Fall 2026

Are Treasury Teams Ready to Fight Fraud?

As payment scams become more sophisticated and difficult to detect, treasury departments are under growing pressure to strengthen controls and serve as a critical line of defense.
By Teri Saylor

Corporate treasury departments are under attack. Responsible for high-value transactions, vendor payments, and banking relationships, they’re prime targets for fraudsters, whose threats are quickly evolving.

While phishing emails are still prevalent among cybercriminals, today’s fraud schemes are becoming evermore sophisticated as artificial intelligence (AI) is making it easier to impersonate trusted vendors or executives, create convincing payment instructions to divert funds to fake bank accounts, and execute check fraud, among other nefarious acts.

In many cases, fraud attacks exploit routine business processes, making them especially difficult to detect, resulting in measurable financial losses, operational disruption, and reputational damage.

What Today’s Fraud Looks Like

In the Association for Financial Professionals’ (AFP) 2025 Digital Payments Survey, 76% of respondents indicated their organizations had been targets of either actual or attempted fraud activity.

According to Fraud.com, fraud is defined as “deceit with an intent to illegally gain a financial advantage over a person or an entity … using an intentional misrepresentation of facts to convince a person to hand over money or possessions.”

One bank executive’s recent experience with a client shows just how convincing—and costly—those misrepresentations can be.

Katherine Cobb, CFE, CTP, treasury consultant for City Bank in Texas and an anti-fraud expert, recalls a tense moment last summer when one of her clients received a phone call from someone stating they worked in City Bank’s treasury wire department.

“The red flag was that our bank has no treasury wire department,” Cobb says. “We have a treasury department and a wire department—the two aren’t combined.”

The caller told Cobb’s client that funds were being wired from her firm’s bank account to a recipient and provided seemingly legitimate information about the transaction, including a reference number. The caller also offered to review the client’s bank account to ensure no other fraud was committed and asked for the account information.

Cobb’s client, who served as the account administrator, provided her username, password, and token credentials to the caller who used them to log in to the account and view not only financial details but also the credentials of all the other users.

Cobb, who says she’d never ask any client for their login credentials, acted quickly to stop the fraudulent transaction: “We immediately shut down all transactions on the account and prevented loss. The fraudulent caller caught our client off guard, pressured her to act quickly, and she rushed to provide the account information out of fear.”

AI Is Complicating the Landscape

The emergence of AI has opened a new toolbox for schemes, making it even harder to spot fake correspondence. Gone are the days when fraudulent email was readily detected by misspellings, bad grammar, or phone calls and voicemails delivered in foreign languages.

Today, AI is making it easy for fraudsters to assimilate into our daily lives by generating the proper use of language and colloquial phrasing.

“AI is helping companies operate more efficiently,” says Jennifer Kentos, senior vice president and commercial relationship manager with Associated Bank. “At the same time, it’s made it easier for bad actors to create highly convincing emails, realistic professional images, and cloned voices, increasing the sophistication and effectiveness of fraud attempts.”

In 2025, the FBI’s Internet Crime Complaint Center (IC3) received over 22,000 complaints reporting AI-related scams, with losses totaling more than $893 million. The agency warns that chat generators can quickly create an official-sounding email to mimic a company’s CEO or other officials and insert phishing links or instructions to wire funds. It can also enable the creation of synthetic content, such as social media profiles and personalized conversations, often in mass quantities.

Further, AI security training software company Adaptive Security reports that scammers using voice cloning need only a few seconds of audio to produce a clone with an 85% voice match to the original—and thanks to the popularity of social media reels and videos, voicemail greetings, and website content, original voices are easy for fraudsters to access.

“We can learn a lot about people from their online presence— just think of how many of us are on LinkedIn,” says Joe Lenzie, senior vice president and treasury management officer lead at Associated Bank. “It’s pretty easy to understand people’s roles in their professional and daily lives through social media. If an individual can pull up information about their friends, colleagues, and even strangers, then a fraudster can access it to spoof their identity.”

Leading Forms of Fraud

The FBI’s IC3 received more than 1 billion fraud complaints in 2025, with losses totaling almost $21 billion, a 26% increase from 2024, with cyber-enabled fraud responsible for almost 85% of all reported losses.

Business email compromise remains one of the most common forms of payment fraud, and the FBI calls it “one of the most financially damaging online crimes.” Through the practice, cyber thieves use hacked or spoofed emails to trick their victims. They’ve also started using AI to create deepfakes to convince people to direct wire transfers into fraudulent accounts.

Other forms of fraud are also prevalent, with check fraud topping the list of financial theft schemes. According to AFP’s 2025 survey, 58% of organizations reported check fraud, outpacing ACH fraud and wire fraud.

Cobb advises companies to stop writing checks altogether: “Mail theft continues to be a growing problem in the United States. Thieves are stealing mail, taking checks, and either changing the payee, payment amount, or using checks to create counterfeit items.”

Additionally, with bank account numbers and routing numbers clearly printed on checks, Cobb adds that thieves can perform fraudulent ACH debits with those details.

How Treasury Teams Can Fight Back

“Treasuries put a lot of money and time into fortifying their defenses,” Cobb notes. “But if a fraudster can trick one of our customer businesses into either sending a payment willingly or giving up their credentials, there’s not a lot financial institutions can do to protect them.”

But it’s not all doom and gloom—there are actions organizations can take to mitigate the risk:

Slow Down

Kentos warns that heavy reliance on email, coupled with a culture of remote and fast-paced workplaces, create an opendoor environment, allowing fraudsters to simply walk in: “When organizations are operating in a culture of urgency to get things done while using manual processes, they’re creating gaps that allow sophisticated fraudsters to gain access.”

Because of this, Cobb advises employees to take a pause and carefully examine email messages, voicemail requests, and phone calls for suspicious signs: “When an employee receives a request, they should stop and ask if it makes sense. Are there unusual email addresses, links, attachments, or other irregularities?”

Kentos agrees that pausing is critical, adding that employees should follow their company’s internal control processes before reacting: “Such processes may include confirming the legitimacy of the email by contacting your vendor via a verified phone number that your company used previously or navigating to the vendor’s corporate online homepage to find a phone number.”

The FBI notes that the display name on the address line may look real, but the domain may have minor spelling changes, extra characters, or unusual extensions. Recipients should avoid opening links and attachments, as they may contain malware that can infiltrate company networks and access employee data, including their login credentials.

Additionally, perpetrators often pressure their victims into acting immediately, which is typically not necessary in performing legitimate transactions. The message might also threaten legal trouble; create a false crisis; or ask for passwords, personal data, gift cards, wire transfers, or cryptocurrency payments.

Verify the Requester

The client whose phone call to Cobb saved her organization from losing money called after the fact and was nearly too late. Cobb recommends refraining from responding to a caller’s request immediately. Instead, call the person who’s listed as the sender or requester.

“Don’t use the phone number in the email or voicemail—those could be spoofed too,” she adds. “Instead, use a phone number on file, or call their company and ask to be connected to them.”

Avoid Using Paper Checks

Instead of paying with paper checks, organizations should set up an ACH system. But if using paper checks is the preferred payment method, Cobb recommends using fraud prevention services, like Payee Positive Pay, which adds payee name verification to standard check matching protocols that compare information on the check against an official payment authorization list: “If it matches, the bank will pay it, and if it doesn’t, it becomes an exception that requires authorization to either pay or reject it.”

For companies using ACH to pay bills, Cobb recommends ACH Positive Pay, a popular fraud prevention solution that allows organizations to preapprove a list of companies authorized to receive payments: “With it, companies can set parameters, including maximum payment amounts. If someone tries to debit that account outside those parameters, the transaction is stopped for authorization.”

Establish Fraud Prevention Protocols

Both Lenzie and Kentos recommend organizations establish protocols to take control over their payment systems, including:

  • Requiring dual approvals: This makes sure one person is initiating a transaction or template for payment and a different person is approving it.
  • Maintaining vendor lists: Lenzie and Kentos advise keeping an approved-vendor list the treasury team can use to quickly identify up-to-date vendor names with specific representative names and contact information.
  • Using an enterprise resource planning system: These systems automate processes through encryption, which is a good way to protect money and data.
  • Shortening account reconciliation schedules: Kentos says this is a good way to catch or deter fraud: “If real-time reconciliation isn’t possible, try to at least shorten the lag time to weekly or daily.”

Invest in Employee Training

The AFP recommends training employees on financial fraud schemes and offers guidelines for fighting back against core threats, like business email compromise, check fraud, and AI-driven phishing. Use ongoing education to teach staff to spot phishing emails, urgent requests, and altered vendor payment details, and train teams to use trusted call-back procedures rather than replying to suspicious digital messages.

Cobb adds that organizations can also incorporate phishing simulations into their training programs, giving employees hands-on practice identifying and responding to suspicious requests and messages.

When the Unthinkable Happens

Despite corporate training, education, policies, and company protocols, fraudsters work hard to stay one step ahead, which is why treasury teams need to keep threats top of mind.

If fraudulent transactions occur, they should be reported immediately to the financial institution involved, corporate leadership, and authorities. If it’s a cybercrime, organizations should file a report to the FBI’s IC3.

Being a fraud victim has wide-ranging ramifications, from financial losses to regulatory problems, and the damage can be significant. If sensitive customer data goes out the door, there could be lawsuits or fines associated with it. Fraud can also erode public trust, which could lead to a loss of clients.

For Kentos, the most consequential aspect of fraud is reputational risk: “Organizations grow their business through their reputation in the marketplace, and once that’s damaged, it’s hard to recover.”

As fraud grows more sophisticated, so must the treasury function. As fraudsters target payments, vendor relationships, and routine financial processes, treasury teams are increasingly being called on to do more than manage cash—they must help defend it. That means investing in strong internal controls, employee training, and secure financial technologies that protect the organization’s bottom line, reputation, and customer trust.

After all, in today’s digital economy, the best defense isn’t reacting after the damage is done, it’s building a system where fraud has fewer opportunities to take hold.


Teri Saylor is a freelance journalist in North Carolina where she writes about businesses and lifestyles.

Related Articles