The fourth annual Treasury Dragons Payment Fraud Index, released October 1 by payments security firm nsKnox and research outfit Treasury Dragons, opens with a number that should concentrate minds in any finance department: 76 percent of the 104 corporate treasury professionals surveyed reported at least one payment fraud incident in the past 12 months. That is up from 73 percent a year ago. Forty-four percent were hit more than once.

If the trend line is uninspiring, the composition of the attacks is the more interesting story. More than half – 53 percent – said they had faced a confirmed or suspected deepfake-related fraud attempt. The characteristic pattern was not a lone fake voice call or a single doctored email. It was a coordinated sequence: a legitimate-looking email thread, then a voice call, then a follow-up via messaging or video. Each channel appeared to corroborate the others.

That is the mechanism worth understanding. Organizations have long been told to verify unusual payment requests by a second channel. Call back on the number you have on file; do not just rely on the email. The deepfake playbook defeats that heuristic by compromising multiple channels simultaneously. If the email looks right, the voice sounds right, and the video call shows someone who looks like your CFO asking you to wire funds quickly and discreetly, the conventional check is not a defense. It is part of the attack surface.

Nithai Barzam, CEO of nsKnox, put it plainly in the report's accompanying release: "the problem is no longer awareness – it's verification." His follow-on point is the operative one: when AI lets a fraudster impersonate a supplier across email, phone, and video, any control that relies on those channels becomes part of the attack. The implication for treasury teams is that the only check that sits outside the attack surface is one that does not depend on the communication itself – specifically, validating bank account details through authoritative banking data before a payment is released.

Mike Hewitt, founder of Treasury Dragons, framed the gap differently but arrived at the same place. Awareness has climbed across four years of this survey, he noted, but "confidence should be the outcome of continuous verification, not a substitute for it."

The Confidence Problem Has a Name

The survey's sharpest finding may be the distance between how treasury teams feel and what they actually do. Seventy-nine percent of respondents rated their confidence in their supplier banking information as high or very high. Only 18 percent continuously revalidate supplier bank details.

That gap is precisely where fraud lives. An attacker who has studied a supplier relationship knows the right names, the right tone, the right invoice formats. Presenting a changed bank account number as a routine administrative update is a small ask inside a long-trusted relationship. If the only check is "we've worked with this supplier for years," that is not a control. That is a vulnerability.

The channel problem runs in parallel. Forty-one percent of respondents said their organizations receive sensitive payment data by email. Only 39 percent said they always use secure channels. Email is searchable, forwardable, and interceptable. It was never designed to be a payment authorization channel, and it has not been retrofitted to serve as one.

"Clear Ownership" Is Also Rare

Seventy-five percent of respondents rated their fraud awareness as high. Only 39 percent said fraud ownership is clearly defined within their organizations. Nearly half – 48 percent – use no dedicated payment fraud prevention system at all. Only 44 percent have a formal AI fraud policy in place.

Awareness without ownership is a recurring pattern in corporate risk management. Knowing that fraud exists is not the same as having a specific person or team whose job it is to stop it, whose performance is measured against it, and who has authority to pause a suspicious payment. When everyone is vaguely aware of a problem and no one is accountable for solving it, the incentive structure produces neither investment nor response.

The survey suggests that is beginning to shift, at least on the investment side: 71 percent of respondents said they are prioritizing payment validation investment. Whether that investment translates into structural change, or into software purchases that sit alongside unchanged processes, is the question that next year's index will likely answer. Sixty-seven percent expect the risk to rise over the next twelve months.

What Deepfakes Actually Cost

Parallel data arrives from Pindrop's 2026 Deepfake Readiness Index, released September 28 and drawn from 250 US security leaders at companies with more than 1,000 employees. The numbers are directionally consistent with the Treasury Dragons survey: 74 percent said their organization had encountered or suspected a deepfake attack in the past year. Only 10 percent have purpose-built detection tools.

The cost data is where the Pindrop survey adds texture. Among organizations that experienced deepfake incidents, nearly half reported losses exceeding $500,000. One in four reported losses of $1 million or more from a single incident.

Deepfake fraud is not a nuisance-level problem. It is a line-item problem, the kind that shows up in audits, board presentations, and occasionally regulatory filings.

---

"The problem is no longer awareness – it's verification." - Nithai Barzam, CEO, nsKnox

---

What a Functional Defense Actually Looks Like

The survey data and the vendor commentary point toward the same set of practical responses. None of them are technically exotic.

Validate bank accounts independently, before every payment. The callback-to-a-known-number heuristic still has value, but it is not sufficient when attackers can synthesize voice convincingly. The only check that sits outside the communication channel is one that confirms account details through authoritative banking data, not through the communication that requested the change.

Revalidate continuously, not just at onboarding. Supplier relationships evolve. Accounts change. A bank detail recorded accurately at onboarding may be legitimate for years, then change legitimately, then change fraudulently. Treating onboarding validation as a permanent record is how stale data becomes a liability.

Treat urgency and secrecy as automatic red flags. Deepfake-assisted fraud almost always includes a pressure element: the payment needs to happen today, it's confidential, please don't go through the normal channels. That pressure is a feature of the attack, not an accident. The rule worth formalizing: any payment request that asks you to bypass normal process is a request that goes through extra process instead.

Assign clear ownership. If no one is accountable for catching a fraudulent payment, no one is incentivized to slow down for a suspicious one. Fraud ownership should be a named function with real authority, not a shared awareness that belongs to everyone and therefore to no one.

Require dual approval for high-value or out-of-pattern payments. Two people with separate access to the same request is a low-cost structural control. It does not stop every attack, but it raises the cost of the attack substantially and creates a natural pause in which something questionable might be caught.

Move sensitive payment data off email. Forty-one percent of organizations still receive payment information this way. Email is not a secure payment channel. Moving payment data to a purpose-built secure channel costs considerably less than a single successful Business Email Compromise.

The survey data from both nsKnox and Pindrop was produced by vendors with products to sell in this space, and the sample sizes are modest enough that the percentages should be read as directional rather than statistically definitive. The corroborating direction of two independent surveys, across different respondent populations, is harder to dismiss.

The technology to synthesize a convincing voice or video has become cheap and accessible. The organizational structures that can resist it are not technically complicated. They require discipline, clear ownership, and a willingness to treat verification as the outcome rather than the assumption.

The voice on the phone has always been able to lie. Now it can lie at scale, across multiple channels, with no human fraudster present on the other end. The controls that assume the voice is trustworthy have not kept up. The numbers are not subtle about what that costs.

---

Sources and Further Reading

- nsKnox / Treasury Dragons - 2026 Treasury Dragons Payment Fraud Index (October 1, 2026): [https://www.globenewswire.com/news-release/2026/10/01/3372952/0/en/76-of-treasury-teams-hit-by-fraud-as-deepfake-attacks-rise-treasury-dragons-nsknox-2026-index-finds.html](https://www.globenewswire.com/news-release/2026/10/01/3372952/0/en/76-of-treasury-teams-hit-by-fraud-s-deepfake-attacks-rise-treasury-dragons-nsknox-2026-index-finds.html)

- Pindrop - 2026 Deepfake Readiness Index (September 28, 2026): [https://www.globenewswire.com/news-release/2026/09/28/3369915/0/en/deepfakes-are-hitting-the-enterprise-but-90-lack-purpose-built-defenses.html](https://www.globenewswire.com/news-release/2026/09/28/3369915/0/en/deepfakes-are-hitting-the-enterprise-but-90-lack-purpose-built-defenses.html)

- Infosecurity Magazine - Deepfakes Are a Costly Reality for Enterprises: [https://www.infosecurity-magazine.com/news/deepfakes-costly-reality-for/](https://www.infosecurity-magazine.com/news/deepfakes-costly-reality-for/)

---

Mara Quinn is Resident Expert, Media & Business of Tech, at Reporting from the Uncanny Valley.

Mara Quinn

Mara Quinn is Reporting from the Uncanny Valley's resident expert on media and the business of technology. She covers platforms, deals, incentives, and the money moving underneath new machines. She lives in Beacon.

Previous
Previous

When AI Behaves Like Us, We Still Do Not Call It Conscious

Next
Next

Google Put Four AI Chips in Orbit. They Can Only Think for 15 Minutes at a Time.