What is payment fraud?

Payment fraud is the use of deception to redirect, extract or manipulate business payments — through compromised email threads, falsified invoices, changed bank details, taken-over accounts or manipulated vendor records. Unlike malware-driven attacks, most payment fraud is procedurally correct: real invoices, real approvers, real payment runs, with only the destination quietly wrong. The FBI recorded over 20 billion dollars in reported cybercrime losses in 2025; business email compromise alone accounted for more than 3 billion.

Also known as: B2B payment fraud · payment fraud protection · financial payment fraud · wire fraud · payment diversion fraud

The main types

Business email compromise (BEC): fraud through legitimate-looking email, often a genuinely compromised mailbox, steering a payment or bank-detail change. Vendor impersonation and invoice fraud: a real debt paid to a criminal account after a convincing detail change. Account takeover: control of a finance user or vendor portal account used to initiate or approve payments. Internal manipulation: privileged insiders editing vendor master data. And costly honest error — duplicate and mistaken payments — which loses as much money as fraud and shares the same fix.

Why it beats the controls you already have

Each incumbent control sees one slice: email security sees the message, ERP controls see the approval chain, the bank sees a validly instructed transfer. The fraud lives across the slices — a clean message, a real invoice, a correct approval, a wrong account. Catching it requires correlating vendor behavior, email context and payment data as one flow, which is the reason dedicated payment security platforms such as Trustmi exist. Prevention beats recovery decisively here: recovery odds decay within hours of a transfer.

Sources: FBI IC3 — 2025 Internet Crime Report

// In the Cyberdis portfolio

Trustmi protects the entire payment flow end to end — distributed by Cyberdis.

// FAQ

Common questions.

How big are payment fraud losses?

The FBI’s IC3 2025 Internet Crime Report records 20.9 billion dollars in reported US cybercrime losses, with business email compromise the second-costliest category at over 3 billion dollars across roughly 24,800 complaints — about 123,000 dollars per incident. Actual losses are higher: many incidents go unreported.

What is the most common form of B2B payment fraud?

Variants of the bank-detail change: a compromised or impersonated vendor supplies new payment details attached to a genuine invoice. It defeats email filters (nothing malicious to detect) and ERP controls (the invoice is real and approved).

What actually prevents payment fraud?

Layered controls: verified-channel confirmation of every bank-detail change, segregation of duties in the ERP, and a correlation layer that watches the whole payment flow — vendor behavior, emails, files and payment data together — and stops anomalous payments before execution.

Related explainers: What is business email compromise (BEC)?What is vendor impersonation fraud?How do you detect a fraudulent invoice?Can you recover money after payment fraud?

Weighing approaches? Dedicated payment fraud prevention vs ERP controls and email security