Estimated reading time: 9 minutes
Half of American finance professionals have let an unusual payment request through, or nearly did, because it appeared to come from someone they trusted.
That figure sits at the center of the Yooz 2026 Payment Fraud Readiness Report, published this month. It matters because trust was never a control. It was a shortcut that worked while forged invoices looked forged.
Yooz surveyed 750 US finance, accounting and accounts payable professionals through the Pollfish platform in July. Seventy percent say their organization faced a payment fraud attempt in the past two years or could not rule one out. That number combines 54% reporting a known attempt with 16% who suspect one happened without being able to confirm it.
Among organizations that faced a known attempt, 72% caught it before money moved. The other 28% did not.

What Payment Fraud Actually Costs
Among organizations reporting an incident in the past two years, 57% said their highest one cost at least $25,000. Thirty-nine percent lost $50,000 or more. Fifteen percent lost at least $100,000. Only 11% escaped with no financial loss at all.
Recovery drags. Just 14% fully resolve an incident within a day. Thirty-five percent need a week or more, and 15% take a month or longer.
Business email compromise or phishing aimed at the finance team was the most common attack type at 50%, followed by duplicate payments at 40% and vendor impersonation or unauthorized banking changes at 37%. Asked where fraud enters the process, respondents named email-based payment requests at 44% and rushed approvals or exception handling at 38%.
Why Human Judgment Stopped Being A Payment Fraud Control
Laurent Charpentier, chief executive of Yooz, argues the underlying model has expired.
“For years, companies have treated fraud mainly as a people problem: train employees to spot the fake email and hope an approver catches something suspicious,” he said. “That approach is becoming less reliable as generative AI makes fraudulent invoices, emails, and even voice requests much harder to distinguish from the real thing.”
Asked what replaces judgment, he pointed at the payment process itself.
“Companies should shift from controls that depend primarily on someone spotting something suspicious to controls that are built directly into the payment process,” Charpentier told Cyber Insurance News. “That means independently verifying vendor and banking changes, requiring appropriate approvals for higher-risk transactions, maintaining a clear audit trail and using real-time monitoring to flag unusual activity before money moves.”

The pressure data supports him. Forty-two percent of respondents have felt pushed to approve a payment faster than they were comfortable with at least occasionally. Fifty-four percent say workload makes it harder to follow every fraud-prevention step. Fifty-nine percent spend three or more hours a week on manual exception handling.
Only 20% are extremely confident their current process would stop a sophisticated attempt before money leaves the business. Forty percent accept that one could slip through.
The Automation Finding Does Not Say What It Appears To Say
One result in the report looks like a clean argument for automation, but it is not.
Mostly manual teams lost money in 42% of known fraud attempts. Teams running a mix of automated and manual processes lost money in 22%. Highly automated teams lost money in 30%. If automation reduced losses in a straight line, the most automated group should have performed best.
Charpentier declined to claim the win.
“That result is interesting, but I don’t think it points to a simple conclusion that mixed operations are safer than highly automated ones,” he said. “Only 9% of respondents described their finance operations as highly automated, so that group was relatively small.”
That is a small base carrying a headline number, and he named it about his own product category. What survives is the contrast at the other end.
“The clearest contrast in the data is with mostly manual teams, which lost money in 42% of known fraud attempts,” Charpentier said. He also drew a line around what automation does on its own. “The risk comes when companies treat automation as a substitute for oversight. Rules, thresholds and approval processes still need to be reviewed as the business and threat environment change.”
AI Improves Detection. The Report Does Not Show It Reduces Loss.
Teams actively using AI in finance operations identified fraud attempts at more than twice the rate of teams that did not, 63% against 30%. Forty-six percent of AI users feel more protected than a year ago, against 32% of non-users.
Read those numbers carefully. Every AI finding in the report measures identification or confidence. None measures loss rate by AI use. Higher identification may mean AI catches attempts that manual review misses. It may also mean AI users are noticing what was always happening to them.
For cyber insurance underwriting, that distinction is the whole question. A control that improves visibility changes what an applicant can report. A control that reduces loss changes what a carrier pays. The report evidences the first.
Charpentier frames AI as triage rather than replacement. “Employees still have an important role, but technology can help surface the transactions that actually need their judgment.”
Concern is running ahead of readiness. Forty-eight percent name an AI-powered threat as their top emerging worry, whether AI-generated phishing, fake invoices at scale, or deepfakes. Only 21% believe finance teams are extremely prepared for AI-enabled fraud. The same gap appears in German loss data this year, where companies increasingly suspect AI involvement without being able to prove it.
What Underwriters Can Ask About Payment Fraud Controls
Put the cyber insurance underwriting question to Charpentier directly, and he hands back the questions rather than the answers.
“From a finance operations perspective, those controls can give a useful picture of how an organization is managing payment risk. How insurers ultimately incorporate them into underwriting decisions is their call,” he said. “But the underlying questions are important: How are vendor changes verified? Are sensitive payments subject to the right approvals? Are unusual transactions flagged before payment? Is there a clear record of who approved what?”
He added one caution that cuts against the obvious reading of his own report. “I also wouldn’t look at the amount of automation alone. What matters is how it’s being used.”
That is the difference between asking an applicant whether they have accounts payable (AP) automation and asking whether the automation enforces anything. A platform that routes invoices faster without enforcing dual approval on vendor banking changes has not touched the exposure.
The harder question sits in coverage rather than controls. When an employee authorizes a payment because a convincing impersonation persuaded them it was real, the money leaves voluntarily. That is the distinction most social engineering fraud cover turns on, and it usually sits at a sublimit far below the policy limit. Charpentier sends it where it belongs.
“How a specific loss is covered or transferred is ultimately a conversation for businesses, their advisers and their carriers,” he said. “From our perspective, the focus is reducing the likelihood that the fraudulent payment gets through in the first place.”
Get Our Podcast
Nobody Owns The Password. Passpack CEO Chris Skipworth Explains The Credential Gap Sitting Inside Your Next Renewal – PODCAST

Two things are worth holding in mind.
This is vendor-sponsored research, and every finding points toward the sponsor’s product category. Pollfish is a mobile survey panel, so respondents self-identify as finance professionals rather than being verified through a business panel.
Neither undoes the findings, and Charpentier’s willingness to disown his own strongest-looking data point buys the rest of it credibility. But the manufacturing subsample deserves a closer look than the report gives it. Thirty-one percent of manufacturing finance professionals say an attempt possibly occurred and they could not be certain, nearly double the 16% overall. Manufacturing is also the only sector where manual invoice review tops the list of perceived entry points, at 42%.
That is not a sector with more fraud. It is a sector that cannot tell. For a cyber insurance underwriter pricing crime or social engineering cover on a manufacturing account, uncertainty in the applicant’s own answers is the finding.
The report’s most useful contribution is not that AI is coming for accounts payable. It is that 49% of finance professionals already know exactly how a payment gets through, because they have nearly let one through themselves. The control question is whether anything in the process would have stopped them.
FAQ – Payment Fraud Controls
How common are payment fraud attempts against finance teams?
Yooz found 70 percent of US finance professionals report an attempt in the past two years or cannot rule one out. That combines 54 percent reporting a known attempt with 16 percent who suspect one occurred without confirmation. Among known attempts, 28 percent resulted in lost money.
What does a payment fraud incident cost?
Among organisations reporting an incident, 57 percent said the most significant one cost at least 25,000 dollars. Thirty-nine percent lost 50,000 or more and 15 percent lost at least 100,000. Only 14 percent fully resolve an incident within a day.
Do automated accounts payable processes reduce fraud losses?
The data is mixed. Mostly manual teams lost money in 42 percent of attempts, mixed operations in 22 percent and highly automated teams in 30 percent. Yooz CEO Laurent Charpentier notes only 9 percent of respondents described operations as highly automated, making that group small.
Does AI actually prevent payment fraud?
The report shows AI users identify fraud attempts at more than twice the rate of non-users, 63 percent against 30 percent. It does not report loss rates by AI use. The evidence supports improved detection rather than demonstrated reduction in losses.
Which payment fraud controls matter most to insurers?
Charpentier points to four questions: how vendor banking changes are verified, whether sensitive payments require appropriate approvals, whether unusual transactions are flagged before payment, and whether a clear audit trail exists. He cautions that the volume of automation matters less than what it enforces.
Related Cyber Insurance Posts
- German Cyber Attack Losses Now Come With A Range.
- Does Cyber Insurance Cover Scams? It Depends(Opens in a new browser tab)
- Should Ransomware Payments Be Banned?(Opens in a new browser tab)
- Cowbell 2026 Claims Report: Ransom Payments Fall 44% As Cyber Insurance Claims Rise 40%(Opens in a new browser tab)
- Black Kite 2026: Financial Services Faces A Two-Front Cyber Storm(Opens in a new browser tab)