Version 1 - Primary Nav Search
2 people looking at a laptop

9 min read

Key takeaways

  • AI-enabled fraud increasingly targets trust before payment, using compromised or convincingly impersonated identities to insert false instructions into legitimate workflows.
  • An authorized, policy-compliant payment can still be fraudulent when the identity or instruction behind it has been compromised.
  • Stronger prevention depends on verifying trust at critical handoffs and aligning teams around clear ownership and escalation.

AI is changing where fraud enters the payment lifecycle. Increasingly, losses can stem from authorized payments initiated through compromised or convincingly impersonated identities. False supplier or payee instructions can enter a legitimate workflow early, pass through established approvals and still direct funds to the wrong account.

That shifts the risk upstream. Transaction-level checks remain important, yet they may offer limited protection when the identity or instruction was compromised before the payment reached approval.

J.P. Morgan views the full chain of trust behind a payment as part of the customer’s control environment—especially the steps used to establish or change payment instructions before release.

What is vendor impersonation fraud?

Vendor impersonation fraud occurs when a fraudster poses as a legitimate supplier or business contact to persuade an organization to change payment instructions, update account details or send funds to a fraudulent account. The request may appear authentic because it uses familiar names, communication patterns, invoices or compromised email accounts.

Historically, convincing impersonation required more effort to reproduce the signals people associate with a trusted supplier. AI lowers that barrier. Fraudsters can mimic familiar communication patterns or reinforce a request with realistic voice or video, making trusted signals easier to replicate at scale.1

The payment request may also be the visible result of a broader cyber compromise. Account takeover or stolen credentials can give an attacker access to a trusted identity or communication channel long before a fraudulent instruction reaches the payment workflow.2

When the documentation aligns with a legitimate transaction, the request may not raise immediate concerns. The invoice may be real and the amount expected even though the identity behind the request or the account-verification process has been compromised.

A compliant payment can still be fraudulent

Consider a supplier asking to update its bank details. The request appears to come from a known contact and references an expected invoice, with a reasonable explanation. An employee verifies the information, updates the record and routes the change through the normal approval process.

When the payment is released, the established supplier and expected amount make it look routine. The required approvals are already in place because the fraudulent instruction entered the workflow much earlier.

The process may have worked as designed even though the information supporting it was compromised. The payment can be fully authorized because the compromise happened earlier, in the identity or instruction supporting it.

The verification call may have relied on details supplied in the request rather than a separately maintained source.3 A compromised email makes the instruction even harder to distinguish from ordinary business activity.

Authorization alone can’t establish authenticity. An employee may have the right authority to approve the transfer, and the payment may fall within policy. Neither confirms that the request was genuine or that the account belongs to the intended recipient.

Even attentive employees can act on a malicious request when it closely resembles something they handle every day. AI makes that resemblance easier to create and repeat, giving attackers more opportunities to find a weak point in the process.

Payment integrity depends on controls that operate well before release, including those used to onboard suppliers and verify changes to account information. A weakness in any of these areas can shape the payment before the approver ever sees it.

Payment initiation provides another critical checkpoint, where identity assurance can draw on credentials, device signals, patterns, entitlements and established counterparty relationships—signals AI cannot readily generate.

Trust requires better evidence

Business payments depend on established relationships. Teams learn how suppliers communicate and which requests fit normal patterns. That familiarity helps work move efficiently. It also gives attackers a model to copy.

Traditional controls often ask whether a payment was approved and whether the transaction looks reasonable. AI-enabled impersonation raises a deeper question: Can the organization trust the identity and instruction behind the payment?

A familiar name can appear in a legitimate email thread after the account has been compromised. A realistic voice message may reduce an employee’s hesitation about an urgent change. When the request aligns with an expected transaction, recognition can feel like confirmation—even though it isn’t enough on its own.

Treating every instruction as suspicious would slow routine activity and create more work for teams already managing complex payment operations.

“Stronger protection comes from recognizing when the context has changed enough to require better evidence.”

For example, a payment to a long-standing, independently verified account carries a different level of risk than an urgent request involving new bank details. The supplier relationship still provides useful context, though it shouldn’t override independent verification when a material instruction changes.

Traditional fraud controls often focus on the transaction itself. They may flag an unusual amount or activity outside an established pattern. Those signals remain useful, yet a carefully constructed attack may avoid them.

The payment amount can match a real invoice, and the request may arrive at the expected time. Viewed on its own, it may offer little reason for concern.

Activity around the transaction can be more revealing, particularly when an account change occurs shortly before payment or the verification process relies on information supplied by the requester.

Seeing those connections requires context across the workflow. Identity and account information should be considered along with how the request moved through the organization. A wider view can expose relationships that a transaction-level check misses and give teams more time to act before funds move.

Prevention depends on the operating model

The strongest operating models apply more scrutiny where risk is elevated while preserving speed for routine activity. That requires clear ownership and practical escalation paths across the teams that shape a payment before release.

Identity proofing can help establish who is making the request, while payee assurance can verify whether the account belongs to the intended recipient. Workflow controls can then trigger further review when a material change falls outside established behavior.

Those controls become more effective when they work together. An account update may look ordinary in one system, then take on greater significance when it coincides with an unfamiliar contact method or a deviation from the expected approval path.

That earlier context changes the response. Teams can challenge a suspicious change before funds move, instead of relying on recovery after the fact.

Technology can surface risk, but ownership determines whether teams act on it. Procurement may manage the supplier relationship, accounts payable the invoice, treasury the release and security the evidence of compromised credentials. When those signals remain separated, a legitimate-looking request can move through the gaps.

A resilient operating model defines who can pause a request, what evidence is required to resume it and how concerns move across functions. The goal is to make risk visible at the handoffs where trust is established or changed.

Better coordination lets teams concentrate scrutiny where risk is meaningful without adding friction to every payment. Over time, that operating discipline becomes part of resilience, helping the organization adapt as threats change while legitimate payment activity keeps moving.

A wider view creates more time to act

As fraud becomes more industrialized, the challenge expands from detecting suspicious transactions to validating the trust behind the identities and instructions that produce them. Automation makes attacks easier to repeat and adapt, increasing the value of seeing risk across the payment ecosystem.

A transaction-level view may identify a suspicious payment. Broader context can reveal the sequence of events that produced it, including a compromised identity or a change introduced earlier in the workflow.

The sooner those signals come together, the greater the opportunity to prevent loss.

J.P. Morgan approaches fraud prevention as an ecosystem challenge. Intelligence drawn from the payments environment can help enterprises identify risk earlier and respond with greater confidence.

AI is also being used defensively as fraud becomes more automated. Bot detection, deepfake detection and layered biometric controls can provide additional signals for assessing whether an interaction or identity is genuine.4

Protection should begin before release and extend across the payment workflow, including verification of the receiving account and the approvals supporting the instruction.

A request can sound authentic and move through a policy-compliant workflow even when the underlying instruction has been compromised. Organizations that connect identity, account verification and workflow context earlier can challenge suspicious changes before funds move.

As AI makes trusted signals easier to imitate, resilience will increasingly depend on how well organizations validate trust across the payment ecosystem while keeping legitimate business activity moving.

Frequently asked questions about AI-powered B2B payment fraud

Vendor impersonation fraud occurs when a criminal poses as a trusted supplier or business partner to convince an organization to change payment instructions or send funds to a fraudulent account. These attacks often rely on convincing communications that appear to be part of a legitimate business process.

Vendor impersonation fraud describes the scheme used to redirect payments by impersonating a trusted vendor. Business email compromise (BEC) is one way attackers carry out that scheme, often by taking over or spoofing a legitimate email account to make fraudulent payment requests appear authentic.

AI makes convincing impersonation easier to create and repeat at scale. Fraudsters can reproduce familiar communication patterns or use realistic voice and video to make false requests appear more credible, increasing pressure on organizations to verify the identity and instruction behind a payment.

Transaction-level checks remain important, but they may not reveal a compromise that entered the workflow earlier. A payment can follow established approval rules even when the identity, account information or instruction supporting it has been manipulated.

Organizations can strengthen resilience by validating material changes independently, connecting identity and account information to the surrounding workflow and establishing clear ownership for escalation. Cross-functional coordination helps teams respond when trusted signals no longer provide enough evidence on their own.

Contact us

This field is required.

This field is required.

This field is required.

This field is required.

This field is required.

Please enter a valid business email. This field is required.

Please enter a valid business email. This field is required.

Please enter a valid business email. This field is required.

By checking the box below I consent to JPMorganChase using the information I have provided to send me:

Learn more about our data practices in our privacy policy.

Disclaimer: 

J.P. Morgan, JPMorganChase, Chase, Chase Merchant Services, and Chase Payment Solutions are marketing names for certain businesses of JPMorganChase and its subsidiaries worldwide (collectively, “JPMorganChase”). Products or services may be marketed and/or provided by commercial banks such as JPMorgan Chase Bank, N.A., securities or other non-banking affiliates or other JPMorganChase entities. JPMorganChase contact persons may be employees or officers of any of the foregoing entities and the terms “J.P. Morgan”, “JPMorganChase”, “Chase”, “Chase Merchant Services” and “Chase Payment Solutions” if and as used herein include as applicable all such employees or officers and/or entities irrespective of marketing name(s) used. Nothing in this material is a solicitation by JPMorganChase of any product or service which would be unlawful under applicable laws or regulations. 

In preparing this material, we have relied upon and assumed, without independent verification, the accuracy and completeness of all information available from public sources or which was provided to us or which was otherwise reviewed by us. This material is for discussion purposes only and is incomplete without reference to any other applicable briefings provided by JPMorganChase. Neither this material nor any of its contents may be disclosed or used for any other purpose without the prior written consent of JPMorganChase.

This material is not intended to provide legal, tax, investment, accounting, financial, business, real estate, technology or other advice, and should not be used for or relied upon for these purposes. The views, opinions, estimates and strategies expressed in this material are those of the respective individual contributors, authors or speakers, and may differ from those of JPMorganChase, or its employees and affiliates. Any market and/or economic commentary in this material in no way constitutes JPMorganChase research and should not be treated as such. Further, the views expressed in this content may differ from those contained in JPMorganChase research reports. The content in this material has been obtained from sources deemed to be reliable, but JPMorganChase makes no representation or warranty as to its accuracy or completeness. In no event shall JPMorganChase nor any of its directors, officers, employees or agents be liable for any use of, for any decision made or action taken in reliance upon, or for any inaccuracies or errors in or omissions from, this material.

The information in this document may be based upon management forecasts supplied to us and reflects prevailing conditions and our views as of this date, all of which are accordingly subject to change. JPMorganChase’s opinions and estimates constitute J.P. Morgan’s judgment and should be regarded as indicative, preliminary and for illustrative purposes only.

Not all products and services are available in all geographic areas. Eligibility for particular products and services is subject to final determination by JPMorganChase and or its affiliates. This material does not constitute a commitment by any JPMorganChase entity to extend or arrange credit or to provide any other products or services and JPMorganChase reserves the right to withdraw at any time. All products and services are subject to applicable laws, regulations, and applicable approvals and notifications. 

Any mentions of third-party trademarks, brand names, products and services are for referential purposes only and any mention thereof is not meant to imply any sponsorship, endorsement, or affiliation.

Notwithstanding anything to the contrary, the statements in this material are not intended to be legally binding. Any products, services, terms or other matters described herein (other than in respect of confidentiality) are subject to, and superseded by, the terms of separate legally binding documentation and/or are subject to change without notice.

JPMorgan Chase Bank, N.A. Member FDIC. Deposits held in non-U.S. branches are not FDIC insured. Non-deposit products are not FDIC insured.

JPMorgan Chase Bank, N.A., organized under the laws of U.S.A. with limited liability. 

© 2026 JPMorgan Chase & Co. All Rights Reserved.