
What happened
J.P. Morgan says AI lets fraudsters mimic supplier communication patterns, voice and video more easily, so fraudulent payment instructions can enter a legitimate workflow early and still pass established approvals.
Why it matters
The risk has shifted upstream from the transaction to the identity and instruction behind it, so transaction-level checks may offer limited protection when the compromise happened before approval.
What to watch
Whether firms connect identity proofing, payee assurance and workflow context before release, since detecting a change shortly before payment is more revealing than checking the amount alone.
WHO IT HITSThis lands hardest on accounts payable, procurement, treasury and security teams at companies that pay suppliers, because they own the supplier onboarding, account-change verification and release steps where fraudulent instructions now enter.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
J.P. Morgan's argument starts from a shift in where fraud enters the payment lifecycle. Traditionally, transaction-level controls looked for an unusual amount or activity outside an established pattern. But the bank notes that a carefully constructed attack can avoid those signals: the invoice may be real, the amount expected, and the request may arrive at the expected time.
The more revealing evidence tends to sit around the transaction. An account change shortly before payment, or a verification call that relies on details supplied in the request rather than a separately maintained source, can point to a compromise that happened well before approval. J.P. Morgan frames the full chain of trust behind a payment — especially the steps used to establish or change payment instructions — as part of the customer's control environment.
The stakes come down to coordination. Procurement, accounts payable, treasury and security each hold part of the picture, and when those signals remain separated a legitimate-looking request can move through the gaps. The bank's suggested test is whether firms can challenge a suspicious change before funds move, rather than relying on recovery afterward. It also notes AI is being used defensively, through bot detection, deepfake detection and layered biometric controls, so the outcome may hinge on how well those earlier signals are joined up.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Anthropic launched a new Claude tool aimed at financial advisors, and the offering includes integrations with…

Vertiv agreed to buy UtilityInnovation Group for about $1.45 billion, and Broadcom's fiscal Q3 2026 AI semicon…

CrowdStrike rose 12% to $232.08, Zscaler 12% to $183.97, and Palo Alto Networks 11% to $366.40 in midday Monda…

Seagate posted Q4 revenue of $3.63B, up 48.5% YoY, and is shipping Mozaic 4 HAMR drives up to 44 terabytes to…

Seeking Alpha published an analysis titled "Western Digital: More Consolidation Necessary - Multi-Year AI-Driv…

Intuitive Surgical reported a prospective study tying Force Feedback to faster bowel function recovery after p…
