Posted by Antonina McAvoy in Cybersecurity, Consulting, Fraud/Forensics, Risk Advisory, Business Risk, Artificial Intelligence.
Key topics covered in this article:
-
- AI-enabled fraud is making business impersonation far more convincing, which means traditional warning signs like poor grammar or unusual formatting are no longer enough. Organizations need independent verification procedures, dual approval for higher-risk requests, and business controls that do not rely solely on the communication channel being used.
- Third-party vendors are now part of the organization’s cybersecurity perimeter because they often have access to critical systems, sensitive data, or operational workflows. Strong vendor oversight requires more than upfront due diligence; it also means limiting access, reviewing changes over time, and planning for what happens if a provider is compromised or unavailable.
- Ransomware is not just a technical event, but a business interruption risk that can affect payroll, customer service, financial operations, and communications. Effective preparedness requires integrated incident response, disaster recovery, and business continuity planning, supported by testing that confirms critical systems, backups, decision-making roles, and operational dependencies will hold up under pressure.
Why AI-enabled fraud, third-party access and ransomware require business controls, not technology alone.
The email looks legitimate.
It comes from a familiar vendor, references the correct invoice, and continues an existing email conversation. The sender explains that the company recently changed banks and provides updated payment instructions.
Nothing appears unusual – until the real vendor calls asking why it has not been paid.
By then, the money is gone.
This type of fraud is not new. What has changed is how convincingly and efficiently it can be executed.
Artificial intelligence can help attackers write polished messages, imitate voices, and create believable images and videos. A compromised email account can allow a criminal to study a real business relationship and intervene at exactly the right moment.
The FBI’s 2025 Internet Crime Report, released in April 2026, illustrates the scale of the risk. The FBI received more than one million complaints involving $20.9 billion in reported losses during 2025. Business email compromise accounted for approximately $3 billion, while complaints identified as AI-related represented nearly $893 million in reported losses.
Cyber risk is often treated as a technology problem. In practice, some of the most consequential failures occur where technology intersects with finance, operations, vendors and human decision-making.
A security tool may detect a suspicious login. It cannot independently confirm a vendor’s banking change, determine how the business will operate without a critical provider or establish who has decision-making authority during a crisis.
Those decisions require coordinated business controls – not technology alone.
When Appearance Is No Longer Proof of Identity
Most organizations train employees to look for misspellings, suspicious links and unfamiliar senders. Those warning signs still matter, but they are no longer enough.
AI can produce communications consistent with the apparent sender’s role. Criminals can use information from company websites, social media and professional networking sites to identify who approves payments, manages vendors or has authority to grant access.
The attack may also move beyond email. According to the FBI’s April 2026 release, scammers are using fake social profiles, voice clones, identification documents and believable videos to facilitate fraud.
Organizations need verification procedures that do not depend on the potentially compromised communication.
A request to change payment instructions should be confirmed using a previously established telephone number – not one supplied in the request. Higher-risk transactions should require documented review and approval by more than one authorized individual.
Multifactor authentication remains essential, but it cannot stop an authorized employee from approving a fraudulent request. Technical safeguards and business-process controls must work together.
What This Could Look Like
The following is a fictional example.
An accounts-payable employee receives an email appearing to come from a longtime vendor. The message references the correct invoice and internal contact and explains that the vendor recently changed banks.
The employee calls the telephone number included in the email. Someone answers using the vendor representative’s name and confirms the new instructions. The payment is released.
Several days later, the real vendor follows up on the unpaid invoice. An attacker had compromised an email account, studied the correspondence and redirected the verification call to a number under the attacker’s control.
A callback to the vendor’s previously verified number, combined with a second approval of the banking change, could have interrupted the fraud.
Verification is only effective when it uses information obtained independently of the request being verified.
The FBI’s 2026 public-awareness campaign encourages businesses to “Take a Beat” when confronted with a potentially fraudulent request: resist pressure to act immediately and assess the situation before transferring money or providing sensitive information.
Your Vendors Are Part of Your Cybersecurity Perimeter
Organizations increasingly depend on outside providers to manage technology, host applications, process payments, support customers and store sensitive information. Those relationships create efficiency, but they also create shared risk.
A vendor may have legitimate access to systems or information that a criminal wants. If that vendor is compromised, the attacker may be able to use trusted credentials or an established connection to reach the organization. Vendor risk is not limited to large technology companies. It may include:
- Managed IT and security providers
- Cloud and software platforms
- Payroll and benefits administrators
- Payment processors
- Accounting and professional-service firms
- Contractors and temporary personnel
- Industry-specific operational providers
Leadership should know which third parties have access to critical systems and sensitive information, why that access is needed and how it is controlled. Access should be limited to what the provider requires, protected with multifactor authentication where possible and removed promptly when the relationship or business need ends.
Due diligence before signing a contract is important, but it is only the beginning. A provider’s environment, services and subcontractors can change. Critical vendors should be reassessed periodically, and contracts should address security responsibilities, incident notification, data handling, and the return or destruction of information.
This approach aligns with guidance from the National Institute of Standards and Technology. In June 2026, the National Institute of Standards and Technology finalized updated guidance emphasizing the integration of cybersecurity supply-chain risk into system planning and risk decisions throughout the system life cycle. NIST emphasizes establishing policies and procedures for risks arising from third-party software, data, and other supply-chain relationships. It also calls for contingency processes when a high-risk third-party system or service fails.
In practical terms, vendor oversight should address two different questions:
- How is the provider protecting our systems and information?
- How will we continue operating if that provider becomes unavailable?
An organization can outsource a service. It cannot outsource accountability for understanding how that service affects the business.
Ransomware Is a Business-Interruption Risk
The critical ransomware question is not only whether attackers can encrypt files. It is whether the organization can continue operating if email, financial systems, customer platforms or other essential technology becomes unavailable.
The FBI received more than 3,600 ransomware complaints during 2025, with reported losses exceeding $32 million. However, the FBI explains that those figures generally exclude lost business, employee time, wages, equipment, and third-party remediation costs. The reported amount therefore does not reflect ransomware’s full operational and financial effect.
A technical incident-response plan may explain how to contain an attack. It may not explain how the organization will serve customers, pay employees, or communicate during an extended outage.
That is why incident response, disaster recovery, and business continuity must work together.
Leaders should know which systems and processes are essential, how long the business can operate without them and whether backups can be restored within the required timeframe. A tabletop exercise can expose unclear authority, outdated contact information and overlooked dependencies before a real incident does.
Cybersecurity Awareness Must Lead to Business Action
Cybersecurity Awareness Month is an opportunity to educate employees, but annual training alone will not address today’s most consequential risks.
The more meaningful leadership discussion is whether the organization has designed its processes for an environment in which identities can be convincingly imitated, trusted vendors can be compromised and essential technology can become unavailable without warning.
Leadership teams should begin with five questions:
- How do we independently verify high-risk payment, information and access requests?
- Which third parties have access to our critical systems or sensitive information?
- What business activities would stop if a key system or provider became unavailable?
- When did we last test our incident-response and continuity plans together?
- What unresolved cyber risks have been accepted—and who formally accepted them?
Strong cybersecurity does not require leadership to eliminate every risk or master every technical detail. It requires leaders to understand the organization’s most consequential exposures, assign responsibility and confirm that critical controls work in practice.
Verify before trusting. Limit access. Prepare for disruption. Test the plan before it is needed.
Could Your Leadership Team Answer
Could one employee change vendor banking information and release the payment? Can management produce a current list of vendors with privileged access? Has the organization recently restored a critical system from backup?
If the answers are unclear, PBMares can facilitate a focused Cyber Risk Leadership Discussion to evaluate how cyber risk moves through your business, identify gaps in existing controls and prioritize practical next steps.
For more information contact our Cybersecurity & Risk Advisory Services Partner Antonina McAvoy.
Be sure to consult with your financial or tax advisor on this topic as individual situations may vary. The information contained in this article or webinar, and any related materials, are for informational purposes only, and cannot be relied upon for legal, financial, tax, accounting, or other professional services advice. The content is provided on an “as is” basis and PBMares makes no representations or warranties about the accuracy or sustainability of any information for your purposes. For any specific questions you may have, please contact us.
This content is accurate at the time of publication. Always ensure you are reviewing the most recent information available. Contact your tax or financial advisor if you need clarification.
Contact Us
About the Author
Antonina McAvoy
CISA, CISM, QSA, PCIP
Partner, Risk Advisory Services
Norfolk
Antonina McAvoy specializes in cybersecurity, data protection, and privacy. She has 14 years of experience leading and performing a wide spectrum of cybersecurity reviews.
View Bio