Procurement Against AI Driven

This approach transforms supplier intelligence from a static onboarding checklist into a living defence layer. By correlating external threat feeds—such as newly registered lookalike domains or compromised credential dumps—with internal communication baselines, the system anticipates impersonation attempts before they reach accounts payable. Crucially, it avoids blanket suspicion; instead, it allocates verification effort where statistical models indicate genuine threat, preserving throughput for legitimate, high-volume suppliers.

$185,000Average Loss per SME Incident
60%Detection Time Reduction Target
3Mandatory Verification Points

Key Takeaways

Stop treating payment verification as a checkbox exercise. Embed real-time supplier identity validation into every disbursement workflow—cross-referencing communication channels, behavioural baselines, and threat intelligence before releasing funds. This isn't about adding another approval layer; it's about redesigning the trust architecture so that anomalous requests trigger automated holds and step-up verification without manual intervention.

CFOs must demand that procurement and treasury systems ingest continuous feeds of compromised credentials, lookalike domain registrations, and dark web chatter linked to supplier ecosystems. When a payment instruction deviates from established patterns—whether via email, portal, or messaging platform—the system should isolate it for forensic review, not rely on an overburdened accounts payable clerk to spot the subtle linguistic tell of a deepfake-generated request.

  • Mandate multi-channel verification for all payment detail changes Require confirmation via a pre-registered phone call to a known supplier contact, not just email reply, before updating banking information in ERP systems.
  • Deploy real-time threat intelligence feeds into payment approval workflows Integrate feeds monitoring compromised credentials, lookalike domains, and dark web mentions tied to supplier ABNs to trigger automated holds on anomalous requests.
  • Establish supplier trust scores based on communication behavioural baselines Use historical tone, timing, and channel patterns to flag deviations indicative of AI-generated impersonation attempts in payment instructions.
VERIFY NOW

Run a free supplier check in seconds

Search by business name, ABN, or ACN. Instant PASS/WARN/FAIL across 8 verification signals.

Start verifying →
VERIFY A SUPPLIER
Run a free check in seconds

Search by business name, ABN, or ACN. Get a real-time PASS/WARN/FAIL report across 8 verification checks.

Start verifying →

Contains data sourced from the Australian Business Register and ASIC, © Commonwealth of Australia, licensed under CC BY 3.0 AU.