News & Information

Articles

Protecting Businesses from Payment Fraud

Something Can Be Done

September 03, 20267 min read

Something Can Be Done: Protecting Businesses From Payment Fraud by Shannon M. Watt

In the face of a growing problem, it is easy to believe that nothing can be done.

Payment fraud has become increasingly sophisticated. Criminals now have access to tools that allow them to impersonate executives, imitate trusted vendors, compromise legitimate email accounts, and create convincing copies of familiar websites.

The size and complexity of the threat can leave business owners and employees feeling powerless. However, history—and the continued efforts of financial institutions, regulators, law enforcement agencies, and vigilant business leaders—tells a different story.

Something can be done.

Progress begins when people recognize a threat, share information, strengthen their procedures, and take practical steps to protect one another.

Fraud

A Lesson in Connecting the Dots

The attacks of September 11, 2001, changed the United States forever. In addition to the unimaginable loss of life, the attacks exposed weaknesses in how critical information was collected, communicated, and understood.

One of the most enduring lessons was the importance of connecting the dots before a threat becomes a crisis.

In the weeks following the attacks, Congress passed the USA PATRIOT Act of 2001. Although much of the public conversation surrounding the legislation focused on national security and law enforcement, the act also strengthened safeguards throughout the American financial system.

Title III expanded measures intended to prevent, detect, and prosecute money laundering and terrorist financing. It also promoted greater cooperation among financial institutions, regulators, and law enforcement.

Several provisions had a lasting impact:

  • Section 314 encouraged information sharing to help identify suspicious financial activity.

  • Section 326 established minimum standards for verifying the identities of customers opening financial accounts.

  • Section 352 required financial institutions to establish anti-money-laundering programs that included internal controls, employee training, designated oversight, and independent testing.

  • Section 362 called for a secure communication network through which financial institutions could submit reports and receive alerts.

These measures were never a promise that every threat could be eliminated. They were proof that risks could be confronted through better information, stronger controls, and coordinated action.

That distinction matters.

We may not be able to prevent every criminal from attempting fraud, but we can make it far more difficult for them to succeed.

Fraud

The Threat Is Still Growing

Payment fraud occurs when criminals make unauthorized payments from a business account or manipulate an employee into completing a transaction for them.

The most recent numbers demonstrate how widespread the problem has become.

According to the Association for Financial Professionals’ 2026 Payments Fraud and Control Survey, 76% of U.S. organizations experienced attempted or actual payment fraud in 2025.

Business email compromise affected 74% of organizations, while checks remained the payment method most frequently targeted by fraud. Fifty-eight percent of organizations reported check-related fraud activity.

The same survey found that only 17% of organizations currently use artificial intelligence to help combat payment fraud. Yet organizations using AI reported improvements in fraud reporting, deepfake detection, and real-time identification.

The FBI’s 2025 Internet Crime Report adds even more perspective. The agency received more than one million complaints of suspected internet crime during the year, with reported losses exceeding $20 billion.

These figures do not tell us that the fight is hopeless. They tell us that awareness and prevention must keep evolving alongside the threat.

The Most Common Threats to Businesses

Criminals do not always defeat a company’s technology. Frequently, they exploit human trust.

Their requests are designed to look ordinary. An employee may receive an email that appears to come from the company’s owner. A familiar vendor may seem to provide updated banking instructions. A link may lead to a website that looks nearly identical to a trusted login page.

The criminal does not always break through the front door. Sometimes, they convince someone inside to open it.

Phishing

Business Email Compromise

Business email compromise occurs when a criminal sends a message that appears to come from a trusted colleague, executive, customer, vendor, or business partner.

In some cases, the attacker creates an email address that closely resembles a legitimate one. In others, a real email account has been compromised.

The message may include genuine names, contact information, company branding, previous conversations, or other details that make the request appear authentic. Once trust is established, the criminal may request sensitive information, initiate an unusual transaction, or redirect a payment to a fraudulent account.

These requests often create a sense of urgency because urgency discourages verification.

Phishing

Phishing attacks use fraudulent emails, text messages, advertisements, social media posts, and websites to obtain sensitive information.

A message may direct someone to a website that looks almost identical to a legitimate login page. Once the victim enters a username, password, credit card number, or other confidential information, the criminal can use it to access an account.

Technology makes these attacks easier to create, but human awareness can still stop them.

An employee who pauses before clicking a link or entering information may prevent an incident that no automated security system would have caught in time.

Vendor Impersonation

Vendor impersonation takes advantage of the trust that already exists within a business relationship.

A criminal may pose as a supplier or service provider and submit a fraudulent invoice. The attacker may also request that banking information be changed before the next payment is processed.

The email address may differ from the legitimate vendor’s address by only one letter or character. Because the vendor’s name and services are familiar, an employee may process the request without questioning it.

Trust should always remain part of a strong business relationship, but trust must be supported by a consistent verification process.

Scam

Six Actions That Make a Difference

There is no single tool that can eliminate payment fraud. Effective protection comes from combining awareness, communication, technology, and accountability.

1. Pick Up the Phone

When payment instructions change or a request feels unusual, call the person or company involved.

Use a trusted phone number already in your records. Do not rely on contact information included in the questionable message.

A two-minute phone call can prevent a devastating loss.

2. Train Every Employee

Fraud prevention should not be limited to the accounting department.

Every employee should know how to recognize suspicious messages, misleading links, fake invoices, unusual payment requests, and attempts to collect confidential information.

Criminal tactics continue to change, which means employee training cannot be treated as a one-time exercise.

3. Question Unusual Activity

Familiar names and professional-looking messages do not guarantee that a request is legitimate.

If a transaction is unusual, urgent, secretive, or inconsistent with normal procedures, take the time to investigate it.

A healthy question is not an inconvenience. It is a safeguard.

4. Separate Financial Responsibilities

Whenever possible, one person should not control an entire payment process.

Requiring a second employee to review or approve transactions creates another opportunity to catch errors, inconsistencies, and attempted fraud.

Internal accountability protects both the business and the employees responsible for handling its money.

5. Use the Tools Available Through Your Bank

Business owners should speak with their bank about the fraud-prevention tools available to them.

These tools may include approved payee lists, transaction alerts, payment limits, account controls, and additional approval requirements.

The goal is to identify suspicious activity as early as possible—and ideally before funds leave the account.

6. Require Multifactor Authentication

Passwords can be guessed, stolen, or exposed through phishing attacks.

Multifactor authentication adds another identity-verification step before someone can access an account or complete a transaction. It cannot prevent every attack, but it creates an important additional barrier.

Prevention

Prevention Is Proof That Something Can Be Done

It would be unrealistic to suggest that legislation, technology, financial institutions, or internal controls can eliminate every financial threat.

They cannot.

However, it would be equally inaccurate to say that businesses are powerless.

The financial safeguards strengthened after September 11 demonstrate what can happen when institutions recognize vulnerabilities and take coordinated action. The fraud-prevention practices used today bring that same principle into the daily operations of every business.

Information can be shared.

Employees can be trained.

Transactions can be verified.

Responsibilities can be separated.

Technology can provide additional protection.

Suspicious activity can be questioned before money is lost.

The existence of a threat is not proof that nothing can be done. It is evidence that something must be done.

Businesses cannot control every criminal who attempts to deceive them. They can control how prepared their people are, how carefully payments are reviewed, and how quickly concerns are communicated.

The latest statistics are serious, but they are not a reason to surrender to the problem. They are a reason to become more informed, more disciplined, and more prepared.

That preparation can be the difference between an attempted fraud and a successful one.

The most important first step is believing that our actions matter.

Because they do.

blog author image

Shannon Watt

Shannon M. Watt currently serves as Executive Vice President of Corporate Banking for Frost Bank. He has been with Frost since 2004 serving as a Credit Analyst, Commercial Loan Officer, Community Leader, and Sales Manager. At Frost, he helps lead a team of Business Bankers build long-term relationships with business owners in DFW based on top-quality service, high ethical standards, and trusted financing solutions. Shannon earned a Bachelor’s Degree in Finance at Baylor University and a Master of Business Administration at The University of Texas at Arlington. Shannon is active in his community serving multiple community organizations including the Northeast Leadership Forum, Northeast Tarrant Chamber, Longhorn Council of the Boy Scouts of America, North Area Council of the Fort Worth Chamber, Fort Worth Business Assistance Center, YMCA of Metropolitan Fort Worth, and the Camp Bowie District. Shannon is a graduate of Leadership Northeast and Leadership Fort Worth – LeadingEdge. Shannon has received multiple honors and awards including Bob Hamilton MVP of the Year and Gertrude Tarpley Director of the Year from the Northeast Tarrant Chamber, Henry Meadows Volunteer of the Year from the YMCA of Metropolitan Fort Worth, and Forty Under Forty Honoree from the Fort Worth Business Press.

Back to Blog

Join Us Every 2nd Friday of the Month

11:30am-1pm

Address:
Holiday Inn Express & Suites N Fort Worth Haltom City

5040 NE Loop 820

Haltom City, 76117

5040 NE Loop 820, Haltom City, TX 76117, USA

Learn, Connect, Share

© 2026 The LCS Network- All Rights Reserved, Created by Magik Digital