As our technological innovation accelerates, so does the use case for scammers who leverage it to perpetuate crimes. I’ve seen payment fraud become increasingly sophisticated, making it much harder to detect. It’s no longer as simple as looking for a spoofed email with a misspelling or a typo in a subject line. Fraud tactics continue to evolve in ways that make scams appear legitimate, even to those who are trained to spot them.
As financial fraud methods change, I believe one of the best ways to protect yourself is to build a strong relationship with your banker and work as a team. In my job, I advise clients every day on cash flow strategy and financial decisions, and the thread that runs through nearly every conversation is that businesses with a strong, communicative relationship with their banker are far harder to victimize.
Here, I’m sharing some of the most common fraud scams I see today, along with practical tips for protection and ways businesses can better prevent and respond to fraud attempts.
What I’m seeing in business fraud right now
Digital scams
The most dangerous schemes I’m seeing involve sophisticated social engineering and business email compromise (BEC). These scams can be so elaborate and seemingly legitimate – sometimes spanning days, weeks or months — that you wouldn’t think twice before responding to a scammer with sensitive information.
From a digital perspective, I’ve seen fraudsters become increasingly sophisticated in learning a company’s routines and communication patterns. They can hack or spoof email accounts to make fraudulent requests appear highly realistic and credible. For example, you might receive what appears to be a legitimate reply from a known vendor explaining they’ve experienced a security issue and need future payments sent to a different account. Lately, artificial intelligence (AI) has made tracking and mimicking communication even easier for fraudsters.
BEC scams remain one of the costliest forms of cybercrime with losses exceeding $3 billion in 2025, while overall cybercrime losses in the U.S. last year surpassed $20 billion for the first time, according to the latest IC3 report‡.
Check fraud
While digital fraud receives significant attention, I still frequently remind clients not to overlook check fraud. As many businesses shift their prevention focus to cyber threats, we’ve continued to see check fraud rise, particularly through stolen mail and altered checks. Despite the growth in cybercrime, check fraud remains one of the most common types of fraud‡ impacting businesses today.
Banker insight: How to protect yourself and your business
First, and most importantly, you need to have genuine relationships with your vendors—especially with your bankers. Fraud is about creating belief in scams, but if you have a regular relationship with the people with whom you do business, it’s significantly harder for fraud attempts to look credible.
Your banker should continuously work to understand your business, how you operate, how you pay vendors, and potential risk points, so any inconsistencies can be spotted immediately. There are instances where we contact clients to ask, “Did you intend to send that payment? It appears unusual based on your normal transaction activity.”
I also encourage businesses to regularly review and strengthen their internal processes and fraud protection practices. This includes technology solutions that can help identify fraud attempts, such as Positive Pay, payee validation, and e-payables solutions. These tools can provide additional layers of protection against many of the most common fraud schemes businesses face today.
What are the best ways to avoid business fraud?
Here are the practices I recommend most often to clients to help prevent business fraud.
- Call before you click. If you have an unusual link in your email asking for payment or to update payment instructions, especially one that has a sense of urgency, pause for a moment and pick up the phone to call your vendor using the phone number you have on record, not one from an email.
- Don’t send money to anyone you don’t already know.Remember, emails may look like they’re from your vendor or trusted partner, but if they are asking you to take a new step or do something different, it’s always best to verify the request over the phone or in person.
- Know your vendors and your bankers. Touch base regularly to know when something is changing or needs updating. You should never hear about a change for the first time in an email.
- Don’t provide any confidential information. If anyone, even someone that sounds like they are from a trusted source, is asking for confidential information, you should not provide it. Keep your user credentials and token information secure and never disclose it to anyone who contacts you.
- Just because you don’t use an account often doesn’t mean you don’t need protection. Sometimes people think accounts that aren’t a business’ main cash flow account aren’t at-risk, but that is not always the case. Accounts you rarely touch are often more vulnerable because fraudulent activity can go undetected longer. Give these accounts deliberate attention during your regular reviews.
- Watch for AI-enhanced phishing. Fraudsters are increasingly using generative AI to produce error-free, highly personalized emails that are nearly indistinguishable from legitimate correspondence. Train your team to verify all requests through a secondary channel; do not just reply.
What you can do today to stop business fraud
I know this can feel like a lot—but don’t let that stop you from starting. There are many practices you can start today to protect your business.
- Review your accounts. Look at all your accounts and review your activity, including regular payments and accompanying details. Become familiar with the activity and expectations of each account. Set time each day to review all accounts to check on activity and money movement.
- Use banking features: Make sure all your accounts are protected with appropriate forms of fraud protection, use online account alerts, and consider using an e-payables or integrated payables solution that can further mitigate fraud risk.
- Talk to your banker and/or treasury management officer. Catch up with your relationship team to discuss your accounts and structure. They will help guide your prevention plan based on your specific needs.
- Ask your banker what could be better. Start by asking, “Is there anything else I should be doing?” You may be surprised by what your bankers have caught or may suggest based on your business type and situations they have helped manage with other clients. Review all forms of payment methods, including electronic payables, which provide many benefits including a reduction in fraud exposure.
- Implement tools. Heed advice from your banker and consider implementing tools to help protect yourself and your business.
The bottom line: if you haven’t made changes to your payables plan in a while, or if you haven’t touched base with your banker recently, it’s time. Don’t wait to become a case of “I can’t believe it happened to me” before you take preventative action.
UMB provides sophisticated products to help protect your accounts from fraudulent activity through transaction review and validation, filtering, blocking, exceptions and approval protocols. For more information on how you can leverage treasury services to reduce fraud, visit our website.
When you click links marked with the “‡” symbol, you will leave UMB’s website and go to websites that are not controlled by or affiliated with UMB. We have provided these links for your convenience. However, we do not endorse or guarantee any products or services you may view on other sites. Other websites may not follow the same privacy policies and security procedures that UMB does, so please review their policies and procedures carefully.





