In short (TL;DR)
Deepfake fraud has reached ordinary finance teams. FBI data published in April 2026 counts $893 million in AI-related fraud losses for 2025, and in the best-known case a finance employee wired $25.6 million after a video call in which every participant was a deepfake. The bad news: people identify high-quality fake video with only 24.5% accuracy on average. The good news: your defense doesn't depend on sharp eyes — it depends on five process rules you can put in place this week.
How does deepfake invoice fraud work?
Classic invoice fraud relies on a forged PDF and a rushed victim. AI added three new weapons:
- Voice cloning: about three seconds of public audio (an interview, a webinar, a social video) is enough to call your accountant in the boss's voice and order an "urgent payment".
- Deepfake video calls: fraudsters invite an employee to a meeting where the "CFO" and "colleagues" are all AI-generated. That's exactly how one company lost $25.6 million across 15 transfers.
- Perfect fake invoices: AI drafts an invoice matching your supplier's layout, numbering logic and tone: the only change is the bank account.
How big is the risk, really?
The hard numbers are mostly American, but the pattern is global. According to FBI Internet Crime Complaint Center data, 22,364 complaints referencing AI were filed during 2025, with adjusted losses of $893 million. Finance teams are the first target because speed, sums and routine intersect there. Voice-cloning attacks on executives follow the same playbook everywhere: the language of the email changes, the pattern doesn't.
Why doesn't "I'd recognize my boss's voice" work?
Because you wouldn't. In controlled tests, people identify high-quality deepfake video with an average accuracy of 24.5% — worse than a coin flip. More than half of business leaders admit their employees have had no deepfake training at all. Vigilance is necessary but insufficient as a strategy: the fraudster needs one lucky afternoon, you need to be right every single day.
The five process rules that stop the fraud
- The call-back rule: every payment or account-change request that arrives by call, video or email gets verified in a second channel on a previously known number. Not the number in the fraudster's signature.
- An IBAN change is always a red flag: never take a supplier's new bank account from an invoice or an email: confirm it through the supplier's established contact.
- Dual approval: payments above an agreed threshold (say €1,000) by two approvers. Urgency is not a reason to skip this — urgency is the fraud's fuel.
- A code question with management: if the "CEO" requests an exceptional payment, ask an agreed question whose answer isn't on the public internet.
- Train with real examples: one 30-minute session walking through actual cases raises alertness more than any policy memo.
How do e-invoicing rails and AI strengthen the defense?
A fake invoice lives in an email attachment. When your invoices travel through an authenticated e-invoicing channel, such as your national operator network or the Peppol network, the sender's identity is verified by the network, and the “same invoice, new IBAN” trick loses its surface. It doesn't replace every PDF overnight, but each supplier you move to e-invoicing is one email-fraud channel closed.
The second layer is a machine that never gets bored by routine: AI compares every incoming invoice's details, amounts and rhythm against history and flags the outliers before payment day. We describe how that works AI-based invoice fraud detection.
Summary
Deepfake fraud is a mainstream business risk in 2026: the losses run to hundreds of millions and the human eye alone doesn't catch a quality fake. The defense is process: call-backs on known numbers, separate verification of IBAN changes, dual approval, a code question and training, plus a technical layer of authenticated e-invoice channels and AI anomaly checks. None of those steps costs more than one successful fraud.
Try Bilnex's free invoice processing, where AI checks every incoming invoice's details.
FAQ
How common is deepfake fraud in 2026?
The FBI's Internet Crime Complaint Center logged 22,364 AI-related fraud complaints for 2025 with adjusted losses of $893 million, in data published in April 2026. The best-known case is a deepfake video call that led a finance employee to transfer $25.6 million.
Can people reliably spot deepfakes?
Well. In controlled tests, people identify high-quality deepfake video with an average accuracy of just 24.5%. That's why effective defense rests on process — like call-backs on previously known numbers — rather than on recognition.
What is the single most effective control?
The call-back rule: verify every payment or bank-detail change request in a second channel using a previously known contact. It defeats voice clones, deepfake video and forged emails alike, because the fraudster doesn't control your second channel.
How does e-invoicing reduce fraud risk?
In an authenticated e-invoicing channel such as the Peppol network, the sender's identity is verified by the network itself, so the forged-PDF-with-a-swapped-IBAN trick doesn't work. Every supplier moved to e-invoicing closes one email-fraud channel.