nsknox.net 76% of Treasury Teams Targeted by Rising Deepfake Payment Fraud
Article Content
- •76% of treasury teams reported payment fraud incidents in the past year.
- •53% faced confirmed or suspected deepfake-related fraud attempts.
- •Only 18% of organizations continuously revalidate supplier bank details.
The 2026 Treasury Dragons Payment Fraud Index reveals that 76% of treasury teams experienced at least one payment fraud incident in the past year, an increase from 73% in 2025. The report highlights a significant rise in deepfake attacks, with 53% of respondents facing confirmed or suspected deepfake-related fraud attempts. The most common attack method involves multi-channel approaches that combine email with voice calls or video interactions. Despite high confidence in supplier banking information (79%), only 18% of organizations continuously revalidate these details. The findings indicate that email remains a primary vector for fraud, with 41% of organizations receiving sensitive payment data via this insecure channel. The report emphasizes the need for organizations to adopt independent and continuous verification methods to combat these sophisticated fraud attempts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What percentage of organizations are affected by payment fraud?
How are deepfake attacks typically executed?
What steps can organizations take to improve verification?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…