Bunny Honey ClubBunny Honey/blog
Work with us
← back to indexblog / ai / ai-invoice-fraud-small-business
AI

How AI Turned Invoice Fraud Into a $3 Billion Problem

The FBI logged $3 billion in business email compromise losses in 2025. AI is what makes the fake vendor email sound real. Here's the fix.

AH
Arthur HofFounder, Bunny Honey Club AI
publishedAug 11, 2026
read5 min
How AI Turned Invoice Fraud Into a $3 Billion Problem

An employee at Arup, the engineering firm behind the Sydney Opera House, joined a video call with his UK-based CFO and several colleagues to approve a confidential transaction. Everyone on the call looked and sounded right. He sent $25.6 mi

An employee at Arup, the engineering firm behind the Sydney Opera House, joined a video call with his UK-based CFO and several colleagues to approve a confidential transaction. Everyone on the call looked and sounded right. He sent $25.6 million across 15 wire transfers before anyone realized every person on that call, other than him, was AI-generated.

That happened in Hong Kong in early 2024. It is no longer the outlier it once was. Business email compromise, the scam where a fraudster impersonates a vendor or executive to redirect a payment, cost businesses reported to the FBI $3 billion in 2025, and generative AI is exactly what's closing the gap between "obviously fake" and "I checked and it looked legitimate." Here's what actually changed, what the FBI's own numbers show, and the workflow that stops it before the wire goes out.

The old wire-fraud trick just got a much better disguise

Business email compromise is not new. It has been the classic move for a decade: compromise or spoof an email account, wait for an invoice thread already in progress, then insert a message asking to redirect payment to a "new" bank account right before money is due to move.

What AI changes is the quality of the disguise. The FBI's own advisory on generative AI and financial fraud describes chat models producing polished, error-free messages that mimic a specific executive's tone, and voice-cloning tools that need only a few seconds of audio, pulled from a podcast, a webinar, or a voicemail greeting, to fake a phone call. The Arup case took that one step further: not a cloned voice on a call, but cloned faces and voices on video, in real time, good enough to fool someone who knew the people they thought they were talking to.

None of this requires a criminal organization with real resources. The tools that clone a voice or write a convincing email are consumer-grade, cheap, and require no special access.

The FBI's own numbers show how fast this is growing

$3.05BUS business email compromise losses reported to the FBI, 2025
$30M+of that specifically tied to a confirmed AI component
~$123Kaverage loss per reported BEC case in 2025
58%success rate of the FBI's fund-freeze program, when reported fast

Business email compromise is the second-costliest crime type the FBI tracks, behind only investment fraud, and it moved $3,046,598,558 out of US businesses in 2025 alone across 24,768 reported cases. That averages out to roughly $123,000 per case, and because 86% of that money moves by wire transfer or ACH, it is usually gone within minutes of being sent, not sitting in a account that can be frozen at leisure.

The $30 million figure businesses specifically flagged as AI-involved is worth reading carefully. It is almost certainly a floor, not a ceiling. The FBI's own report notes that not every BEC tactic is AI-enabled, and the flip side of that is just as true: a business that gets fooled by a cloned voice or a well-written fake email rarely finds out afterward that AI was the tool used. Most victims just find out the money is gone. The real AI-assisted share of that $3 billion is a number nobody can currently put a figure on, ours included.

The moment your business is most exposed: a vendor changes its bank details

Nearly every real BEC loss traces back to the same single moment: someone, somewhere in the payment chain, accepted a change to where money should go without independently confirming it. The email looked right. It came from a thread that had been going on for weeks. The signature block matched. The urgency was plausible, an invoice really was due.

That is precisely the moment AI is built to exploit, because AI's whole advantage is removing the tells a careful reader used to catch: the awkward phrasing, the slightly-wrong signature, the voice that almost sounds right. A well-written scam email or a cloned-voice callback removes the cues your team has been trained to look for, which is exactly why the fix can't be "read more carefully."

If your only defense against a fake vendor email is a human noticing something felt off, AI just took away the thing they were noticing.

Bunny Honey Club

The verification workflow that actually stops it

The single control that stops nearly all of this: any change to payment or bank details gets verified through a channel you already trust, never one supplied in the request. Call the vendor's known number, the one already on file, not the number in the email signature. Confirm with a person, not a reply to the same thread that might itself be compromised.

The problem is that this only works if it happens every single time, under deadline pressure, on the exact day an invoice is due, without depending on someone remembering. That's not a policy problem. It's a workflow problem, which is the part we build for a living.

A verification step that actually holds up looks like this: any bank-detail change on a vendor record triggers an automatic hold on that vendor's next payment, a Slack or email alert to a second person who has to approve it, and a logged callback confirmation before the hold releases. No single person can approve a payment change to an account nobody's verified. It runs the same way at 4pm on a slow Tuesday as it does at 6pm the day before a big vendor invoice is due, because it isn't relying on anyone's judgment in the moment. We've written before about the version of this pattern that runs on the other side of your books, automating the invoice-to-cash flow so you get paid faster; this is the mirror image, the same automation discipline applied to protecting what goes out instead of speeding up what comes in.

The same principle we've argued for AI agents handling anything consequential applies here even without an agent in the loop: never let one unverified input, human or AI-generated, trigger an action you can't undo. A wire transfer is about as undoable as business actions get.

What this costs to build vs. what one wire transfer costs to lose

A hold-and-verify workflow wired into your accounting and communication tools is days of setup, not months, and it runs quietly in the background from then on. Compare that against the FBI's own math: the average reported BEC case in 2025 moved roughly $123,000, and once a wire clears, the Recovery Asset Team's Financial Fraud Kill Chain only has a real shot at freezing it in the hours immediately after, not the days or weeks it usually takes a business to notice.

This isn't a reason to distrust every vendor email or treat your team like suspects. It's a reason to stop trusting the channel and start verifying the change itself, every time, automatically, so nobody has to be the one who has to catch it by instinct on the one day it matters. The same logic we've made for not handing client data to a chat window without a policy behind it holds here too: the risk isn't the tool, it's the absence of a system standing between a request and an action with real money attached.

— share
— keep reading

Three more from the log.