3 min read
Fraud often succeeds not because controls are missing, but because requests appear routine. Fraudsters take advantage of established business relationships, legitimate corporate activities and convincing impersonation techniques to make fraudulent requests appear authentic, increasing the likelihood that normal verification procedures are overlooked.
Many payment fraud schemes are designed to blend into everyday business activity. A request to update payment instructions, an email tied to an active transaction or an urgent message from a familiar contact may not appear unusual at all.
That risk continues to grow. The FBI Internet Crime Complaint Center 2025 Report found that more than $3 billion was lost to impersonation fraud schemes in the United States.1 Fraudsters increasingly use legitimate business contexts, impersonation techniques and AI-generated content to make fraudulent requests appear authentic.
Effective payment controls depend on more than recognizing red flags. They depend on applying consistent verification processes, even when a request appears routine.
Can you outsmart these fraud scenarios? View our quick guide to find out.
Most organizations have controls designed to prevent unauthorized transactions. The challenge is that fraudsters often don't try to bypass those controls directly. Instead, they attempt to work within existing payment processes:
None of these requests are inherently suspicious. In fact, they may closely resemble legitimate communications that payments teams handle every day; but because the request feels familiar, it may receive less scrutiny than it otherwise would. That's where control gaps can emerge.
Impersonation scams are often successful not because controls don't exist, but because normal processes aren't applied consistently. In many cases, fraud succeeds because the request seemed reasonable enough to avoid a second look.
Verification is skipped
A request appears legitimate or originates from an established business contact, so payment details are updated without independent confirmation.
Urgency overrides process
A request tied to a time-sensitive transaction receives expedited treatment, reducing opportunities for review or escalation.
Authority influences decision-making
A request appears to come from a senior leader, legal advisor or important business partner, leading employees to bypass normal approval or verification procedures.
Exceptions become routine
Processes designed for rare circumstances gradually become normalized, creating opportunities for fraudsters to exploit established workarounds.
Strong payment controls don't rely on employees identifying every fraudulent request. They create consistent processes that apply regardless of who makes the request.
Verify payment instruction changes independently
Changes to banking information should be confirmed through a previously verified contact method already on file.
Example: A supplier emails updated account information. Rather than relying on the contact details provided in the email, the Payments team confirms the change using an existing phone number or historic contact record.
Maintain separation of duties
Critical payment activities should be performed and independently reviewed by several individuals. Each step, from creating and approving changes to releasing payments, should require oversight from a different employee to help detect errors, prevent fraud and ensure controls are executed correctly.
Example: One employee updates beneficiary information, a second reviews the change and a third authorizes payment release. Each step of the process is reviewed by another member of the team to ensure controls were followed.
Require additional review for higher-risk activity
New beneficiaries, payment instruction changes and unusual payment requests always require additional approval and validation.
Example: Payment changes require both operational review and payments approval before becoming effective.
Monitor requests that fall outside normal patterns
Unusual timing, changes in communication channels or requests that create urgency must be escalated for additional verification.
Example: A request to move a conversation from email to text messaging during a payment change is escalated for review.
As fraud tactics evolve, technology and monitoring play an important role. However, some of the most effective controls remain process driven.
These questions can help ensure that routine requests receive the same level of scrutiny as unusual ones. Before approving a payment or updating payment details, consider:
Fraudsters understand that trust is essential to business operations. They also understand that familiarity can create assumptions that lead to shortcuts in verification and approval processes.
The supplier may be real, the transaction may be legitimate, and the relationship may be well established—but that doesn’t mean controls or procedures can be bypassed.
The most effective payment controls are the most consistent ones. By applying the same verification, approval and review processes regardless of who is making the request, organizations can help reduce opportunities for fraud and strengthen the integrity of payment operations.
If you believe you’ve sent out a fraudulent transaction or have become a victim of fraud, contact the Global Banking Fraud Recovery Team at gb.fraud.recovery@jpmorgan.com.
If you suspect your account or systems have been compromised, contact your service representative immediately.
For more tips, check out our guide to business email compromise to learn more about payments fraud prevention.
JPMorgan Chase Bank, N.A. Member FDIC. Visit jpmorgan.com/commercial-banking/legal-disclaimer for disclosures and disclaimers related to this content.