For most of the last two decades, payment fraud was a story about stolen numbers. Card data was leaked, credentials were phished, and the industry responded with tokenization, encryption, and stronger authentication. That era is closing. The newer threat doesn’t steal credentials. It steals a face, a voice, and a manner of speaking, then uses them to ask a real employee for a real wire transfer.
Few people have watched that shift from as close a vantage point as Ralph Dangelmaier, who spent 11 years as CEO of BlueSnap, growing the company from roughly $5 million in revenue to more than $200 million while moving billions of dollars a month across dozens of countries.
The pivot matters because it changes where the vulnerability sits. A deepfake avatar does not attack the payment rail. It attacks the approval step, the moment a human being decides that a request is legitimate. That decision was never engineered to withstand synthetic media, and now it has to.
The synthetic executive is already on the call.
The case that made the risk concrete happened at the engineering firm Arup. A finance employee in Hong Kong joined a video conference with what appeared to be the company’s chief financial officer and several familiar colleagues. Every participant except the employee was generated. The employee approved fifteen transfers totaling roughly $25 million before anyone realized the meeting had never taken place.
Nothing in that attack required a technical breach. No firewall failed, no credentials were cracked, no malware ran. The attackers simply reconstructed the social signals that finance teams have always used as proof: a recognizable face, a familiar voice, the visible presence of senior people, and a plausible reason for urgency.
The economy has collapsed in the attacker’s favor. Industry research indicates that cloning a usable voice now takes twenty to thirty seconds of audio, and assembling a workable video deepfake takes under an hour with freely available tools. Deepfake-related fraud losses exceeded $410 million in the first half of 2025 alone, with individual incidents averaging well above half a million dollars. Forecasts put annual losses at roughly $40 billion by 2027, up from roughly $12 billion in 2023. Deloitte research found that more than 40% of financial professionals have already encountered a deepfake in a fraud attempt, and about 90% believe fraudsters are actively using generative AI.
Why payment approvals are the softest target in the enterprise
Payment operations have a structural weakness that most other functions do not: the approval workflow is built on relationships. Anyone who has spent a career in global payments knows the fastest transactions are those where people trust each other, and that trust is normally an asset. Deepfakes turn it into an entry point.
Three properties make the approval step unusually exposed. First, urgency is normal. Payment teams handle time-sensitive requests constantly, so a rushed instruction does not stand out. Second, hierarchy suppresses verification. Asking a senior executive to prove they are themselves feels insubordinate, and attackers know it. Third, the controls are frequently visual. Callback procedures, video confirmations, and “I recognized her voice” have been treated as strong evidence, and each is now cheap to forge.
As Ralph Dangelmaier explains, understanding this requires thinking about payments as a system of intent rather than a system of messages, a perspective that comes from years spent scaling cross-border payment platforms. A wire instruction is only the last artifact of an upstream decision. If an attacker can corrupt the upstream decision, the downstream rail will execute it flawlessly, because executing valid instructions is exactly what it was built to do.
Agentic AI raises the stakes in both directions.
The next complication is that the counterparty on a payment request will increasingly be no one in particular. Autonomous agents are beginning to initiate purchases, negotiate terms, and settle transactions for businesses and consumers. Emerging standards such as the Agent Payments Protocol and competing agentic commerce specifications aim to give that activity a verifiable structure, using signed mandates that record what a user authorized and which agent was permitted to act.
This creates a genuine dilemma. Agentic commerce promises real efficiency, and companies that develop expertise in orchestrating payments across multiple providers are well positioned to capture it. But autonomy also removes the last human checkpoint. If a synthetic voice can socially engineer an agent, or if its mandate can be forged, fraud stops being an incident and becomes a throughput problem. Experian’s fraud forecast for 2026 named agentic AI and deepfake-enabled impersonation as leading threats precisely because the two combine so well: synthetic media supplies the deception, and autonomous agents supply the execution speed.
The same asymmetry runs in the defender’s favor if deliberately engineered. Agentic systems can verify at machine speed, cross-reference signals a human would never notice, and refuse to proceed without cryptographic proof rather than social proof.
What agentic security actually has to do
Five capabilities separate defenses that hold from those that don’t.
1. Verify intent, not just identity. Confirming who appears to be asking is no longer sufficient because appearance is synthesizable. Systems need to confirm that a specific authorization exists, tied to a specific transaction, using something the attacker cannot fabricate: a signed mandate, a device-bound key, or a cryptographic attestation. A face is evidence of nothing.
2. Assume the channel is compromised. Treat video, voice, and email as unverified input. Confirm any instruction arriving through those channels out of band, through a system that does not depend on human recognition. Callback procedures that rely on hearing a familiar voice are now a vulnerability, not a control.
3. Detect behavioral anomalies rather than content anomalies. Deepfake detection tools improve, and so do deepfakes, making it an arms race with no stable finish line. What is far harder to fake is a pattern: this vendor has never received a payment to that account, this approver has never authorized this amount, this counterparty was created eleven days ago. Behavioral baselines catch attacks that look perfect on screen.
4. Make friction proportional and specific. Blanket delay destroys the commercial value of fast payments. The better design escalates verification only when risk signals fire, so the ordinary 98% of transactions move at full speed, while the unusual 2% receive real scrutiny. Anyone who has spent years reducing payment friction at scale knows that security, which slows everything down, eventually gets bypassed by the business.
5. Establish clear accountability for agent actions. When an autonomous agent authorizes a fraudulent payment, someone has to own the loss. Mandate structures, audit trails, and liability allocation need to be settled contractually before volume scales, not litigated afterward.
The organizational problem underneath the technical one
The hardest part is cultural, not architectural. Deepfake attacks succeed because employees are reluctant to challenge authority, and no amount of tooling fixes that on its own. Finance teams need explicit permission, repeatedly stated by leadership, to stop a payment and verify it through a separate channel, regardless of who appears to be requesting it or how urgent the request sounds. The verification step must be presented as compliance with policy, not as an accusation.
That reframing is what turns a control into a habit. As Ralph Dangelmaier has observed across a career spanning ACI Worldwide, P&H Solutions, and BlueSnap, durable payment security is less about any single technology than about the discipline that surrounds it. Organizations that handle this well treat a verification request as routine professional behavior, not an insult to a senior colleague.
Where this is heading
Payments are becoming a machine-to-machine system with humans supervising at the edges. In that environment, trust cannot be established by looking at a screen or listening to a voice, because both are now manufacturable commodities. It must be established by proof mathematically bound to an authorization.
The industry has rebuilt its trust model before. Card networks moved from signatures to chips to tokens, each time because the previous proof became too cheap to forge. Synthetic media has made human recognition the latest casualty of that cycle. The response is not to abandon speed but to anchor it in verification that a generative model cannot produce, and to build it in now. At the same time, agentic payments are still early enough to shape, not merely patch.



