AI Voice Scams Are Now Calling Accounts Payable

Team Neuron·
Split screen: on the left, a sleek navy robot with glowing amber eyes speaks into a call-center headset; on the right, an accounts payable clerk in a warehouse office holds a desk phone, mouth open in shock, a hand pressed to their cheek.

It is a Thursday afternoon, two days before a big steel delivery. Your office manager gets an email from your biggest supplier. They have changed banks, the new details are attached, and could the next payment go there.

She has been trained for this. She picks up the phone to check. Before she dials, her phone rings. It is the supplier's sales rep, the one she has spoken to for six years, confirming the change. Same voice, same small talk about the weather. She updates the vendor record.

Three weeks later the real supplier calls about an unpaid invoice for $84,000. The rep never made that call.

What actually changed

The scam itself is old. The FBI calls it business email compromise: a criminal gets into an email conversation, or fakes one, and redirects a payment. It is not a niche problem. In its 2025 annual report, the FBI's Internet Crime Complaint Center logged 24,768 of these complaints and just over $3 billion in reported losses. Those are only the ones people reported.

What changed is the phone call. For years, the standard advice was simple: if an email asks you to move money, call and confirm. That advice worked because faking a voice was hard.

It is not hard anymore. A few seconds of someone talking is enough to build a convincing copy of their voice. Owners and sales reps put plenty of that online without thinking about it: a video on the company website, a podcast, a voicemail greeting, a trade show clip. The same FBI report says businesses reported over $30 million lost in 2025 to these scams where artificial intelligence was involved.

That figure is small next to $3 billion, and it is worth being honest about why. Most of these frauds still work without any clever technology at all. The voice is not the new threat. It is the new way around the one check most businesses rely on.

Where it goes wrong on a normal payables desk

Almost every loss we hear about follows one of a handful of patterns.

The call comes to you. A callback only proves something if you placed the call. An incoming call that confirms the email is part of the scam, not a check on it.

The number came from the email. If you call the number in the signature block, you are calling the criminal. The same goes for a number they text you or leave in a voicemail.

The owner is "unreachable". A classic version is an urgent wire request that arrives while the owner is travelling or at a job site. There is a quick follow-up voicemail in their voice, and a note that they cannot take calls for the rest of the day. The pressure is the point.

Nobody feels allowed to say no. In a 20-person company, the controller does not want to be the one who held up the owner's deal. Criminals know this. They pick the request that feels most awkward to question.

The real inbox was broken into. Sometimes the email is not fake at all. It comes from the vendor's genuine account, which someone else now controls. It will look right because it is right, apart from the bank details.

What good looks like

The fix is not better hearing. You cannot train people to spot a cloned voice reliably, so stop asking them to. The fix is a few rules that do not depend on recognising anyone.

Bank details never change on the strength of a single contact. Not an email, not a call, not both together. Changes to where money goes get confirmed by calling a number you already had on file before the request arrived.

Two people touch every bank detail change. One person enters it. A second person, who did not take the request, makes the confirmation call and approves it.

New details wait before the first payment. Even a few business days gives the real vendor time to notice that something is off. It costs almost nothing when a change is genuine.

Unusual wires have a code word or a second channel. If the owner really does need an urgent wire, the controller confirms it through a channel agreed in advance: a word only the two of them know, or a text to a known personal number. Set this up while nobody is in a hurry.

Saying no is protected. The owner tells the finance team, in plain words, that nobody will ever be in trouble for delaying a payment to verify it. Then the owner backs that up the first time it happens.

Your own email is locked down. Many of these scams start inside your inbox, reading real invoices to learn names, amounts and timing. MFA (the extra code you get on your phone when you sign in) on every email account closes the most common way in. If you want to know what else your insurer will expect here, we covered that in what your cyber insurance renewal will actually ask.

None of this needs new software. It is policy, written down, with the owner's name behind it.

What to do about it this month

Write the one-page rule. It should say that bank detail changes are confirmed by a call to a number already on file, approved by a second person, and held before the first payment. Hand it to everyone who can pay a bill.

Pull your vendor list and check that you actually have a known phone number for each supplier you pay regularly. It should be a number from your records, not one from a recent email. This is usually an afternoon of work, and it is the foundation for everything else.

Agree the code word or second channel between the owner and whoever releases wires. Do it this week, face to face.

Ask your bank two questions. What fraud controls do they offer on outgoing payments, such as approval by a second person in online banking? And what exactly should you do in the first hour if a payment goes to the wrong place?

That second question matters more than it sounds. The FBI's same report describes a process for freezing stolen funds that recovered money in 58% of the cases it worked in 2025. Its guidance is blunt: time is of the essence. Call your bank immediately, ask for a recall of the payment, and file a complaint at ic3.gov with the full transaction details. Put those three steps on the same page as your payment rule, so nobody has to look them up in a panic.

Finally, confirm that sign-in protection is switched on for every mailbox, including shared ones like accounts@ and the owner's. If you are not sure, that is the answer.

A low-stakes way to check

Most of this you can do yourself, and we would rather you did it than waited. If you would like a second pair of eyes, our free IT assessment looks at how email, sign-in and payment approval actually work in your business today. You get a short list of where a convincing phone call could still move your money. What you do with it is up to you.