Version 1 - Primary Nav Search
man using credit card on laptop

3 min read

Key takeaways

  • Fraudsters’ main objectives are to redirect funds, alter beneficiary and account data, obtain sensitive information or get staff to bypass established payment procedures
  • Fraudsters succeed by making payment-related requests feel normal and familiar, so they receive less scrutiny than they should
  • When a request feels urgent, secretive or out of the norm, the safest action is to pause and verify before moving funds

Fraud often succeeds not because controls are missing, but because requests appear routine. Fraudsters take advantage of established business relationships, legitimate corporate activities and convincing impersonation techniques to make fraudulent requests appear authentic, increasing the likelihood that normal verification procedures are overlooked.

Many payment fraud schemes are designed to blend into everyday business activity. A request to update payment instructions, an email tied to an active transaction or an urgent message from a familiar contact may not appear unusual at all.

That risk continues to grow. The FBI Internet Crime Complaint Center 2025 Report found that more than $3 billion was lost to impersonation fraud schemes in the United States.1 Fraudsters increasingly use legitimate business contexts, impersonation techniques and AI-generated content to make fraudulent requests appear authentic.

Effective payment controls depend on more than recognizing red flags. They depend on applying consistent verification processes, even when a request appears routine.

Can you outsmart these fraud scenarios? View our quick guide to find out.

When familiar requests bypass scrutiny

Most organizations have controls designed to prevent unauthorized transactions. The challenge is that fraudsters often don't try to bypass those controls directly. Instead, they attempt to work within existing payment processes:

  • A supplier requests updated banking information
  • An executive asks for an urgent payment
  • A legal partner involved in a transaction provides payment instructions

None of these requests are inherently suspicious. In fact, they may closely resemble legitimate communications that payments teams handle every day; but because the request feels familiar, it may receive less scrutiny than it otherwise would. That's where control gaps can emerge.

Where payment controls can break down

Impersonation scams are often successful not because controls don't exist, but because normal processes aren't applied consistently. In many cases, fraud succeeds because the request seemed reasonable enough to avoid a second look.

Verification is skipped

A request appears legitimate or originates from an established business contact, so payment details are updated without independent confirmation.

Urgency overrides process

A request tied to a time-sensitive transaction receives expedited treatment, reducing opportunities for review or escalation.

Authority influences decision-making

A request appears to come from a senior leader, legal advisor or important business partner, leading employees to bypass normal approval or verification procedures.

Exceptions become routine

Processes designed for rare circumstances gradually become normalized, creating opportunities for fraudsters to exploit established workarounds.

Strengthen controls around routine requests

Strong payment controls don't rely on employees identifying every fraudulent request. They create consistent processes that apply regardless of who makes the request.

Verify payment instruction changes independently

Changes to banking information should be confirmed through a previously verified contact method already on file.

Example: A supplier emails updated account information. Rather than relying on the contact details provided in the email, the Payments team confirms the change using an existing phone number or historic contact record.

Maintain separation of duties

Critical payment activities should be performed and independently reviewed by several individuals. Each step, from creating and approving changes to releasing payments, should require oversight from a different employee to help detect errors, prevent fraud and ensure controls are executed correctly.

Example: One employee updates beneficiary information, a second reviews the change and a third authorizes payment release. Each step of the process is reviewed by another member of the team to ensure controls were followed.

Require additional review for higher-risk activity

New beneficiaries, payment instruction changes and unusual payment requests always require additional approval and validation.

Example: Payment changes require both operational review and payments approval before becoming effective.

Monitor requests that fall outside normal patterns

Unusual timing, changes in communication channels or requests that create urgency must be escalated for additional verification.

Example: A request to move a conversation from email to text messaging during a payment change is escalated for review.

Verification remains one of the strongest controls

As fraud tactics evolve, technology and monitoring play an important role. However, some of the most effective controls remain process driven.

These questions can help ensure that routine requests receive the same level of scrutiny as unusual ones. Before approving a payment or updating payment details, consider:

  • Is this request consistent with normal business activity?
  • Has it followed established approval procedures?
  • Have payment instructions been independently verified?
  • Is urgency influencing the decision-making process?
  • Would the same controls be applied if the request came from someone unfamiliar?

Familiar doesn't always mean legitimate

Fraudsters understand that trust is essential to business operations. They also understand that familiarity can create assumptions that lead to shortcuts in verification and approval processes.

The supplier may be real, the transaction may be legitimate, and the relationship may be well established—but that doesn’t mean controls or procedures can be bypassed.

The most effective payment controls are the most consistent ones. By applying the same verification, approval and review processes regardless of who is making the request, organizations can help reduce opportunities for fraud and strengthen the integrity of payment operations.

Final takeaways

  • Impersonation scams leverage legitimate organizations, established business relationships and convincing impersonation techniques to disguise fraudulent payment schemes as authentic business activity
  • Fraudsters may target both payment processes and authentication workflows
  • Executive requests, acquisition-related communications and bank security notifications can all be impersonated
  • Consistent verification, independent confirmation and separation of duties remain highly effective controls
  • Familiarity should never replace verification when payments, credentials or account access are involved

How we can help

If you believe you’ve sent out a fraudulent transaction or have become a victim of fraud, contact the Global Banking Fraud Recovery Team at gb.fraud.recovery@jpmorgan.com.

If you suspect your account or systems have been compromised, contact your service representative immediately.

For more tips, check out our guide to business email compromise to learn more about payments fraud prevention. 

JPMorgan Chase Bank, N.A. Member FDIC. Visit jpmorgan.com/commercial-banking/legal-disclaimer for disclosures and disclaimers related to this content.