AI-Powered Fraud: What AP Teams Are Up Against

July 22, 2026

Share

64
22 min
Fraud expert Paul Zikmund joins host Grace Berube to walk through four AI-driven fraud schemes that are reshaping the threat landscape for AP teams.
Paul Zikumund
Paul Zikumund, Chief Resiliency Officer, Berkadia
Grace Berube
Grace Berube, Senior Content Manager, IOFM

In this episode, fraud expert Paul Zikmund joins host Grace Berube to walk through four AI-driven fraud schemes that are reshaping the threat landscape for AP teams. From deepfake voice calls impersonating executives to business email compromise powered by large language models, phantom vendors with entirely fabricated online identities, and AI bots quietly submitting small invoices at scale, Paul breaks down how each scheme works, what real-world losses have looked like, and what AP professionals can do — both with traditional controls and new AI-detection tools — to stay ahead of increasingly sophisticated attacks.

WHAT YOU’LL LEARN IN THIS EPISODE

  • How deepfake voice cloning works — and how fraudsters use it to impersonate executives and pressure AP teams into authorizing wire transfers.
  • Why AI-generated business email compromise is harder to catch than ever, with LLMs crafting contextually accurate emails that reference real projects, vendors, and relationships to request fraudulent bank changes.
  • What phantom vendor fraud looks like when bad actors use generative AI to build a complete fake company — website, LinkedIn profiles, deep-fake employees, and all — and win legitimate contracts.
  • How automated invoice manipulation works as a “death by a thousand cuts” scheme, with AI bots submitting hundreds of small, below-threshold invoices across multiple locations over months.
  • What AP teams can do right now — from deepfake detection tactics on video calls, to code words for banking changes, to building a closer working relationship with cybersecurity and investing in continuous fraud training.

Paul Zikumund
Chief Resiliency Officer, Berkadia

Paul E. Zikmund serves as SVP Chief Risk, Compliance & Information Security Officer at Berkadia. He is responsible for managing the company’s enterprise risk management program, ethics & compliance, internal audit function, information security, data privacy, and corporate investigations. Prior to his role at Berkadia, Paul served as a Director of Baker Tilly’s Global Fraud and Forensic Investigations, Compliance and Security Services practice where he was responsible for helping clients develop, assess and administer ethics and compliance programs, conduct global and cross-border fraud and misconduct investigations, including, bribery, corruption and compliance matters and manage risks related to ethics and compliance failures. Prior to that, Paul served as Deputy CCO & Vice President Global Security, Bunge in White Plains, NY where he was responsible for development and implementation of Bunge’s fraud, ethics, compliance and security risk management programs and controls designed to protect company assets, mitigate fraud and misconduct, ensure compliance with federal and state laws, protect company assets, and promote adherence to Bunge’s core values.

Paul managed and conducted investigations of compliance matters, fraud and ethics violations. Paul assisted with the development and implementation of tools and techniques to mitigate enterprise security, fraud & compliance risk, manages the company’s third party risk management program, and administers security, compliance training and awareness programs. Prior to joining Bunge, Paul worked as the Senior Director Forensic Audit at Tyco International in Princeton, NJ and the Director Litigation Support Services at Amper, Politziner, & Mattia, LLP, in Philadelphia, PA where he was responsible for developing, implementing, and administering fraud risk management services to Tyco and to clients. He possesses nearly 28 years of experience in this field and has effectively managed global compliance and forensic audit teams at various Fortune 500 companies.


Grace Berube
Senior Content Manager, IOFM

Grace is the Senior Content Manager at the Institute of Finance & Management (IOFM), where she has led content strategy and development since 2022. In this role, she oversees all aspects of IOFM’s digital and event-based content, ensuring it remains timely, relevant, and actionable for all financial operations professionals.

Grace manages IOFM’s robust library of site content, leads the organization’s editorial and member webinar programming, and hosts IOFM’s podcast series. She also oversees a team of subject matter experts who contribute thought leadership and educational articles. In additional, Grace curates and manages all speaker content for IOFM’s in-person and virtual events, ensuring consistency and quality across every touchpoint. With nearly three years in the role, Grace brings a deep understanding of the financial operations landscape and a passion for delivering content that empowers professionals to excel in their roles.

Subscribe Today

Listen below and subscribe on Apple Podcasts today.

b65d517b-5d22-47a4-b892-eac317be49e6.png.small.300x300.png


Transcription

Grace Berube: Welcome to the IOFM podcast. This is a podcast for accounts payable and accounts receivable professionals who want to stay in the know with current AP and AR trends and ideas. We’ll be interviewing professionals in this space on a wide variety of subjects, including automation, artificial intelligence, career growth, compliance, leadership, and much more.

Hi, Paul. Welcome back to the IOFM podcast. We're happy to have you back today. 

Paul Zikmund: Hi, Grace. Great to be with you here.

Grace Berube: Yeah, absolutely. And as we're recording this, we're pretty much two weeks away from IOFM Spring. I think when you guys are listening to this, we're into summertime, but we're getting excited. This episode with Paul today is going to be about a similar topic to what he's talking about at IOFM Spring. So what are we talking about today, Paul?

00:00:56

Paul Zikmund: Well, today we're going to talk a little bit about artificial intelligence and some of the risk that it presents to our AP professionals, and do a little deep dive into some of the different types of sort of what I would call the new faces of fraud that we're seeing around AI and deep fake schemes that are impacting accounts payable.

Grace Berube: Yeah, I think that it's just gotten so much more sophisticated, even in the past six months to one year. AI is just so much on the rise and that really just correlates to fraud and these different schemes. You gave me a few different areas that we're going to cover today, so I think, to start out, talk to me a little bit about that deep fake voice cloning and what's going on with that.

00:01:40

Paul Zikmund: Yeah, when you think about deep fake voice cloning, this is an area that is developing rapidly. So, if we look at some of the statistics around AI-induced fraud, in 2024, we had about $16 billion that was fraudulently taken from companies. In 2025, that moved up to about $18 billion. We're seeing projection in the area of $40 billion due to AI and deep fake fraud by 2027.

When you look at that deep fake voice cloning, if you will, really what's happening is that the bad actors are using some type of—whether it's retrieval-based voice conversion techniques or text-to-speech models, and they're scraping our audio from different sources. So it could be a YouTube keynote. It could be other type of social media posts. It could be an earnings call. 

00:02:47

When they scrape those audios, they create what's known in the industry as a voice skin, and then they convert that with real-time conversion software to match our breath patterns, our accents, the pace in which we speak, and then they eventually use that to what we call fake. Deep meaning deep learning, and faking us out through social engineering, and look to move money out of a company. 

So if you think about a recent example, you have an AP manager that receives a call from someone alleging to be the CEO, and this person actually knew the CEO was at a conference in Europe. This individual basically created some urgency. "We need to move some funds immediately. We're engaged in a large deal." And the individual believed this person and eventually wired over $15 million to a fraudulent account. 

Grace Berube: Wow, that's so scary. It's so scary that that can happen now. When do you think that really ramped up? When did you see this really start to be rising?

00:04:06

Paul Zikmund: Well, I gave some numbers there around 2024 and '25. In '24, I think we had about $300 million of the AI-induced fraud that was attributed to deep fake. In 2025, just over a billion. So what we have seen is it's rapidly advancing in 2025. And I think the reason for this rapid increase, Grace, is the technology. It keeps getting better and better, and it becomes harder and harder for us to detect those red flags, and that's why it's so important for us to understand what those red flags are so we can do a better job, if you will, of protecting our assets.

Grace Berube: Yeah, so really scary with that rapid increase to think about what 2026 could be, if we're not looking out for things like this.

00:04:53

Paul Zikmund: No doubt. Absolutely. 2026 is going to be a year where it's no longer going to be a nice-to-have deep fake AI detection checklist. It's going to be a must-have.

Grace Berube: Right. Absolutely. We also talk a lot about business email compromise on webinars, at our events. Talk to me about what's happening in that space as well.

Paul Zikmund: Well, business email compromise has been around for a while now. It's one of those fraudulent schemes that we are seeing all the time. But just like deep fakes, they're getting better and better, and harder and harder to detect.

00:05:33

Here, we're seeing that attackers are using large language models (those LLMs) and they're really ingesting thousands and thousands of data points, Grace—data points from LinkedIn, from SEC filings, from stolen email threads—that maybe were disclosed in a previous breech. 

What the AI then does it really matches—it creates this exact relationship between your company and a vendor. And then once that relationship is created, it crafts an email that maybe it references a project. Maybe it references a particular office. Maybe it references a particular model or version of a product. And it creates the tone, if you will, of a vendor, a legitimate vendor, and requests payment. 

00:06:25

But generally there's a trust anchor attached to it, explaining that: We have to make this banking account change immediately in order for us to A) continue doing business with you and not cutting your services so that you can stay current. 

Here, great example. A construction company received a bank change request from one of their primary suppliers. The actual request, Grace, even specifically mentioned a delay in a project that was basically from a project management portal.

00:07:03

Now, interestingly enough, the project that it referenced was recently in the news, so the bad actor scraped that bit of news, included it in the email, grammatically perfect, referenced the project, and the accounts payable clerk wired an $800,000 payment, which ultimately went to a fraudulent account. 

Grace Berube: That's so terrifying because, really, I feel like the classic red flags that we've been told to look for are just not applying anymore. They can be, but it's just so much more sophisticated now.

Paul Zikmund: That's exactly correct. There's a lot of those red flags that are still present, but we have to do a better job now. We have to look a little deeper. We have to understand what we're exactly looking for.

00:07:46

And now, Grace, what we're going to be speaking about at the spring conference is we have to actually use AI a little bit to help us identify them in real time and really strengthen our defenses, if you will. We can't rely on humans as much as we used to. 

Grace Berube: Yeah, it's a great tool. So is that for something like this, where it's really personalized, grammatically correct? We look for that sense of urgency, but even sometimes that's not there. Is that the first step you would do, would be go to an AI source to kind of help you sort through something like this?

00:08:21

Paul Zikmund: Yes, absolutely. In addition to improving our training for AP professionals, it's also the adoption of some real-time AI tools to help us. So maybe the invoice looked incredibly duplicate of the previous invoice, but the pixels are off. The logo's a bit shaded. There's something different. Maybe a slight change in the font or language. Some slight changes that maybe the human eye wouldn't pick up, but an AI agent would.

Grace Berube: Right. It's scary stuff, but definitely ways that we can still combat this. One that I hadn't heard of until you brought it up: phantom vendors. What is that all about?

00:09:02

Paul Zikmund: In the fraud world, they call it the full-stack fraud. So, here, this is soup to nuts. These are bad actors using gen AI to create a complete fake company. They have a website, fake LinkedIn profiles. They use deep fakes for face-to-face verification calls. They use deep fakes for AI-generated faces on their website. I've seen some of these websites with deep fake employees. I've got to be honest with you: first blush, it's really hard to tell the difference. The deep fake technology is becoming so good.

00:09:42

Here, you have an example of a company that was going through a procurement process. The VP of sales and someone from procurement participated in a 15-minute Zoom interview with a company that participated in the RFP. A woman shows up in the interview, realistic setting, high-quality deep fake being used here. Ultimately, this company wins the contract and they are paid $1.2 million for work that was never done, and work that was paid to a company that never actually existed. 

00:10:20

The actual headquarters, they later found out, was a vacant lot. It wasn't even a real company. This is what I want to make sure we are highlighting to our listeners. I'll talk about this in Florida in May. Yes, we do need to apply advanced capabilities to identify some of these red flags, but we cannot forget, Grace, the traditional methods that we've been using for decades to identify red flags for fraud. So you have a vacant lot as a headquarters here. We still can do those basic things that we sometimes forget. 

00:10:57

Grace Berube: Absolutely. Any other checkpoints or things—not giving away too much from Florida—that people could do that are listening, that maybe won't be able to attend? Checking the vacant lot. But what are some other things that they could be doing? That's just crazy to think about that someone could—you don't even think that that's possible, a whole fake company, fake employees. It's wild.

Paul Zikmund: Yeah, absolutely. So when you think about these deep fakes, there's things that you can look for. Does the individual when they're talking, do the edges around the face flicker when they turn their head? You may have a vendor with really a high polished presence, but whose web domain, LinkedIn profiles, all created within the last 90 days.

00:11:41

Maybe their website, their company was just created within the last 90 days. So, this high polished presence just doesn't align with a company that says "we've been in business for years." 

Grace Berube: Right, exactly.

Paul Zikmund: Tax forms—they might look like they have perfect text, but maybe there's some underlying what we would call digital noise in the metadata. So some digital noise in that. And when you think about identifying those deep fakes, this is an example where we have to be a little bit more vigilant when we are on these Zoom calls. It's almost like, hey, can we ask the individuals to—and it sounds a little odd, but sometimes, like when we're doing interviews with people that are on Zoom calls or Teams calls, "Hey, can you hold up a piece of paper and turn you head?"

Grace Berube: Yeah.

00:12:33

Paul Zikmund: And the deep fake technology is not completely mastered yet, where they're able to get away with that. There's some clear indications. And now, as we are creating more capabilities to perpetrate fraud through deep fakes and AI, we're also seeing companies that are providing us with better AI tools to detect these in real time. So, as the bad actors get better, our technology is catching up. There's always going to be a curve. There's always going to be a little bit of a lag, but we are doing better and better. The problem, Grace, is that not all companies are investing in these type of technologies, fraud prevention, fraud detection, training employees. We have to continue to do better.

00:13:19

Grace Berube: Absolutely, yeah, because as they get smart, we also have to.

Paul Zikmund: We have to. We absolutely have to.

Grace Berube: Absolutely. One more here that you've pointed out: automated invoice manipulation. What is that?

Paul Zikmund: Yeah, so here you have basically an AI agent. The bad actors, they continue to get smarter and smarter over the years. If you go back to duplicate invoicing fraud where you're getting the same invoice for services that were already provided and paid for, and now they're being paid for twice, or you're getting an invoice for services that were not performed, historically, a lot of the bad actors were going after the big bucks. So they submit a $3,000, a $9,000, and then if you have that $10,000 threshold, ultimately, once they became comfortable that this was a legitimate company, they'd go for that $30,000, that $50,000, that $100,000 invoice.

00:14:17

There, you'd have that one-and-done, right? They'd embezzle and ensure that you paid money that you had never paid for—invoices that you had never paid before. Now, these automated invoice manipulations, you have these AI agents who are out there creating 10,000 $4,500 invoices or 1,000 $2,490 invoices. It's almost like death by 1,000 cuts. 

So we've even seen examples where the invoices were for $450. Who's going to question it? But if you're paying those three, four, thirty times a month, and those agents are sending those invoices to many, many companies, imagine over time. Here you have a retail chain that had paid over $3 million in fraudulent invoices in about an 18-month period. And all this was, was an AI bot submitting invoices—they were about $2,850—to 150 different regional branches. 

00:15:20

Now, interestingly enough, the bots were actually using the company's own branding and color schemes, and they were making them look like internal cross charges. So when you look at some of the things that maybe would be indicative of a red flag, a sudden increase in invoices that fall just below that 5-10% manual approval limit. Or those generic service descriptions. In other words, broad terms. They don't really tie back to a physical deliverable or a verified PO. It's more generic in nature. Multiple invoices, different vendors, identical bank routing numbers. 

00:16:03

And so as we create our abilities to identify these red flags, it's going to be very, very important to not only automate it, but to ensure that we have some level of identification and escalation procedures in place within our companies to better prepare us. We need to strengthen our overall security. 

Interestingly enough, Grace, we're seeing today that there has to be a marriage, if you will, a partnership, a collaboration between finance, accounts payable, and technology. Our AP professionals have to be sitting down with our cyber professionals, having that close relationships, explaining what these schemes look like, and developing ways that we can do a better job to prevent them. 

00:16:57

Grace Berube: Yeah, absolutely. I think that that is so important, the partnership with technology. Everything is just, as we said at the beginning, changing so rapidly. Being able to have that extra tool, those layers of tools, is going to be so important.

Paul Zikmund: Absolutely.

Grace Berube: Any closing points here? If someone really had to do something as they start Monday morning, what are some conversations they could have or some things that they could do to really enhance and start combatting these things, if you had a couple of key points?

00:17:29

Paul Zikmund: Absolutely. I think, one, learn more about AI. Learn how it works. Learn the different types of AI, whether it's narrow AI, gen AI, super—whatever it might be. Learn how AI is being used in our environment today.

Look, it's being used for good and bad, right? So when we think about speed, accuracy, reliability, efficiencies, increase in automation—areas where AI is making great improvements, it's freeing us up, if you will, to do more critical thinking, reducing manual processes, and it's making us better in many areas. Learn AI, number one. 

We're going to need to marry the financial controls and the IT controls. We're going to have to determine that a dual financial control is great, but it's not great enough. Like we have to identify those technology controls that are going to help us improve our overall control environment. 

00:18:32

We're going to have to do better focusing on the cyber side of things. So we bring our information security team to the meetings and enable them to help us. 

I think also on the training side, we have got to do more in the area of training and awareness, and it has to be a continuous process. It can't be a one and done. We provide anti-fraud and awareness training once a year—it's not enough. We have to provide more detailed training, bespoke training. There's a great opportunity for us to improve our knowledge in this area. The more we know, the better equipped we are. 

00:19:11

I think our culture, from a cultural perspective, it wasn't just a week ago we elevate awareness in my own company for somebody who identified a business email compromise scheme. We want to celebrate that success. Hey, that's a great catch. We want to let the rest of the company know. 

Reverse audits. Look at your top ten vendors and put processes in place to make sure that you're verifying banking details, that you have—some companies now, Grace, are actually putting in code words just for any type of banking change. Any change to banking account information, I have a preapproved phone number that I'm going to use, and you have a code—whether it's a phrase, a word, whatever that might be. 

00:19:59

And then really looking at any type of behavioral technology biometrics. Monitor how users interact with your systems, whether it's the day of the week these invoices are normally received, or what deviations should we be elevating immediately? Is it time of day? Is it frequency of invoices? There are even tools that we can use now that would identify a change in the way we talk to each other. 

So if I'm receiving an invoice from you once a month, twice a month, and it's, "Hey, Grace. Hope things are well. Please see the attached." Hopefully, we're moving away from that. But, believe it or not, a lot of companies still receive emails with invoices attached. You might see a change in the way—so I address you not only by Grace, by I address you by your last name as well. The way I talk to you is different than when I normally talk to you. 

00:20:55

There's so many little things that we can start putting in place, if you will, to really help us identify these changes in real time. 

Grace Berube: Yeah, absolutely. That's such fantastic advice. I'm so excited to be able to sit in on your session in just a couple of weeks and to hear more about this, because this is such a rapidly changing subject. It's just always great to talk to you, Paul, so thank you so much for being back on today.

Paul Zikmund: Absolutely, Grace, and likewise. It's always wonderful talking to you as well, and I'm really looking forward to seeing you and everyone else in Florida.

Grace Berube: Awesome. Well, thank you so much. We'll talk soon. We'll have you back on soon.

Paul Zikmund: Great. Have a great day.

Grace Berube: You, too.

00:21:34

Thank you so much for listening to the IOFM podcast. Remember to head on over to the Member Forum to discuss today's episode and provide ideas for our next one. And to stay up-to-date on IOFM's current events, both in-person and virtually, head on over to IOFM.com

Continuing Education Credits available:

Receive 1 CEU per hour of listening time towards IOFM programs:

AP CertificationPP-OC_seal_APP_outline.FNLReceive 1 CEU per hour of listening time towards maintaining any AP and P2P related program through IOFM! These programs are designed to establish standards for the profession and recognize accounts payable and procure-to-pay professionals who, by possessing related work experience and passing a comprehensive exam, have met stringent requirements for mastering the financial operations body of knowledge.

Continuing Education Credits available:

Receive 1 CEU per hour of listening time towards IOFM programs:

AP CertificationPP-OC_seal_APP_outline.FNLReceive 1 CEU per hour of listening time towards maintaining any AP and P2P related program through IOFM! These programs are designed to establish standards for the profession and recognize accounts payable and procure-to-pay professionals who, by possessing related work experience and passing a comprehensive exam, have met stringent requirements for mastering the financial operations body of knowledge.

Subscribe to our Monthly Insider

You may unsubscribe from our mailing list at any time. Diversified Communications | 121 Free Street, Portland, ME 04101 | +1 207-842-5500