Eftsure acquires Relish to lead trusted enterprise payments globally

Read more

AI has made deception cheap, and verification hasn't caught up

AI has made deception cheap, and verification hasn't caught up

Running a convincing deception at scale used to require a staff: writers to draft messages, people to keep dozens of personas consistent over weeks, callers to handle the moments email couldn't fake. Anthropic's newest threat intelligence report shows that requirement is gone.

In September 2026, Anthropic published case studies from AI misuse it disrupted between December 2025 and August 2026, including a China-based operation that built a network of more than 20 fake dating apps using Claude. Over two weeks in April 2026, more than 4,700 AI personas exchanged roughly 2.36 million messages with at least 25,000 people. Real gig workers handled some calls and video chats alongside the AI accounts, so nothing about the service read as automated to the people on the other end. The finding that matters is not that the scam was elaborate. It is that one operator, with no call centre and no team of script writers, produced a volume and consistency of tailored deception that used to require a large criminal enterprise.

The same mechanics apply directly to supplier impersonation and Business Email Compromise (BEC). At engineering firm Arup, a finance worker joined what looked like a normal video call with the CFO and several colleagues, the kind of live, multi-person check email cannot fake, and authorised US$25 million in transfers before learning that every other person on the call had been a deepfake.

Generative models remove the exact signals accounts payable teams were trained to catch: a strange turn of phrase, a rushed tone, a signature that does not quite match. A model holds a consistent voice across a hundred email threads at once, references a prior invoice accurately, and never slips into the broken phrasing that used to give a scam away. The tell finance teams were trained to look for is gone, not because the fraud improved, but because writing and speaking convincingly at scale no longer needs a skilled operator behind it.

Most finance teams still treat message legitimacy as the primary control, checked inconsistently across email review, verbal habits and ad hoc callbacks rather than one consistent standard. That gap is built into how verification works today, not a failure of any individual team's effort.

Verification has to sit outside the message

Verification has to move outside the message itself. A callback to a phone number sourced independently, not the one supplied in the email, confirms who actually sent the request. A registry check against verified supplier ownership data confirms the bank account belongs to who it claims to. Neither depends on how the message reads, which is the point: the content of a request is now the least reliable signal available, and any control still grading messages for legitimacy is grading the wrong thing.

AI, cheap digital tools and closer collaboration among criminal networks are driving what INTERPOL calls "the industrialisation of fraud," Secretary-General Valdecy Urquiza said in INTERPOL's 2026 Global Financial Fraud Threat Assessment.

Verify the payee, not the message

Practically, that means separating two checks that are often treated as one: confirming a request looks legitimate is a judgment call about tone and formatting, while confirming a supplier's identity and bank details through an independent, pre-verified source is a fact check. Only the second holds up against a persona built specifically to pass the first.

Anthropic disrupted this operation before most of its 25,000 targets lost money, but that capability is not unique to this one case. It is available to anyone directing a general-purpose model at the same goal. That is the shift finance leaders are actually being asked to plan for: fraud that INTERPOL estimates is now 4.5 times more profitable to run than it was before AI got involved. Eftsure exists for exactly that gap: the trust layer behind every payment, verifying supplier identity and bank details independently of whatever channel a request arrives through, so the decision to pay does not rest on how convincing the message looked.See how Eftsure verifies every payment.

Author

Catherine Chipeta

Published

17 Sep 2026

Reading Time

4 minutes

security-image

The New Security Standard for Business Payments

security-image
security-image