Some finance leaders have done the maths on payment fraud and reached a simple conclusion: preventing it would cost more than the business currently loses. So they accept the losses and move on.
We hear this argument from time to time. If only a small percentage of payments are lost to fraud each year, why spend more to stop it?
The problem is that fraud losses aren't fixed.
Criminals choose who they target and, when an attack works, they have a reason to try again. A business that accepts fraud losses today may be making itself a more attractive target tomorrow.
Why budgeting for fraud can look reasonable
There's logic behind the idea: retailers have treated card fraud and chargebacks as a cost of doing business for decades. The losses tend to be relatively small and frequent, and completely eliminating them could cost more than accepting some fraud.
But accounts payable fraud is different.
Instead of thousands of low-value transactions, a business might make a smaller number of very large payments. Criminals can target individual businesses, vendors and invoices, then use what they learn to make the payment request look legitimate. One successful attack can therefore cost far more than the fraud allowance sitting in a budget.
What the fraud budget usually misses
When a fraudulent payment happens, the obvious loss is the money that left the bank account.
But that isn't the whole bill.
There can also be costs for:
- investigation, forensics and external incident response
- legal advice and managing the fallout with the vendor being impersonated
- finance and AP teams spending hours reconstructing what happened
- new controls introduced after the incident
- insurance deductibles and potentially higher renewal costs
Those costs can quickly turn a manageable-looking write-off into a much more expensive incident.
The stolen payment is only part of the cost
LexisNexis Risk Solutions has tried to measure that difference. Its 2025 True Cost of Fraud study, based on 507 risk and fraud executives across the US and Canada, found that every US$1 lost to fraud costs North American financial institutions about US$5 overall.
That multiplier has risen 25% in four years.
In other words, a US$100,000 fraud loss doesn't necessarily cost the business US$100,000. The final cost can be much higher once the response, investigation and control changes are included.
Shameela Gonzalez, executive director and financial services lead at CyberCX, described what happens after a significant incident in an interview with Eftsure:
"If you have lost a significant amount, you have then got to quantify how much it is going to take to go in and fill those gaps, those vulnerabilities that are around your perimeter, those controls you now need to put in place to prevent it. None of those come for free."
Shameela Gonzalez, CyberCX
And payment fraud isn't a rare problem.
The 2026 AFP Payments Fraud and Control Survey found that 76% of U.S. organisations faced attempted or actual payments fraud in 2025. Another 74% were affected by business email compromise (BEC).
The FBI's Internet Crime Complaint Center recorded US$3.04 billion in BEC losses in 2025, averaging more than US$122,000 per complaint. So budgeting for one manageable fraud incident a year can create false confidence, since the next loss doesn't have to look anything like the last one.
If an attack works, criminals have a reason to come back
Writing off a fraudulent payment might be an internal accounting decision. But the criminal knows the payment worked. They know the money cleared, they know whether anyone managed to recover it. And if the same payment process remains in place, they may have a route to try again.
"One of the things that's done is it signals to that criminal group that you're willing to wear that cost. It makes you a bit of a provocative target for the future."
Shameela Gonzalez, CyberCX
That information may not stay with the original attacker either. Gonzalez said criminal groups trade information with each other. Groups that break into systems can sell what they find to groups that specialise in fraud.
A business that has paid once can become a more attractive target because criminals now know something important: the attack worked.
What ransomware can tell us about repeat attacks
While Eftsure has seen fraudsters repeatedly target the same organisation, there isn't good public data showing how often businesses that absorb payment fraud losses are targeted again. One reason is simple: businesses that write off a loss may never report it.
Ransomware provides a useful comparison because researchers can track what happens after organisations pay. Cybereason surveyed more than 1,000 security professionals for its 2024 study and found that 78% of organisations that paid a ransom were attacked a second time.
Of those organisations, 36% were attacked again by the same group and 63% were asked for more money the second time.
The fraud tactic is different, but the lesson is relevant: paying a criminal doesn't necessarily make the problem disappear.
Today's fraud loss doesn't predict tomorrow's
When a business decides how much fraud it can tolerate, it's effectively making a forecast.
That forecast assumes future losses will look something like past losses.
There is no guarantee they will.
"They don't have an integrity play here. If they've managed to steal even a dollar out of you, why wouldn't they come back tomorrow again for another dollar?"
Shameela Gonzalez, executive director and financial services lead, CyberCX
U.S. BEC losses increased from US$2.77 billion in 2024 to US$3.04 billion in 2025. At the same time, attackers have access to tools that make convincing impersonation attempts easier and cheaper to produce.
What can push losses higher
A business can face greater exposure for several reasons:
- more fraud attempts as impersonation becomes cheaper and easier
- more convincing impersonation that isn't exposed by obvious spelling or formatting mistakes
- vendor and payment information exposed through third parties
- slow detection, which can allow several fraudulent payments to leave before anyone notices
This is why last year's losses are a poor ceiling for next year's fraud budget.
Some of the biggest costs never appear in the fraud budget
Recovering the money depends on speed
Recovering a fraudulent payment isn't automatic.
The FBI's Recovery Asset Team froze US$679 million across 3,900 incidents in 2025, with a 58% success rate.
But speed matters. The sooner a business spots the fraud and reports it, the better its chance of stopping or recovering the money.
If the payment is simply treated as a write-off, that response may never happen. By the time someone does act, the recovery window may have closed.
Insurance may cover less than you expect
Cyber insurance can help, but the headline policy limit doesn't necessarily tell you how much protection you have against payment fraud.
Social engineering and funds transfer fraud often sit under a separate sublimit, which can be much lower than the overall policy limit.
If the fraud loss is larger than that sublimit, the business pays the difference.
That needs to be part of the fraud calculation before an incident, not discovered afterwards.
The longer fraud goes undetected, the more it can cost
Detection also changes the size of the loss.
The ACFE's Occupational Fraud 2026 report, covering 2,402 cases across 143 countries, found a median loss of US$104,000.
The typical scheme continued for 12 months before it was discovered. And 43% of cases were uncovered through a tip rather than a control.
That creates another problem with budgeting based on historical fraud losses: a business only knows about the fraud it has found.
Undetected fraud doesn't appear in the spreadsheet.
Work out the real cost before deciding what fraud you can afford
Accepting some fraud risk can be a legitimate business decision. But finance leaders need the full cost before deciding how much risk they're prepared to accept.
That doesn't necessarily mean spending heavily on new controls. It starts with getting a clearer picture of the exposure.
- Calculate the full cost of previous fraud incidents, not just the amount stolen. The LexisNexis multiplier can provide a useful sense check.
- Track attempted fraud as well as successful fraud. Attempts can show whether pressure is increasing before losses follow.
- Verify every vendor bank detail change using a contact and communication channel you've sourced independently. Don't rely on the contact details supplied in the change request.
- Check the social engineering and funds transfer limits in your cyber insurance policy before assuming insurance will cover the loss.
- Set a target for how quickly fraud should be detected and track performance against it.
- Report incidents to law enforcement quickly because the opportunity to recover funds can disappear fast.
Gonzalez says some large enterprises think about security spending as a percentage of their overall technology investment. The logic is straightforward: technology only delivers its full value if the business protects it.
Payment controls can be viewed the same way. They're there to protect the money leaving the business.
That's why preventing a bad payment is different from budgeting to absorb one.
Eftsure provides end-to-end payment assurance by checking vendor identity and bank account ownership so businesses can verify payment details before money leaves the account. You can see how the verification works in a demo.
The question isn't simply how much fraud the business can afford to lose, it's whether accepting that loss today makes the next one more likely tomorrow.