The AirPlus Global

Why payment fraud is becoming more sophisticated

Written by AirPlus Editorial Team | Aug 31, 2026

"I like the term 'cyber hygiene' – the habits and best practices we need to follow everyday to keep our data secure."

Lilian-Margarete Biel is the Product Manager of the AirPlus Portal, overseeing the development of features to not only make it more capable, but also more secure.

The ability to lock down access to data and reduce the risk of fraud has always been important in business, especially for corporate payments. But as payment fraud becomes more sophisticated, it has become a key point of focus.

 

Why is payment fraud becoming more sophisticated?

"Fraud attempts have become more sophisticated due to the growing adoption of technologies like AI in the form of LLMs and deepfakes, as well as the increasing complexity of digital workflows." 

Fraud often relies on social engineering rather than finding technical vulnerabilities. By manipulating individuals, fraudsters can gain access to sensitive infromation, like your payment data. 

They use all the means at their disposal: Email, phone calls, video calls, SMS, and more.

 

AI

That's where AI comes in.  

In the wrong hands, it can be used to craft realistic sounding emails and SMSs from a manager of top level executive asking for sensitive data. When used to develop deepfakes, it becomes possible to fake video calls by taking on the appearance of others.

 

Complex systems

Then there's the complexity of modern business workflows.  

Looking at corporate payments, you may find yourself accessing multiple different platforms for each stage of the purchasing process. Each one of these is a potential point of vulnerability where a weak password could be exploited.

 

What can businesses do about it?

Thankfully, there are plenty of ways to manage this risk. Here are a few worth highlighting:

 

Manage data access effectively

"It's best practice to maintain a 'need-to-know' approach to data. Not everyone needs access to everything. I am a big fan of the 'roles and rights' approach, where you're able to assign individuals the right amount of access based on what they need to complete their tasks." 

Effective data access management is both a preventative and mitigation tactic. It stops would-be fraudsters from gaining access while limiting damage in the case of a breach. 

That's why we've implemented this in the AirPlus Portal with an ever-evolving roles and rights approach. All users are allocated a role with which certain rights are provided.  

What's important is that these roles and rights are continuously being updated based on feedback and usage of the platform to find the best balance between security and convenience.

 

Offer the most secure authentication methods

"Having effective authentication methods available in place is an obvious option. Passwords alone aren't ideal. But I believe having several secure options available is best. That way, individuals can select whichever is most convenient for them which goes a long way to ensuring they maintain their cyber hygiene." 

Login credientials have long been the point of focus for scams. A lot of the tactics and tricks mentioned above aim to steal these credentials as a means to gain access to your systems.  

The standard used to be passwords – but their effectiveness relies heavily on the strength and uniqueness of the password, which can't always be guaranteed. 

Thankfully, there are more secure options available. 

Passkeys are considered one of the best options as they are resistant to phishing, use cryptographic authentication that's tied to your device, and are generally more convenient to use. 

Two-factor authentication via authenticatior apps also helps prevent fraud while reducing dependance on passwords alone. 

The good news for AirPlus Portal used is that we've now added support for logging in via Authenticator and Passkeys, further enhancing  your ability to prevent fraudulent access to your account.

 

Education

"Maintaining cyber hygiene is not something that can be achieved centrally. It requires the input of everyone to make it work best." 

Perhaps the best security remains education. Keeping everyone informed about potential fraud tactics helps turn employees from a possible point of vulnerability into an active line of defense. 

And so cyber hygiene should be treated as an ongoing habit rather than a one-off training exercise. Regular reminders, clear internal processes, and a culture where people feel comfortable questioning unusual requests can all help reduce the risk of fraud. 

For businesses, this also means making it easy for users to know what good practice looks like: checking sender details, verifying payment-related requests through a second channel, avoiding password reuse, and reporting suspicious activity as quickly as possible. 

We offer plenty more detailed guidance and practical advice on identifying phishing, vishing, smishing, and other scams – see our dedicated page on fraud prevention for more.

 

Staying ahead

Payment fraud will continue to evolve as technology, business processes, and fraud tactics become more advanced.  

That means prevention cannot rely on a single tool, policy, or point of control. It requires a layered approach that incorporates practices like secure access, strong authentication, clear processes, and informed users who understand their role in protecting sensitive payment data. 

With good cyber hygiene, organisations can make it harder for fraudsters to succeed while keeping payment processes efficient and convenient for those who rely on them. 

Here at AirPlus, we cover plenty of interesting topics relevant to corporate payments. Sign up for our global newsletter to get the latest to your inbox.