Yooz 2026 Fraud Readiness Survey Report
Payment Fraud Has Become Routine, and Manual Processes are Holding Finance Teams Back
70% of U.S. finance professionals say their organization experienced a payment fraud attempt in the past two years or couldn’t rule one out, and 28% of known attacks succeeded.
Payment fraud has become a routine operating risk for finance and accounts payable teams. Fraudsters no longer need inside knowledge or elaborate schemes to hit a company’s payables. They need a busy AP inbox, a rushed approval, or a manual process with just one gap in it.
Generative AI is making the threat harder to manage by producing more convincing phishing emails and fake invoices at scale. As the volume and sophistication of attacks increase, many companies are still working to bring their defenses up to speed.
Purpose of this study
To understand how prepared finance teams are for today’s payment fraud threats, Yooz partnered with the third-party survey platform Pollfish in July 2026 to survey 750 U.S. professionals in finance, accounting or accounts payable roles about their organizations’ experiences with fraud and the controls used to prevent it.
The Yooz 2026 Payment Fraud Readiness Report examines where payment fraud is entering the finance process, how quickly organizations identify and respond to it and whether current controls are keeping pace as fraud becomes more sophisticated. It also explores how manual processes, automation and AI shape an organization’s ability to detect threats before money leaves the business.
Key Findings of the Yooz 2026 Payment Fraud Readiness Report
- 70% of finance professionals say their organization experienced a payment fraud attempt in the past two years or could not rule one out.
- 28% of organizations that experienced a known fraud attempt lost money.
- 39% of organizations that experienced a fraud incident put the financial impact at $50,000 or more.
- Finance teams with mostly or almost entirely manual processes lost money in 42% of known fraud attempts, versus 30% for highly automated teams and 22% for teams with mixed operations.
- 49% of finance professionals have let, or almost let, an unusual payment request move forward without verification because it came from a trusted source.
- 48% name an AI-powered threat as their top emerging fraud concern.
- Only 21% believe finance teams are extremely prepared for AI-enabled fraud.
- Finance teams actively using AI identified fraud attempts at more than twice the rate of teams not using it, 63% compared with 30%.
- Only 20% are extremely confident their current process would stop a sophisticated fraud attempt before money leaves the business.
Most Finance Teams Have Faced Accounts Payable Fraud
70% of finance teams faced a fraud attempt in the past two years or couldn’t rule one out.
54% of finance professionals report a fraud attempt against their organization in the past two years. Another 16% say an attempt possibly occurred but they couldn’t be certain. Only 30% are confident they saw no attempt at all.
Among organizations that experienced an attempt, 72% caught it before any money left the business and 28% lost money.
Business Email Compromise Is the Most Common Type of Payment Fraud
50% of organizations that experienced fraud were hit by business email compromise or phishing targeting the finance team.
Among organizations that experienced a fraud incident, business email compromise or phishing targeting finance teams was the most common attack type (50%), followed by duplicate payments (40%), vendor impersonation or unauthorized changes to vendor banking details (37%), internal theft or financial manipulation (34%), and fake or altered invoices (33%).
Asked where fraud is most likely to enter their finance process, respondents point to email-based payment requests or approvals (44%), rushed approvals or exception handling (38%), vendor setup or banking detail changes (33%), manual invoice review or data entry (33%), and gaps in approval workflows (30%). 15% say they don’t know where they’re vulnerable.
Payment Fraud Often Carries a Five-Figure Cost
39% of organizations that experienced a fraud incident put the financial impact at $50,000 or more.
Among organizations that experienced a fraud incident in the past two years, 57% said their most significant incident cost at least $25,000. That includes 39% who reported losses of $50,000 or more and 15% who lost at least $100,000. Only 11% said the incident caused no financial loss.
Once fraud is detected, only 14% of organizations fully resolve the incident in less than a day, while 35% need a week or more, including 15% that take a month or longer.
Manual Accounts Payable Processes Lose More Money to Fraud
Finance teams with mostly or almost entirely manual processes lost money in 42% of known fraud attempts, the highest loss rate of any automation level.
Only 9% of finance teams describe their operations as highly automated. Nearly half, 49%, use a mix of automated and manual processes, while 19% remain mostly or almost entirely manual.
Finance teams with mostly manual operations that faced a known fraud attempt lost money 42% of the time. Teams with accounts payable automation in place fared far better: mixed operations lost money in 22% of attempts and highly automated operations in 30%.
Highly or mostly automated teams also feel their defenses are improving. 50% say they’re more protected against fraud than a year ago, compared with 38% of mostly manual teams.
Human Pressure Drives Invoice Fraud Risk
49% of finance professionals have let, or almost let, an unusual payment request through without verification because it came from a trusted source.
28% of finance professionals have let an unusual payment request move forward without additional verification because it came from a trusted person or familiar email address, and another 21% say they almost did.
42% have felt pushed to approve a payment faster than they were comfortable with at least occasionally, and 12% feel it frequently. 54% say workload pressures at least sometimes make it harder to follow every fraud-prevention step, and 59% spend 3 or more hours a week on manual exception handling.
Respondents’ top priorities for reducing fraud risk are strengthening defenses against phishing and social engineering (41%) and reducing human error and rushed decision-making (41%).

AI Fraud Is the Top Emerging Threat, and Readiness Lags Behind
48% name an AI-powered threat as their top emerging fraud concern; only 21% say finance teams are extremely prepared for AI-enabled fraud.
Asked which emerging fraud threat concerns them most, finance professionals put AI-generated phishing emails first (22%), ahead of traditional phishing (21%), insider fraud (15%), fake invoices generated at scale (14%), deepfake voice or video impersonation (11%), and vendor account takeover (10%). Combined, 48% picked an AI-powered threat (AI-generated phishing, fake invoices at scale, or deepfakes).
21% believe finance teams are extremely prepared for AI-enabled fraud threats, 41% say somewhat prepared, 24% are neutral, and 15% say unprepared.
AI Is Helping Helping Finance Teams Surface More Fraud Attempts
Finance teams using AI identified fraud attempts at more than twice the rate of teams without it: 63% vs. 30%.
64% of organizations already use AI actively in finance operations, including flagging suspicious transactions (30%), invoice review and matching (31%), and reporting and forecasting (32%).
Teams actively using AI reported identifying fraud attempts at more than twice the rate of non-users, 63% compared with 30%. The difference suggests AI-enabled monitoring may help organizations recognize suspicious activity that is harder to identify through manual review alone.
41% of teams using AI say automation has dramatically or significantly reduced the number of fraud-vulnerable touchpoints in their finance process over the past two years, versus 17% of non-users. And 46% of AI users say they’re more protected against fraud than a year ago, compared with 32% of teams not using AI.
Finance Teams Point to Training and Real-Time Detection as Priorities
Only 20% of finance professionals are extremely confident their current process would stop a sophisticated fraud attempt before money leaves the business.
Only 20% of finance professionals are extremely confident that their current process would stop a sophisticated, well-disguised fraud attempt before any money leaves the business. 40% acknowledge that a sophisticated attempt could slip through their current controls.
Respondents are specific about what would raise that confidence: employee fraud awareness training (37%), real-time anomaly detection built into their finance software (35%), stricter approval workflows with full audit trails (33%), and better visibility into payment status across the team (33%). Only 11% say nothing would increase their confidence because they believe their processes are already fraud-resistant.
Manufacturing Finance Teams Often Can’t Tell Whether They’ve Been Hit
31% of manufacturing finance professionals say a fraud attempt possibly occurred in the past two years but they couldn’t be certain, nearly double the overall rate of 16%.
Manufacturing’s defining fraud problem is visibility. 31% of manufacturing finance professionals say their organization possibly experienced a fraud attempt in the past two years but couldn’t be certain, nearly double the 16% of respondents overall. Another 35% caught a known attempt and 11% lost money.
Manufacturing is also the only industry where manual invoice review and data entry tops the list of perceived fraud entry points (42%, versus 33% overall), ahead of email-based payment requests (29%). 20% of manufacturing respondents name outdated technology as the greatest fraud risk in finance operations, versus 13% overall, and 64% spend three or more hours a week on manual exception handling.
Only 13% of manufacturing finance professionals are extremely confident their current process would stop a sophisticated fraud attempt, and 20% say finance teams are unprepared for AI-enabled fraud.
“For years, companies have treated fraud mainly as a people problem: train employees to spot the fake email and hope an approver catches something suspicious. That approach is becoming less reliable as generative AI makes fraudulent invoices, emails, and even voice requests much harder to distinguish from the real thing.
Finance teams need controls that do not depend on someone noticing every warning sign. Verification should be built into vendor changes and payment workflows, with automation checking every transaction, and employees reviewing the exceptions that require judgment. Fraud attempts will continue to become more sophisticated, but stronger processes can prevent more fraudulent payments from going through.”
— Laurent Charpentier, CEO, Yooz
Survey Methodology
The Yooz 2026 Payment Fraud Readiness Survey was conducted in July 2026 via Pollfish among 750 U.S. professionals working in finance, accounting, or accounts payable roles, ages 18 to 64. The survey assessed fraud attempt frequency and financial impact, fraud entry points, detection and resolution speed, the role of automation and AI in prevention, and preparedness for AI-enabled fraud threats. Percentages are rounded to the nearest whole number.
FAQ
How common is payment fraud for finance teams?
Very common. According to the Yooz 2026 Payment Fraud Readiness Report, 54% of U.S. finance professionals say their organization experienced a fraud attempt in the past two years, and another 16% say an attempt possibly occurred. Only 30% are confident they saw no attempt.
How much does payment fraud cost businesses?
Among organizations that experienced a fraud incident, 57% put the cost of their most significant incident at $25,000 or more, 39% at $50,000 or more and 15% at $100,000 or more.
What is the most common type of accounts payable fraud?
Business email compromise and phishing targeting finance teams was the most common type, reported by 50% of organizations that experienced fraud. Duplicate payments followed at 40%, vendor impersonation or banking-detail changes at 37%, internal theft at 34% and fake or altered invoices at 33%.
What is invoice fraud?
Invoice fraud is the submission of fake, altered or duplicate invoices to trick a business into paying money it does not owe. It is a growing concern as AI makes fake invoices easier to produce. In the survey, 14% of finance professionals named fake invoices generated at scale as their top emerging fraud threat.
How does AP automation reduce invoice fraud?
Automation reduces the manual touchpoints where fraud can enter, including invoice review, email-based approvals and rushed exception handling. It can also apply checks such as invoice matching, vendor verification and anomaly detection to every transaction. Finance teams with mostly or almost entirely manual processes lost money in 42% of known fraud attempts, compared with 22% for teams with mixed operations and 30% for highly automated teams.
How can companies prevent payment fraud?
Survey respondents’ top priorities are strengthening defenses against phishing and social engineering and reducing human error and rushed decision-making, both at 41%. Other priorities include improving visibility into approvals and payments and preparing for AI-driven fraud threats, both at 33%. The measures that would most increase confidence include employee fraud awareness training, real-time anomaly detection built into finance software and stricter approval workflows with full audit trails.
Are finance teams prepared for AI-enabled fraud?
Mostly not. Only 21% of finance professionals believe finance teams are extremely prepared for threats such as realistic phishing emails, fake invoices and impersonation attempts. Meanwhile, 48% name an AI-powered threat as their top emerging fraud concern.
What should finance teams take from the report?
Payment fraud concentrates in the manual steps of the AP process: manual invoice review, email-based approvals, vendor banking changes, and rushed exceptions. Closing those gaps means building verification into the workflow itself, with automated invoice matching, vendor verification on every banking change, and anomaly detection running on every transaction, so human judgment is reserved for the exceptions that need it. Teams that work this way lost money far less often when fraud reached them.








