top of page

Payment Fraud Controls: Why Finance Is a Critical Line of Defense

The FBI’s 2025 Internet Crime Report, released in 2026, recorded approximately $20.9 billion in reported losses. Business email compromise accounted for approximately $3.0 billion, while complaints containing AI-related information were associated with approximately $893 million in adjusted losses. These figures reinforce a point finance leaders cannot delegate entirely to technology teams: payment fraud is also an internal-control risk.


Finance professionals applying payment fraud controls while independently verifying vendor payment instructions.

The risk is becoming more difficult to recognize. In May 2026, the FBI warned that a phishing-as-a-service platform was being used to capture Microsoft 365 access tokens and bypass multifactor authentication. Once an email account is compromised, a fraudulent request may arrive inside a legitimate conversation, use familiar language and appear to come from a known executive or vendor.


Technology controls matter. So do finance procedures designed around the possibility that a convincing request may still be fraudulent.


Six payment fraud controls finance teams should strengthen


1. Independently verify payment changes


Changes to bank instructions, remittance addresses or payment methods should be verified using contact information already maintained in an approved vendor record—not the telephone number, email address or link included in the change request.

The employee performing the verification should document who was contacted, the number used, the date and the result. This control should apply even when the request appears urgent or comes from senior leadership.


2. Separate vendor changes from payment release


An employee who creates or changes a vendor should not be able to approve and release payment to that vendor without meaningful independent review.

Where staffing is limited, management can implement compensating controls. For example, an owner or finance leader who did not process the change could review a daily report of newly created and modified vendors.


3. Make dual approval substantive


Two clicks are not the same as two reviews. The second approver should receive enough information to evaluate the payment, including the vendor name, amount, bank-account change indicator and supporting documentation.


Approval thresholds should reflect the organization’s risk and transaction patterns—not simply the financial institution’s default settings.


4. Protect the vendor master file


Limit vendor-setup rights and regularly review newly created and recently changed vendors. Organizations should also monitor for duplicate bank accounts, unusual addresses or payments issued immediately after a vendor change.


Dormant vendors should be disabled rather than left available for possible reuse.


5. Strengthen access beyond multifactor authentication


Multifactor authentication remains important, but the FBI’s 2026 warning demonstrates why it should not stand alone.


Organizations should also review active sessions and connected applications, restrict risky authentication methods, remove access promptly when roles change and investigate unusual mailbox rules or forwarding activity. Finance and information technology teams should agree in advance on which alerts require an immediate payment hold.


6. Prepare the response before an incident


Speed can materially affect the opportunity to recover funds. The response plan should identify who can stop a payment, contact the financial institution, preserve email and approval evidence, notify leadership and report the event to the FBI’s Internet Crime Complaint Center.


The plan should also establish how the organization will confirm that the attacker no longer has access before normal payment processing resumes.


Questions for leadership


  • Can one employee change a vendor and release the related payment?

  • Are changes to bank instructions verified outside email?

  • Do approvers receive enough information to identify an unusual payment?

  • Who can immediately request a wire or ACH recall?

  • When was the payment-fraud response process last tested?


How JConner can help


JConner’s Advisory team helps organizations assess payment processes, strengthen segregation of duties, design practical approval controls and document response protocols proportionate to their size and risk.



Sources and further reading



This material is general information and is not accounting, tax, legal, cybersecurity or investment advice for any specific organization or transaction.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

Hours

Monday–Friday | 8:00 a.m.–5:00 p.m. CT

© 2026 JConner PC. All rights reserved.

JConner
Assurance + Tax + Advisory

  • Facebook
  • Linkedin
  • AICPA SOC for Service Organizations logo

Privacy Policy

Terms & Conditions

Cookie Policy

Record Retention & Destruction

Client Portal & Electronic Communication

Website Accessibility Statement

bottom of page